T09 · Insecure Skill Coding Practices
- Location
douyin-uploader.js:369- Finding
Chromium Sandbox Is Unconditionally Disabled
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Douyin uploader is purpose-aligned, but it needs review because it handles account sessions and publishing while disabling browser sandboxing and silently granting broad browser permissions.
Install only if you are comfortable with a local automation script storing Douyin session cookies and publishing to your account. Prefer running it in a dedicated, low-privilege environment, avoid sharing the skill directory or generated cookie/profile files, use --no-publish when you want a draft, and review the browser permission and sandbox choices before using it with a sensitive account.
douyin-uploader.js:369Chromium Sandbox Is Unconditionally Disabled
douyin-uploader.js:387Unnecessary Camera, Microphone, Geolocation, and Clipboard Permissions Are Automatically Granted
douyin-uploader.js:54Authentication Cookies Are Stored in Plaintext Without Explicit Owner-Only File Permissions
The documented purpose understates the skill’s actual capabilities and side effects. Beyond simple upload/login, it can publish content, handle SMS verification input, request broad browser permissions, and delete local authentication/session data; this reduces informed consent and can lead users to authorize more access or actions than they intended.
The code silently approves multiple high-risk browser permissions without any user-facing disclosure. In the context of a login/upload automation tool, this broadens the trust boundary significantly and could enable capture of audio/video, location leakage, clipboard theft/modification, or abusive notification flows if the target site or loaded content is malicious or compromised.
The code saves authenticated Douyin cookies to a local JSON file, creating persistent bearer-token style session material on disk. Anyone with local access, malware on the host, or another process reading that file may reuse the session to access the user's account without re-authentication.
The tool will automatically click publish when autoPublish is not explicitly false, meaning publication can occur as a side effect of running the upload flow. In a content publishing context, unintended posting can cause account misuse, reputational harm, and release of sensitive or unreviewed content.
The browser context auto-grants sensitive permissions including camera, microphone, geolocation, notifications, and clipboard access for Douyin domains. A video upload/login tool does not inherently need blanket pre-approval for all of these, so if the site, embedded content, or a compromised page requests them, the automation silently exposes device capabilities and user data without meaningful consent.
The natural-language comments and usage text are written only in Chinese, with no indication that the skill is region-specific or that users can opt into this locale. This can violate language/locale policy when a skill implicitly constrains users to a specific language without documented justification.
The top-of-file comments and usage text are written in Chinese, which imposes a specific language on users without any visible opt-in or explanation that this skill is intended only for a Chinese-speaking or region-specific audience. This matches the language/locale policy violation category because the file does not offer an alternative language or document a justified locale constraint.
The file presents its purpose and usage text in Chinese ('抖音视频上传脚本', '用法') while the script itself is otherwise generic CLI tooling and does not provide any language selection or opt-in. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is explicitly justified.
The dependency uses a caret range (^23.11.1) instead of an exact pinned version, which makes builds non-reproducible and can pull in different upstream releases over time. In a skill that automates browser login and video upload, dependency drift increases supply-chain risk because changed transitive code runs with access to authenticated browser sessions and local environment data.
"manage": "node scripts/manage.js"
},
"dependencies": {
"puppeteer": "^23.11.1"
}
}
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
No suspicious patterns detected.