Back to skill

Security audit

Douyin

Security checks for vulnerabilities and agentic risk

Overview

This Douyin uploader is purpose-aligned, but it needs review because it handles account sessions and publishing while disabling browser sandboxing and silently granting broad browser permissions.

Install only if you are comfortable with a local automation script storing Douyin session cookies and publishing to your account. Prefer running it in a dedicated, low-privilege environment, avoid sharing the skill directory or generated cookie/profile files, use --no-publish when you want a draft, and review the browser permission and sandbox choices before using it with a sensitive account.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
douyin-uploader.js:369
Finding

Chromium Sandbox Is Unconditionally Disabled

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
douyin-uploader.js:387
Finding

Unnecessary Camera, Microphone, Geolocation, and Clipboard Permissions Are Automatically Granted

Content
View full analysis
{ console.error('Failed to override permissions for creator.douyin.com:', error instanceof Error ? error.message : String(error)); }); await context.overridePermissions('https://www.douyin.com', [ 'geolocation', 'notifications', 'camera', 'microphone' ]).catch((error) => { console.error('Failed to override permissions for www.douyin.com:', error instanceof Error ? error.message : String(error)); }); } ``` ### Technical Analysis The Skill automatically grants multiple sensitive permissions to two web origins whenever Chromium runs in non-headless mode. The granted capabilities include geolocation, camera, microphone, clipboard read/write access, and notifications. The documented tasks—authentication, cookie validation, and video upload—do not demonstrate a need for all of these permissions. Automatically approving them bypasses the browser's normal user-consent boundary and violates least privilege. The permissions are assigned at the origin level. Consequently, any script executing under an authorized origin may attempt to use them. This includes legitimate first-party scripts, compromised origin content, or code injected through a same-origin cross-site scripting vulnerability. Although the launch configuration also uses fake-media flags, those flags do not eliminate the risks associated with clipboard access, geolocation, notifications, or future configuration changes involving real me ...[truncated 1566 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
douyin-uploader.js:54
Finding

Authentication Cookies Are Stored in Plaintext Without Explicit Owner-Only File Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose understates the skill’s actual capabilities and side effects. Beyond simple upload/login, it can publish content, handle SMS verification input, request broad browser permissions, and delete local authentication/session data; this reduces informed consent and can lead users to authorize more access or actions than they intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code silently approves multiple high-risk browser permissions without any user-facing disclosure. In the context of a login/upload automation tool, this broadens the trust boundary significantly and could enable capture of audio/video, location leakage, clipboard theft/modification, or abusive notification flows if the target site or loaded content is malicious or compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code saves authenticated Douyin cookies to a local JSON file, creating persistent bearer-token style session material on disk. Anyone with local access, malware on the host, or another process reading that file may reuse the session to access the user's account without re-authentication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The tool will automatically click publish when autoPublish is not explicitly false, meaning publication can occur as a side effect of running the upload flow. In a content publishing context, unintended posting can cause account misuse, reputational harm, and release of sensitive or unreviewed content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The browser context auto-grants sensitive permissions including camera, microphone, geolocation, notifications, and clipboard access for Douyin domains. A video upload/login tool does not inherently need blanket pre-approval for all of these, so if the site, embedded content, or a compromised page requests them, the automation silently exposes device capabilities and user data without meaningful consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language comments and usage text are written only in Chinese, with no indication that the skill is region-specific or that users can opt into this locale. This can violate language/locale policy when a skill implicitly constrains users to a specific language without documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-of-file comments and usage text are written in Chinese, which imposes a specific language on users without any visible opt-in or explanation that this skill is intended only for a Chinese-speaking or region-specific audience. This matches the language/locale policy violation category because the file does not offer an alternative language or document a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file presents its purpose and usage text in Chinese ('抖音视频上传脚本', '用法') while the script itself is otherwise generic CLI tooling and does not provide any language selection or opt-in. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency uses a caret range (^23.11.1) instead of an exact pinned version, which makes builds non-reproducible and can pull in different upstream releases over time. In a skill that automates browser login and video upload, dependency drift increases supply-chain risk because changed transitive code runs with access to authenticated browser sessions and local environment data.

Content

Scanner excerpt · package.json (reported line 17)May include surrounding context.

json
"manage": "node scripts/manage.js"
  },
  "dependencies": {
    "puppeteer": "^23.11.1"
  }
}

Unverifiable Dependency: puppeteer has 1 known advisory(ies) (CVE-2019-5786 (Use-After-Free in puppeteer)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.