Back to skill

Security audit

抖音热榜 / Douyin Hot

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly fetches Douyin trending data, but it also ships under-described local database/report tools, including an unsafe HTML report path that can run untrusted content in the browser.

Review this before installing if you plan to use the database or HTML reporting scripts. The basic Douyin fetch command is narrow, but the bundled report generator should be treated as unsafe with untrusted remote data until it escapes text, validates links, and avoids innerHTML. The package does not show credential theft, destructive actions, or system persistence, so this is a Review concern rather than a malicious classification.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_html.py:234
Finding

Stored Cross-Site Scripting Through Untrusted Remote Data in Generated HTML

Content
View full analysis
const items = {json.dumps(items, ensure_ascii=False)}; function formatHeat(num) {{ if (num >= 10000) return (num / 10000).toFixed(1) + '万'; return num.toLocaleString(); }} function getRankClass(rank) {{ if (rank === 1) return 'top1'; if (rank === 2) return 'top2'; if (rank === 3) return 'top3'; return 'normal'; }} function renderItems() {{ const dateSelect = document.getElementById('dateSelect').value; const search = document.getElementById('searchInput').value.toLowerCase().trim(); let filtered = items.filter(item => {{ if (dateSelect && item.date !== dateSelect) return false; if (search && !item.title.toLowerCase().includes(search)) return false; return true; }}); document.getElementById('showCount').textContent = filtered.length; const container = document.getElementById('hotList'); if (filtered.length === 0) {{ container.innerHTML = `
🎵
没有找到记录
`; return; }} // 按日期分组 const grouped = {{}}; filtered.forEach(item => {{ if (!grouped[item.date]) grouped[item.date] = []; grouped[item.date].push(item); }}); let html = ''; Object.keys(grouped).sort().reverse().forEach(date => {{ html += grouped[date].map(item => `
Remediation
View remediation
`, and `&`. For example: ```python serialized_items = json.dumps(items, ensure_ascii=False) serialized_items = ( serialized_items .replace("&", "\\u0026") .replace("<", "\\u003c") .replace(">", "\\u003e") ) ``` A safer design is to store JSON in a separate file and load it as data, subject to the same-origin policy and an appropriate Content Security Policy. 4. Validate and normalize remote fields before database insertion. Enforce expected types, maximum lengths, numeric ranges, and an allowlist of permitted URL schemes and hosts. 5. Add a restrictive Content Security Policy. Remove inline scripts where possible and use a separate JavaScript file so that a policy such as the following can be applied: ```html
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

A skill that claims to fetch live Douyin data but instead queries a local SQLite database and exposes undeclared statistics or fetch-log inspection creates a trust-boundary violation. Users may grant or run the skill expecting a simple external data fetch, while the real behavior can reveal local stored data and operational history that were not disclosed, increasing the risk of unintended data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

A skill that claims to fetch live Douyin data but instead queries a local SQLite database and exposes undeclared statistics or fetch-log inspection creates a trust-boundary violation. Users may grant or run the skill expecting a simple external data fetch, while the real behavior can reveal local stored data and operational history that were not disclosed, increasing the risk of unintended data exposure.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
node scripts/douyin.js hot

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
node scripts/douyin.js hot

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
node scripts/douyin.js hot

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
node scripts/douyin.js hot

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The HTML document declares lang="zh-CN", and all visible interface text is presented in Chinese, which imposes a specific language/locale on users. There is no visible opt-in, language selector, or documentation that this page is intentionally limited to a China-specific audience.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a skill for obtaining Douyin hot list/trending data and outputting titles, heat values, and links. This script goes beyond simple data retrieval/output by generating and writing a persistent HTML visualization report to disk, which is an additional reporting capability not stated in the manifest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file’s natural-language interface and user-facing messages are entirely in Chinese, including the tool description, docstrings, usage help, and printed output. This creates a language/locale constraint without any opt-in, alternative language path, or justification that the skill is region-specific, which matches the policy category for forced language behavior.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/save_to_db.py (reported line 25)May include surrounding context.

python
try:
        # 调用Node.js脚本获取数据
        result = subprocess.run(
            ['node', str(node_script), str(limit)],
            capture_output=True,
            text=True,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The request sets Accept-Language to 'zh-CN,zh;q=0.9,en;q=0.8', which imposes a specific language/locale preference in the skill's behavior. The file does not provide user opt-in, configurability, or a documented region-specific justification for this locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The request hard-codes Accept-Language: zh-CN,zh;q=0.9,en;q=0.8, which imposes a specific locale preference. Under the policy, forcing a language or locale without user opt-in can be a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The generated HTML hard-codes lang="zh-CN" and Chinese-only UI text in the document metadata and title. This imposes a specific language/locale in the output without any opt-in, alternative, or justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes a skill for retrieving Douyin hot-list/trending content and outputting titles, heat values, and links. This file also provides a logs command that reads and displays internal fetch execution logs (started_at, found, new, status), which is operational metadata rather than hot-list/trending data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings and documentation in Chinese, and later output is also presented only in Chinese. Under the policy rule for language/locale, forcing a specific language without user opt-in is a violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.