T09 · Insecure Skill Coding Practices
- Location
scripts/downloader.py:26- Finding
Unrestricted URL Processing Enables Requests to Unintended Network Destinations
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward local TikTok bulk downloader, but users should be aware it installs and runs yt-dlp and will download from whatever URLs are placed in the input file.
Install only if you are comfortable running yt-dlp locally. Use a URL file you created or trust, keep the output directory scoped to a folder you expect to fill with downloads, and consider pinning yt-dlp in an isolated virtual environment before use.
scripts/downloader.py:26Unrestricted URL Processing Enables Requests to Unintended Network Destinations
scripts/requirements.txt:1Unpinned Third-Party Dependency Creates a Mutable Supply-Chain Risk
The skill instructs the agent to operate on local files such as a URL list and output directory, but the manifest does not declare any explicit tool scope or permissions. That mismatch can cause over-broad file access at runtime or make review and enforcement of least-privilege controls harder, especially because the skill is meant to read arbitrary local path inputs.
This markdown file explains that the script downloads multiple TikTok videos and saves them into a local downloads folder, which involves both outbound network requests and local file writes. Under the markdown-specific warning criterion, the description lacks any explicit caution about these behaviors' impact on user data, bandwidth, or storage.
The dependency is specified as yt-dlp>=2024.1.1, which allows future versions to be installed without review and makes builds non-reproducible. This increases supply-chain risk because a later compromised or breaking release could be pulled automatically, and the exact security posture of the installed package cannot be guaranteed.
yt-dlp>=2024.1.1
yt-dlp has multiple known advisories, and because the manifest does not pin an exact version, it is impossible to verify whether deployments will install an affected or fixed release. In a bulk TikTok downloader skill, this matters more because the package is core functionality and will process many untrusted remote URLs, increasing exposure to parser, extractor, or command-injection-related flaws in vulnerable versions.
No suspicious patterns detected.