Back to skill

Security audit

Bulk Tiktok Downloader

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward local TikTok bulk downloader, but users should be aware it installs and runs yt-dlp and will download from whatever URLs are placed in the input file.

Install only if you are comfortable running yt-dlp locally. Use a URL file you created or trust, keep the output directory scoped to a folder you expect to fill with downloads, and consider pinning yt-dlp in an isolated virtual environment before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/downloader.py:26
Finding

Unrestricted URL Processing Enables Requests to Unintended Network Destinations

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:1
Finding

Unpinned Third-Party Dependency Creates a Mutable Supply-Chain Risk

Content
View full analysis
=2024.1.1 ``` The dependency is installed through the documented command: ```bash python3 -m pip install --user -r scripts/requirements.txt ``` ### Technical Analysis The lower-bound version constraint permits pip to install any available `yt-dlp` release equal to or newer than `2024.1.1`. Therefore, the dependency actually installed can change over time without any modification to this project. No cryptographic hashes or lock file are supplied to verify the exact distribution artifact. The installed code is subsequently imported and executed by `scripts/downloader.py`. This prevents reproducible installation and expands the trust boundary to future package releases and the package-index delivery path. This finding does not establish that `yt-dlp` is malicious. The vulnerability is the project's failure to constrain and integrity-check the reviewed dependency version. ### Attack Path 1. A user follows the project's setup instructions. 2. Pip queries the configured package index for a version satisfying `yt-dlp>=2024.1.1`. 3. Pip selects a release that may not have existed or been reviewed when this skill was audited. 4. The selected package is installed into the user's Python environment without project-supplied hash verification. 5. The downloader imports `yt_dlp` and executes its code when processing URLs. 6. If the selected package artifact or a future release is compromised, its code executes with the permissions of the user running installation or the downloader. ### Impact Assessment A compromised dependency could execute arbitrary Python code with the current user's privileges. This could potentially read or modify files available to that user, access user-level credentials and environment data, make network connections, or alter t ...[truncated 257 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill instructs the agent to operate on local files such as a URL list and output directory, but the manifest does not declare any explicit tool scope or permissions. That mismatch can cause over-broad file access at runtime or make review and enforcement of least-privilege controls harder, especially because the skill is meant to read arbitrary local path inputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file explains that the script downloads multiple TikTok videos and saves them into a local downloads folder, which involves both outbound network requests and local file writes. Under the markdown-specific warning criterion, the description lacks any explicit caution about these behaviors' impact on user data, bandwidth, or storage.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified as yt-dlp>=2024.1.1, which allows future versions to be installed without review and makes builds non-reproducible. This increases supply-chain risk because a later compromised or breaking release could be pulled automatically, and the exact security posture of the installed package cannot be guaranteed.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
yt-dlp>=2024.1.1

Unverifiable Dependency: yt-dlp has 16 known advisory(ies) (CVE-2023-46121 (yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy Injection); GHSA-3v33-3wmw-3785 (yt-dlp has dependency on potentially malicious third-party code in Douyu extract); CVE-2023-40581 ( yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

yt-dlp has multiple known advisories, and because the manifest does not pin an exact version, it is impossible to verify whether deployments will install an affected or fixed release. In a bulk TikTok downloader skill, this matters more because the package is core functionality and will process many untrusted remote URLs, increasing exposure to parser, extractor, or command-injection-related flaws in vulnerable versions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.