Back to skill

Security audit

抖音全站数据采集

Security checks for vulnerabilities and agentic risk

Overview

The skill is a mostly disclosed Douyin analytics connector, but it handles login-equivalent Douyin cookies and proxy/device credentials in ways that need careful review before use.

Install only if you trust MaxHub/aconfig.cn with the data you query. Prefer public/read-only endpoints, do not provide a primary Douyin account cookie, avoid sending proxy credentials, use a disposable test account for any cookie-required endpoint, revoke cookies after use, and consider pinning the installer version instead of running an unpinned npx command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
references/api-creator.md:24
Finding

Transmission of Login-Equivalent Session Cookies to a Third-Party API

Content
View full analysis

Vulnerability Details

File Location: references/api-creator.md:24-67
Vulnerability Type: Third-party disclosure of authentication credentials
Risk Level: High

Vulnerable Code Snippet

markdown
## fetch_author_diagnosis

`POST /api/v1/douyin/creator_v2/fetch_author_diagnosis`

This endpoint requires your platform session Cookie, which is a
sensitive credential equivalent to a login session.

Only provide your Cookie if you fully trust the service provider.

Your Cookie/session data will be transmitted to a third-party API
service (`https://www.aconfig.cn`) for processing.

The same behavior is documented for additional endpoints in:

  • references/api-user.md:458-479
  • references/api-video.md:913-934
  • references/api-video.md:968-989
  • references/api-video.md:1028-1049
  • references/api-video.md:1131-1152
  • references/api-video.md:1235-1256
  • references/api-video.md:1348-1369
  • references/api-video.md:1438-1459
  • references/api-video.md:1501-1522
  • references/api-video.md:1609-1630
  • references/api-video.md:1698-1719

Technical Analysis

The Skill instructs the Agent to obtain a user's full Douyin browser-session cookie and forward it to https://www.aconfig.cn. A browser-session cookie is a bearer credential: possession may be sufficient to impersonate the authenticated user until the session expires or is revoked.

This credential has substantially greater authority than the Skill-specific MAXHUB_API_KEY. The Skill's core public-data analytics features do not require possession of a user's full authenticated browser session. Consequently, cookie forwarding exceeds the minimum privileges necessary for most declared functionality.

Security warnings disclose the danger but do not provide technical controls. The Skill does not enforce:

  • Explicit, endpoint-specific confirmation immediately before transmission.
  • Credential scoping or least-privile ...[truncated 1437 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove endpoints that require full browser-session cookies from the default analytics Skill.
  2. Replace browser cookies with narrowly scoped OAuth or API tokens whenever the upstream platform supports them.
  3. Place credential-dependent functionality in a separate, explicitly privileged Skill.
  4. Require informed, endpoint-specific user confirmation immediately before each credential transfer.
  5. Never request credentials through conversational prompts that may be retained in history.
  6. Accept credentials only through a secret-management interface that prevents display and logging.
  7. Redact cookies from application logs, HTTP diagnostics, traces, error messages, and audit output.
  8. Enforce short-lived credentials and provide an immediate revocation procedure.
  9. Block primary-account credentials and clearly require a disposable test account where cookie use remains unavoidable.
  10. Obtain and link independently reviewable privacy, retention, deletion, and incident-response policies for the receiving provider.

T09 · Insecure Skill Coding Practices

Error
Location
references/api-video.md:108
Finding

Sensitive Session Cookies and Proxy Credentials Accepted by GET Endpoints

Content
View full analysis

Vulnerability Details

File Location: references/api-video.md:108-124
Vulnerability Type: Sensitive credential exposure through URL parameters
Risk Level: High

Vulnerable Code Snippet

markdown
## fetch_cartoon_aweme

`GET /api/v1/douyin/web/fetch_cartoon_aweme`

| Parameter | Type   | Required | Description          |
|-----------|--------|----------|----------------------|
| cookie    | string | No       | User provided Cookie |

A related privileged endpoint is documented at references/api-video.md:4147-4170:

markdown
## register_device

`GET /api/v1/douyin/app/v3/register_device`

| Parameter | Type   | Required | Description |
|-----------|--------|----------|-------------|
| proxy     | string | No       | Proxy       |

Proxy credential format: `username:password@ip:port`

Returns device information and device Cookie information.

