T08 · Insecure Dependencies
- Location
SKILL.md:31- Finding
Unpinned Global npm Dependency Creates a Supply-Chain Execution Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a real Doubao automation toolkit, but it uses a logged-in browser session, exports sensitive content, and contains unsafe command/browser-eval patterns that need review before installation.
Install only if you are comfortable letting this skill control your logged-in Doubao session and create local plaintext outputs. Avoid using confidential documents, secrets, regulated data, or private chat history until the maintainer pins dependencies, removes Invoke-Expression, safely serializes browser-eval input, isolates downloads per run, and adds clear consent and retention controls for backups and logs.
SKILL.md:31Unpinned Global npm Dependency Creates a Supply-Chain Execution Risk
scripts/doubao_ppt_gen.ps1:170User-Controlled PPT Content Is Embedded into Executable Browser JavaScript
scripts/doubao_podcast_gen.ps1:404Invoke-Expression Enables PowerShell Command Injection through the Output Path
scripts/doubao_podcast_gen.ps1:329Ambiguous Downloads-Folder Detection Can Copy Unrelated WAV Files
scripts/doubao_ppt_gen.ps1:403PPT Download Detection and Fallback Can Copy an Unrelated Local Presentation
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<#
.SYNOPSIS
Doubao CLI Toolkit - based on opencli doubao
.DESCRIPTION
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<#
.SYNOPSIS
Doubao CLI Toolkit - based on opencli doubao
.DESCRIPTION
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<#
.SYNOPSIS
Doubao CLI Toolkit - based on opencli doubao
.DESCRIPTION
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<#
.SYNOPSIS
Doubao CLI Toolkit - based on opencli doubao
.DESCRIPTION
The skill explicitly advertises a backup function for all conversations, but the documentation does not warn that this may export sensitive chat history to local storage. Because the skill reuses an already authenticated browser session, users may back up more data than intended, including personal, confidential, or regulated content, increasing privacy and data retention risk.
The podcast generation feature accepts URLs and PDF files and sends their contents to Doubao for remote processing, but the skill description does not clearly warn users that supplied content leaves the local machine and is disclosed to a third-party service. This can cause unintentional disclosure of proprietary, personal, or regulated information if users assume processing is local automation only.
The script sends the user-supplied prompt to doubao.com through browser automation without any explicit notice that the content leaves the local machine and is disclosed to a third-party service. This is risky because users may provide sensitive prompts, credentials, internal data, or regulated content under the assumption that the script is only performing local automation.
The script writes the raw prompt and generated image URLs to timestamped files on disk without explicitly warning the user that their input and output metadata will be persisted locally. This can expose sensitive business data, personal information, or proprietary prompts to other local users, backups, endpoint monitoring tools, or later unintended disclosure.
The script supports sending user-supplied text, URLs, and PDF files to doubao.com for processing, but it does not present an explicit privacy or consent warning before transmitting potentially sensitive content to a third-party service. In an automation context, users may unintentionally upload confidential documents or internal URLs because the workflow abstracts the transmission behind browser automation.
The script reads the full contents of a user-supplied draft file and injects that content into doubao.com via browser automation, but it does not present an explicit privacy warning or require confirmation before transmitting potentially sensitive local data to a third-party service. In this skill context, that is materially relevant because the script is designed for automation and batch use, making accidental external disclosure of internal documents more likely.
The backup action exports all conversation history and detailed content to a local JSON file without any warning, consent prompt, retention control, or access protection. Because Doubao conversations may contain sensitive prompts, personal data, meeting notes, or proprietary information, this creates a real confidentiality risk if the workstation is shared, compromised, or the output directory is later synced or exfiltrated.
This functionality is intentionally designed to collect all available conversation contents and persist them locally, which materially increases the exposure surface for user data. Even if intended for backup, bulk aggregation of historical chat data into a single file makes accidental disclosure, unauthorized access, or later exfiltration much easier and more damaging.
The documentation describes automatic downloads and moving files into local output directories, but does not clearly warn that running the skill changes the filesystem. While this is expected for a content-generation automation skill, lack of notice can still surprise users, overwrite expectations about disk usage, or create unintended local copies of sensitive generated content.
Natural-language user-facing strings, parameter descriptions, and examples are entirely in Chinese, which effectively forces a specific language for use and troubleshooting. The file does not indicate that Chinese is optional, user-selected, or required for a justified region-specific purpose.
This code reads from the user's Downloads folder, creates an output directory, copies downloaded files, and later deletes/replaces the original output file during trimming. While these actions are partly visible through progress messages, there is no upfront warning in the documentation that local filesystem contents will be monitored and modified.
The manifest and script documentation frame this skill as using opencli browser bridging to automate Doubao features. In addition to browser automation, the code invokes local ffmpeg/ffprobe commands through PowerShell to rewrite downloaded files, which is a separate host-command execution capability not clearly justified by a Doubao CLI/browser skill description.
The description says the PPTX is automatically saved to Downloads, which implies the download destination behavior. In practice, the script additionally creates an output directory, writes logs there, and copies the downloaded file from Downloads into that directory, which is extra persistence behavior not described in the documentation.
The script automatically triggers a PPTX download to the user's Downloads folder and later copies that file into the configured output directory. While the header describes the behavior, the executable flow performs these file write operations without an explicit runtime warning or confirmation, which may surprise users in automation contexts.
The meeting summary command automatically writes retrieved summary content to disk without notifying the user that potentially sensitive meeting content will be persisted locally. While narrower than full backup, meeting summaries commonly contain confidential business discussions, so silent export still poses a privacy and data-handling risk.
The batch feature stores raw user questions and model responses together in a plaintext markdown file, effectively creating an audit log of potentially sensitive user inputs. This is a legitimate feature, but without notice or safeguards it can leak private prompts, secrets pasted into questions, or regulated data through local files.
No suspicious patterns detected.