Back to skill

Security audit

抖音实时上升热点榜

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Douyin trend-fetching API client, but users should treat its API key as sensitive and avoid passing it on the command line.

Install only if you trust coze-js-api.devtool.uk/devtool.uk with your AZT_API_KEY and query filters. Prefer setting AZT_API_KEY through a managed secret or environment variable, do not pass real keys as command-line arguments, and rotate any key previously exposed in shell history or logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_hot_rise_list.py:21
Finding

API Key Exposure Through Command-Line Arguments

Content
View full analysis
str: """优先使用参数传入的 key,否则读取环境变量 AZT_API_KEY""" key = arg_key or os.environ.get("AZT_API_KEY", "").strip() if not key: print( "❌ 未检测到 API Key。\n" " 请前往 https://devtool.uk/wiki 购买或查看使用说明,\n" " 然后通过以下任一方式提供 Key:\n" " 1. 设置环境变量:export AZT_API_KEY=\"your_key\"\n" " 2. 传入参数:python3 fetch_hot_rise_list.py --azt_api_key your_key", file=sys.stderr, ) sys.exit(1) return key ``` The corresponding argument is registered as follows: ```python parser.add_argument("--azt_api_key", default=None, help="API Key(也可通过环境变量 AZT_API_KEY 设置)") ``` ### Technical Analysis The script accepts the API credential through the `--azt_api_key` command-line option and explicitly recommends this method in its error message. Secrets supplied as command-line arguments can be exposed through: - Shell history files. - Process listings and process-monitoring utilities while the script is running. - Terminal logging and command auditing systems. - Wrapper scripts, job schedulers, or diagnostic tools that record complete command lines. The implementation does not print the resolved key, and the outbound request uses HTTPS. However, those controls do not prevent local disclosure before the request is made. Accepting the key through an environment variable is safer than a command-line argument, but the current documentation and implementation continue to promote both methods. The key is sent only to the declared service endpoint and is necessary for the advertised API functionality. No unrelated environment variables or loc ...[truncated 1555 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documents capabilities to read environment variables and make outbound network requests, but it does not declare any explicit tool scope or permission boundary. That omission can cause users or hosting platforms to underestimate what the skill can access and where data may be sent, increasing the risk of unintended secret exposure or unauthorized external communication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the user to send an API key in a POST request to an external service but does not clearly warn that credentials will be transmitted off-platform to a third-party endpoint. In a skill context, this is dangerous because users may provide sensitive secrets without understanding the trust boundary or the risks of disclosure, logging, or misuse by the remote service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and all user-facing messages are written in Chinese, which effectively constrains interaction to a specific language. There is no indication that this is optional, configurable, or justified as a region-specific tool.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch_hot_rise_list.py (reported line 58)May include surrounding context.

python
payload["keyword"] = keyword

    try:
        response = requests.post(
            API_URL,
            json=payload,
            timeout=30,

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill tells the agent to read a credential from the AZT_API_KEY environment variable without a corresponding warning about sensitive secret handling. While accessing env secrets is common, the missing guidance makes accidental disclosure, misuse, or forwarding of the secret to unintended contexts more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code posts the user's API key and optional keyword/sentence_tag values to a third-party service. Although it logs that a request is being made, it does not clearly warn the user that credentials and query content will be transmitted off-machine to an external domain.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.