Technical Analysis

The documented API method is GET while the accepted parameters may contain a full session cookie or authenticated proxy URL. GET parameters are conventionally encoded into the request URL.

Sensitive URL values can be retained by:

  • Shell history and process diagnostics.
  • HTTP client debug output.
  • Reverse-proxy and web-server access logs.
  • Network monitoring and application-performance systems.
  • Error-reporting platforms.
  • Browser history or intermediary caches, depending on the client.
  • Provider-side analytics and telemetry.

TLS protects the URL while it is in transit but does not prevent exposure at either endpoint or in local and server-side logs.

The register_device endpoint also exceeds ordinary read-only analytics scope. It accepts proxy credentials, creates a platform device identity, and returns cookie information. This conflicts with the narrower claim that the Skill performs only read-only data queries.

Attack Path

  1. A user supplies a Douyin session cookie or authenticat ...[truncated 1089 chars]
Remediation
View remediation

Remediation Suggestions

  1. Prohibit all secrets in GET parameters.
  2. Convert credential-bearing endpoints to POST and place sensitive values in the request body.
  3. Mark responses as non-cacheable and disable request-body logging for credential endpoints.
  4. Reject proxy URLs containing embedded usernames or passwords.
  5. Supply proxy credentials through a dedicated secret store rather than user prompts or URLs.
  6. Apply automatic redaction to cookies, authorization values, proxy passwords, tokens, and complete query strings.
  7. Remove register_device from the default analytics Skill or isolate it as an explicitly privileged protocol utility.
  8. Require explicit confirmation before device registration and clearly disclose the returned identity and cookie material.
  9. Add tests that fail when secret parameter names such as cookie, token, password, or authorization appear on GET endpoints.
  10. Align the declared read-only capability with the actual endpoint set.

T08 · Insecure Dependencies

Warning
Location
README.md:17
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: README.md:17-21
Vulnerability Type: Unpinned executable dependency and supply-chain exposure
Risk Level: Medium

Vulnerable Code Snippet

bash
npx clawhub install maxhub-douyin

The equivalent installation instruction also appears in README_CN.md:17-21.

Technical Analysis

The installation command invokes npx without pinning the clawhub package to a specific audited version. Depending on the local package-manager configuration, npx may download and execute the currently resolved registry package.

The effective installer code can therefore change after this Skill artifact has been reviewed. The project does not provide a version constraint, integrity hash, lockfile, verified binary checksum, or immutable source reference for the executed installer.

This is a supply-chain weakness rather than evidence that the current package is itself malicious. Exploitation requires compromise or malicious replacement of the resolved package, release process, registry account, registry infrastructure, or dependency chain.

Attack Path

  1. A user copies the documented installation command.
  2. npx resolves the latest available clawhub package from the configured registry.
  3. An attacker compromises the package, a maintainer account, or one of its executable dependencies.
  4. The malicious release is returned to the user because no audited version or integrity value is pinned.
  5. npx executes the downloaded CLI code with the user's local privileges.
  6. The malicious package accesses files, environment variables, API keys, or other resources available to the installation process.

Impact Assessment

Successful exploitation can provide arbitrary code execution under the account running the installer. Accessible scope may include the user's files, shell environment, OpenClaw configuration, configured API keys, network access, and any other permissions ...[truncated 201 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the installer to a reviewed version, for example npx clawhub@<audited-version> install maxhub-douyin.
  2. Publish and verify package integrity hashes or signed release artifacts.
  3. Document the expected registry and verified package owner.
  4. Use a lockfile or immutable package reference where the installation workflow permits it.
  5. Avoid automatically accepting newly published package versions.
  6. Recommend installation under a non-administrative account in a restricted environment.
  7. Review installer lifecycle scripts and transitive dependencies before updating the pinned version.
  8. Apply the same pinned command to both language versions of the README.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (194)

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
频", "热搜", "视频分析", "用户分析", "创作者", "星图", "抖音指数", "关键词搜索", "评论采集", "直播数据", "话题分析", "舆情监控", "内容营销", "数据采集", "合规", "只读", "数据分析", "合法API"]
    category: productivity
---

# 抖音数据助手

**Get started:** Sign up and get your API key at https://www.aconfig.cn

You are a Douyin Data Assistant. Help users query data via the MaxHub API at https://www.aconfig.cn.

