Back to skill

Security audit

Douyin Upload MCP Skill

Security checks across malware telemetry and agentic risk

Overview

The skill broadly matches its Douyin automation purpose, but it grants persistent account-control and messaging authority with several under-scoped behaviors users should review first.

Install only on a dedicated machine or dedicated browser profile, and review bootstrap before running `--apply`. Expect it to control a Douyin account, send Feishu messages, read Feishu/Douyin interaction data, use configured LLM/video-provider credentials, and run persistent background jobs. Disable or inspect the local scheduler if you do not want automatic comment/private-message replies, and avoid exposing the daemon ports to a network.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (280)

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
主体功能与声明高度重合:代码覆盖了抖音发布、登录守卫、二维码与短信验证、飞书消息路由、数据同步与报告、下一条视频方案、自动回复评论/私信、数字人训练、XiaoIce 一键成片、截图通知等核心声明能力。但按评估标准仍应判定为不匹配,因为代码明显包含多项未在描述中体现的重要能力,尤其是系统级安装与运维功能(bootstrap、systemd-run、systemctl、OpenClaw 配置修改、浏览器自动安装、导出打包)、以及直接删除抖音作品的管理功能。这些不是单纯实现细节,而是独立能力,且部分涉及系统资源和账号内容管理,超出了“自动投放与登录守卫”的描述范围。

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The package description says the skill operates the Douyin creator center webpage for content creation and management, which suggests a browser automation tool for publishing/management. However, the available scripts indicate additional operational roles such as daemon/supervisor processes, scheduled auto-reply and daily reporting, Feishu routing/stability flows, and digital-human training workflows, which go beyond the narrower description of webpage content management.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The manifest describes a Douyin publishing/login/analysis workflow skill, but this file includes capability to run apt-get and fetch a Chrome .deb from Google's servers to modify the host system. While a browser is needed for automation, package-manager driven software installation and arbitrary binary download are host bootstrap capabilities that go beyond the core business purpose described in the manifest.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The manifest focuses on Douyin operations, Feishu notifications, data sync, and content generation, but this code writes ~/.config/systemd/user service units, enables them, and restarts both the skill supervisor and an OpenClaw gateway service. Persistent service management is an infrastructure capability not clearly justified by the functional description presented to users.

Context-Inappropriate Capability

Medium
Confidence
80% confidence
Finding
Although the manifest mentions digital human training and one-click video generation, this file provisions a separate vendor tool into the user's home directory, seeds its .env file, and runs npm install within it. That is a software deployment capability for an auxiliary package, not merely execution of the stated Douyin workflow.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The manifest describes automated publishing, login guarding, QR/login verification handling, analytics, content planning, replies, digital human training, and notifications. This script navigates to the content management page and deletes an existing work by title, a destructive moderation/cleanup capability that is not mentioned in the declared purpose.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The skill manifest describes Douyin publishing/login guarding, Feishu notifications, and data-analysis workflows. While generating a report is in scope, this file goes beyond task-specific inputs by probing generic local agent config under the user's home directory and multiple broad provider credentials (OPENAI, MINIMAX, OPENCLAW) to discover usable LLM access. That credential/config harvesting capability is not obviously required by the stated purpose of producing a Douyin data report from Feishu bitable data.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The manifest describes Douyin publishing, login guarding, data syncing/analysis, next-video generation, digital human training, and Feishu notification. While generating the next video plan is in scope, this file goes further by discovering credentials from general local agent config and environment variables, then using any configured third-party LLM base URL rather than a skill-scoped service. That broad external model-routing capability is not explicitly declared by the manifest and is more expansive than necessary for the stated purpose.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The manifest describes Feishu as a channel for sending reminders to customers, and specifically emphasizes routing user messages through a Feishu text-sending tool. This file also implements inbox-style capabilities: listing messages, retrieving message details, and downloading message resources from Feishu chats, which is a materially broader capability than outbound notification delivery.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The manifest describes a Douyin automation and Feishu-notification skill, but this watcher does more than relay Feishu commands: it directly rewrites local schedule configuration and marketing state after publish completion. That is a material behavior expansion from message watching/routing into persistent automation policy management.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
This file is framed as a Feishu reply watcher for Douyin operations, but it includes process-management logic that kills another server process using pkill. Forcefully terminating local processes is a powerful host-control capability that is not clearly justified by a message-watching/routing role in the manifest text for this specific component.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The manifest describes Douyin publishing, login guard, data analysis, content generation, and digital-human related workflows. In this file, the script proactively loads .env.local/.env.development/.env and later mines ~/.openclaw config for API keys and model endpoints, which is a generic credential/config discovery capability rather than an obvious requirement of collecting persona fields and generating a persona draft.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The manifest mentions generating next-video plans and digital-human related tasks, but this specific script is a local persona-flow tool for collecting fields and producing an IP persona draft. Its code dynamically selects providers and endpoints from user/home configuration and can POST customer persona data to whatever base URL is configured, which is a broader external-network inference capability than the file's stated persona-routing behavior implies.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The manifest says that for Feishu user messaging the skill must actually call douyin__douyin_feishu_route_text, not merely explain a plan. This worker instead uses getFeishuMessage/resolveFeishuConfig/sendFeishuTextChunks from a generic feishu-client and sends notifications directly, which does not match the declared Douyin-specific messaging behavior.