**Data disclaimer:** Data obtained through third-party APIs is for reference only.

**API coverage:** 271 active endpoints **first message** and maintain it throughout the conversation.

| User language | Response language | Number format | Example output |
|---|---|---|---|
| 中文 | 中文 | 万/亿 (e.g. 1.2亿) | "共找到 1,234 条结果" |
| English | English | K/M/B (e.g. 120M) | "Found 1,234 results" |

## API Access

Base URL: `https://www.aconfig.cn`

Use the configured `MAXHUB_API_KEY` value as the `Au

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
> ⚠️ **Capability Classification / 能力分类**
> - **Read-only data queries** (majority): Video details, user profiles, search, trending, analytics — these only retrieve data.
> - **App interaction triggers** ⚠️: `open_*_app_to_*` — these generate deep links that open the platform app. They do NOT directly send messages or perform actions; they only produce URLs the user can choose to open.
> - **Protocol utilities** ⚠️: `generate_*`, `encrypt_*`, `decrypt_*`, `register_device` — these are API compatibility tools for request construction. They do NOT bypass security controls independently.
> - **Cookie-required endpoints** ⚠️: Some endpoints need a user session cookie for personalized data. See Cookie warnings below.
> - **只读数据查询**(大多数):视频详情、用户画像、搜索、热榜、分析——仅获取数据。
> - **应用交互触发** ⚠️:`open_*_app_to_*`——生成打开平台应用的深度链接,不会直接发送消息或执行操作,仅生成用户可选择打开的 URL。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
| 禁止行为 | 正确做法 |
|----------|----------|
| ❌ 自行拼接路径(如 `/api/v1/douyin/search/xxx`) | ✅ 使用 Action Table 或 `<!-- Full path: -->` 中的路径 |
| ❌ 猜测参数名(如把 `aweme_id` 写成 `video_id`) | ✅ 使用 Action Table 或 reference 文件中的参数名 |
| ❌ 假设 v1/v2/v3 参数兼容 | ✅ 降级时重新读取对应版本的参数文档 |
| ❌ 调用 `fetch_hot_search_list` 或 `app/v3/fetch_video_comments` | ✅ 使用替代端点(见废弃标注) |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
| 禁止行为 | 正确做法 |
|----------|----------|
| ❌ 自行拼接路径(如 `/api/v1/douyin/search/xxx`) | ✅ 使用 Action Table 或 `<!-- Full path: -->` 中的路径 |
| ❌ 猜测参数名(如把 `aweme_id` 写成 `video_id`) | ✅ 使用 Action Table 或 reference 文件中的参数名 |
| ❌ 假设 v1/v2/v3 参数兼容 | ✅ 降级时重新读取对应版本的参数文档 |
| ❌ 调用 `fetch_hot_search_list` 或 `app/v3/fetch_video_comments` | ✅ 使用替代端点(见废弃标注) |

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The compliance declaration states the skill performs only read-only data queries and no account actions, yet other sections explicitly include app-interaction triggers and protocol/device operations. This contradiction is dangerous because policy engines, reviewers, or users may rely on the safer statement and authorize behavior they would otherwise restrict.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 330)May include surrounding context.

md
| "analyze" / "分析一下" | Switch to analyze mode |
| "compare with X" / "和X对比" | Add X as second query |

## Output Guidelines

1. **Language consistency** — ALL output matches user's detected language.
2. **Markdown links** — All URLs in `[text](url)` format.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-creator.md (reported line 11)May include surrounding context.

md
`GET /api/v1/douyin/index/fetch_all_area`

<!-- Full path: /api/v1/douyin/index/fetch_all_area -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-creator.md (reported line 180)May include surrounding context.

md
`GET /api/v1/douyin/creator/fetch_creator_material_center_config`

<!-- Full path: /api/v1/douyin/creator/fetch_creator_material_center_config -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-creator.md (reported line 226)May include surrounding context.

md
`GET /api/v1/douyin/creator/fetch_industry_category_config`

<!-- Full path: /api/v1/douyin/creator/fetch_industry_category_config -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-creator.md (reported line 357)May include surrounding context.

md
`POST /api/v1/douyin/creator_v2/fetch_item_analysis_overview`

<!-- Full path: /api/v1/douyin/creator_v2/fetch_item_analysis_overview -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-creator.md (reported line 514)May include surrounding context.

md
`GET /api/v1/douyin/web/fetch_product_review_list`

<!-- Full path: /api/v1/douyin/web/fetch_product_review_list -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-creator.md (reported line 551)May include surrounding context.

md
`GET /api/v1/douyin/xingtu_v2/get_author_base_info`

<!-- Full path: /api/v1/douyin/xingtu_v2/get_author_base_info -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-creator.md (reported line 586)May include surrounding context.

md
`GET /api/v1/douyin/xingtu_v2/get_author_business_card_info`

<!-- Full path: /api/v1/douyin/xingtu_v2/get_author_business_card_info -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-creator.md (reported line 611)May include surrounding context.

md
`GET /api/v1/douyin/xingtu_v2/get_author_local_info`

<!-- Full path: /api/v1/douyin/xingtu_v2/get_author_local_info -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-creator.md (reported line 642)May include surrounding context.

md
`GET /api/v1/douyin/xingtu_v2/get_author_spread_info`

<!-- Full path: /api/v1/douyin/xingtu_v2/get_author_spread_info -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-creator.md (reported line 679)May include surrounding context.

md
`GET /api/v1/douyin/xingtu_v2/get_excellent_case_category_list`

<!-- Full path: /api/v1/douyin/xingtu_v2/get_excellent_case_category_list -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-creator.md (reported line 704)May include surrounding context.

md
`GET /api/v1/douyin/xingtu_v2/get_resource_list`

<!-- Full path: /api/v1/douyin/xingtu_v2/get_resource_list -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-creator.md (reported line 729)May include surrounding context.

md
`GET /api/v1/douyin/xingtu/kol_audience_portrait_v1`

<!-- Full path: /api/v1/douyin/xingtu/kol_audience_portrait_v1 -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-index.md (reported line 11)May include surrounding context.

md
`GET /api/v1/douyin/index/fetch_all_valid_date`

<!-- Full path: /api/v1/douyin/index/fetch_all_valid_date -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-index.md (reported line 62)May include surrounding context.

md
`POST /api/v1/douyin/index/fetch_brand_radar_chart`

<!-- Full path: /api/v1/douyin/index/fetch_brand_radar_chart -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-index.md (reported line 117)May include surrounding context.

md
`POST /api/v1/douyin/index/fetch_portrait`

<!-- Full path: /api/v1/douyin/index/fetch_portrait -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-index.md (reported line 169)May include surrounding context.

md
`GET /api/v1/douyin/xingtu_v2/get_author_market_fields`

<!-- Full path: /api/v1/douyin/xingtu_v2/get_author_market_fields -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-search.md (reported line 11)May include surrounding context.

md
`GET /api/v1/douyin/xingtu/author_content_hot_comment_keywords_v1`

<!-- Full path: /api/v1/douyin/xingtu/author_content_hot_comment_keywords_v1 -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-search.md (reported line 61)May include surrounding context.

md
`POST /api/v1/douyin/index/fetch_brand_suggest`

<!-- Full path: /api/v1/douyin/index/fetch_brand_suggest -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-search.md (reported line 174)May include surrounding context.

md
`POST /api/v1/douyin/search/fetch_challenge_search_v2`

<!-- Full path: /api/v1/douyin/search/fetch_challenge_search_v2 -->

### Parameters

Static analysis

No suspicious patterns detected.