Context-Inappropriate Capability

High
Confidence
96% confidence
Finding
The manifest scope is centered on Douyin publishing, login verification, QR-code/SMS/security handling, analytics, content planning, commenting/DM replies, digital human training/customization, one-click video creation, screenshots, and Feishu alerts. This file instead runs a separate 'persona-flow' job worker for '生成人设', which is a distinct capability not described as part of the Douyin upload/login-guard workflow.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
This module uses bash via spawnSync to probe for installed commands and to enumerate and terminate daemon processes with pgrep/xargs/kill. While browser automation for Douyin is within scope, direct shell execution and host-level process management are broader capabilities not clearly justified by the manifest's stated business functions like publishing, login checks, analysis, messaging, and alerts.

Context-Inappropriate Capability

High
Confidence
94% confidence
Finding
The skill can terminate processes matching src/daemon/server.js and escalate to SIGKILL if shutdown does not complete. That is a strong host-control capability that exceeds what is naturally implied by a Douyin publishing/login/analysis skill, especially since the manifest does not describe local process administration.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The manifest describes Douyin automation workflows such as publishing, login handling, analytics, and Feishu notifications. Returning the browser wsEndpoint together with detailed page information turns this handler into a generic browser introspection/control surface, which is broader than the stated business purpose and could enable external attachment to the browser session.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
Ensuring a browser exists may be an implementation detail for Douyin automation, but exposing its wsEndpoint and process metadata creates a general-purpose browser access capability. That capability is not expressly described in the manifest, which focuses on Douyin publishing, login verification, analytics, content generation, and notifications.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The manifest describes Douyin creator-platform automation such as publishing, login checks, QR handling, verification, analytics, and notifications. Here the code invokes a local Python script via child_process to close browser prompts outside the page/CDP flow, which is an OS-level execution capability not clearly required or declared by that purpose.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The header comment says the module orchestrates operations entirely through CDP and does not inject any objects into the page. However, the implementation calls spawnSync to run close-browser-prompts.py, which is a separate native side-effect path and contradicts the stated '全部通过 CDP 实现' intent.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The header documentation says the operator uses CDP and 'does not inject any objects into the page' and that DOM work is one-shot and leaves no trace. However, L166-L172 directly sets element values and uses dispatchEvent/execCommand within page context, which performs in-page mutation and event synthesis rather than purely external CDP input. This is an active contradiction in the implementation description, not just missing detail.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The manifest describes a skill for Douyin creator-platform publishing, login guarding, verification handling, analytics, comment/DM reply, digital human training, and Feishu notifications. This file instead documents a separate XiaoIce video production service, provider API credentials, callback handling, ngrok exposure, and an MCP tool named `xiaoice_video_produce`, which is a materially different product scope rather than an implementation detail of Douyin automation.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The manifest centers on Douyin publishing, login state management, analytics, content generation, and Feishu messaging. This README adds a separate operational capability for public tunneling of a local service via ngrok so an external XiaoIce provider can reach callback endpoints, which is not an obvious or declared requirement of the stated Douyin workflow.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+2 more)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/agent-ready.js:7

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/background-job.js:117

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/bootstrap-openclaw.js:41

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/digital-human-training-stability.js:138

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/douyin-auto-reply.js:51

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/douyin-login-monitor.js:378

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/douyin-schedule-manager.js:20

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/douyin-skill-supervisor.js:37

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/export-skill-package.js:159

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/feishu-interaction-fallback-stability.js:171

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/feishu-reply-watcher.js:569

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/feishu-route-stability.js:68

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/install-openclaw-skill.js:29

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/marketing-confirmation-mode-stability.js:69

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/marketing-controller.js:375

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/marketing-feishu-flow-stability.js:108

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/marketing-video-job-worker.js:43

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/next-video-plan-job-worker.js:43

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/onboarding-after-persona-worker.js:45

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/openclaw-douyin-health.js:19

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/persona-feishu-messy-stability.js:115

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/persona-generation-job-worker.js:43

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/persona-usage-in-plan-stability.js:174

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/preflight.js:30

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/publish-task.js:32

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/publish-upstream-job-worker.js:47

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/publish-with-guard.js:29

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/run-publish-task-stability.js:32

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/start-lab-daemon.js:34

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/sync-douyin-data-to-feishu-bitable.js:366

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/xiaoice-publish-fields-stability.js:89

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/xiaoice-video-produce.js:294

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/browser.js:43

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/mcp-server.js:487

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
vendor/xiaoice-video-tool/scripts/dev-utils.js:280

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
vendor/xiaoice-video-tool/tests/helpers/ngrok-bootstrap.js:176

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/douyin-comment-reply.js:1708

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/bootstrap-openclaw.js:19

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/digital-human-training.js:5

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/douyin-auto-reply.js:10

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/douyin-data-report-from-bitable.js:7

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/douyin-next-video-plan-from-bitable.js:7

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/douyin-skill-supervisor.js:10

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/feishu-client.js:7

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/openclaw-douyin-health.js:13

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/persona-flow.js:7

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/start-lab-daemon.js:11

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/xiaoice-video-produce.js:9

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/browser.js:62

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
vendor/xiaoice-video-tool/scripts/dev-utils.js:113

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
vendor/xiaoice-video-tool/src/service/server.js:167

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
vendor/xiaoice-video-tool/scripts/dev-ngrok.js:93

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
vendor/xiaoice-video-tool/adapters/openclaw-plugin/openclaw.plugin.json:17

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
vendor/xiaoice-video-tool/tests/fixtures/ngrok-tunnels.multi.json:8

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
vendor/xiaoice-video-tool/tests/fixtures/ngrok-tunnels.single.json:8