Back to skill

Security audit

doubao-opencli

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real Doubao automation toolkit, but it uses a logged-in browser session, exports sensitive content, and contains unsafe command/browser-eval patterns that need review before installation.

Install only if you are comfortable letting this skill control your logged-in Doubao session and create local plaintext outputs. Avoid using confidential documents, secrets, regulated data, or private chat history until the maintainer pins dependencies, removes Invoke-Expression, safely serializes browser-eval input, isolates downloads per run, and adds clear consent and retention controls for backups and logs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Global npm Dependency Creates a Supply-Chain Execution Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/doubao_ppt_gen.ps1:170
Finding

User-Controlled PPT Content Is Embedded into Executable Browser JavaScript

Content
View full analysis
$null Write-Log " -> 填入 textarea ref [$textareaRef]" "INFO" } else { Write-Log " ⚠️ 找不到 textarea,尝试找 contenteditable div..." "WARN" $ceRef = $null $ceResult = opencli browser find --css "div[contenteditable=true]" 2>$null if ($LASTEXITCODE -eq 0 -and $ceResult) { $ceRef = ($ceResult | Select-String -Pattern "ref=(\d+)" | ForEach-Object { $_.Matches.Groups[1].Value } | Select-Object -First 1) } if ($ceRef) { opencli browser eval "var tb = document.querySelector('div[contenteditable=true]'); if(tb) { tb.textContent = '" + $promptText.Replace("'", "\'") + "'; tb.dispatchEvent(new Event('input', {bubbles:true})); 'filled' }" 2>$null Write-Log " -> 填入 contenteditable ref [$ceRef]" "INFO" ``` ### Technical Analysis The script constructs JavaScript source code by concatenating `$promptText` into a single-quoted JavaScript string and then passes the result to `opencli browser eval`. `$promptText` can contain caller-controlled topic or outline data, as well as the complete contents of a caller-selected draft document. Replacing apostrophes with `\'` is not equivalent to safe JavaScript serialization. It does not correctly handle combinations of backslashes and quotes, JavaScript line terminators, or other syntax-significant sequences. For example, an input containing a backslash immediately before an apostroph ...[truncated 1794 chars]
Remediation
View remediation
{ const value = $jsonPrompt; const ta = document.querySelector('textarea[placeholder]'); if (!ta) return 'not_found'; const setter = Object.getOwnPropertyDescriptor( HTMLTextAreaElement.prototype, 'value' ).set; setter.call(ta, value); ta.dispatchEvent(new Event('input', { bubbles: true })); return 'filled'; })(); "@ opencli browser eval $script ``` 4. Prefer an `opencli` interface that accepts structured arguments separately from evaluated source. 5. Add regression tests containing apostrophes, backslashes, CR/LF characters, Unicode line separators, and JavaScript-like payloads. 6. Treat externally supplied draft files as untrusted input and warn users before transmitting their contents to Doubao. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/doubao_podcast_gen.ps1:404
Finding

Invoke-Expression Enables PowerShell Command Injection through the Output Path

Content
View full analysis
&1" $ffmpegResult = Invoke-Expression $ffmpegCmd ``` ### Technical Analysis The script assembles a complete PowerShell command as text and executes it with `Invoke-Expression`. Both `$outputFile` and `$trimmedFile` are derived from the caller-controlled `OutputDir` parameter. Although the paths are surrounded with double quotes, this does not make reparsing through `Invoke-Expression` safe. PowerShell expressions such as `$()` remain active inside double-quoted strings when the generated command is parsed again. Path characters that are valid at the filesystem level can consequently acquire PowerShell syntax during this second interpretation. The flaw is unnecessary because PowerShell can invoke executables directly while preserving argument boundaries. ### Attack Path 1. An attacker convinces the user or an invoking automation process to pass a crafted `-OutputDir` value containing PowerShell syntax, such as a subexpression. 2. The script uses that directory to construct `$outputFile` and `$trimmedFile`. 3. Those paths are interpolated into `$ffmpegCmd`. 4. `Invoke-Expression` reparses the command text as PowerShell source. 5. Embedded PowerShell expressions execute before or while ffmpeg is invoked. 6. The injected command runs with the privileges of the user executing the Skill. This attack requires control over, or influence on, the script parameters. It is particularly relevant when the script is exposed through another automation layer that accepts externally supplied output paths. ### Impact Assessment Successful exploitation can result in arbi ...[truncated 527 chars]
Remediation
View remediation
&1 ``` 3. Resolve and validate `OutputDir` before use: - Require a filesystem path. - Reject non-filesystem PowerShell providers. - Normalize it to a canonical full path. - Optionally require it to remain under a designated workspace output directory. 4. Validate `TrimSeconds` with an explicit safe range, for example: ```powershell [ValidateRange(0, 3600)] [int]$TrimSeconds = 4 ``` 5. Resolve ffmpeg from a trusted absolute path or verify the executable returned by `Get-Command ffmpeg`. 6. Add tests using paths containing spaces, semicolons, dollar signs, parentheses, backticks, and PowerShell subexpression syntax. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/doubao_podcast_gen.ps1:329
Finding

Ambiguous Downloads-Folder Detection Can Copy Unrelated WAV Files

Content
View full analysis
$null Write-Host " -> JS触发结果: $downloadResult" -ForegroundColor Gray Start-Sleep 3 # 等待下载完成(最多等20秒) $waitDownload = 0 $downloadedFile = $null while ($waitDownload -lt 20) { Start-Sleep 3 $waitDownload += 3 $currentFiles = Get-ChildItem $DownloadsDir -Filter "*.wav" foreach ($f in $currentFiles) { $oldSize = $beforeSnapshot[$f.Name] if (-not $oldSize) { $downloadedFile = $f.FullName Write-Host " -> 检测到新文件: $($f.Name)" -ForegroundColor Gray break } elseif ($f.Length -ne $oldSize -and $f.LastWriteTime ...[truncated 1927 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/doubao_ppt_gen.ps1:403
Finding

PPT Download Detection and Fallback Can Copy an Unrelated Local Presentation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/doubao_image_gen.ps1 (reported line 1)May include surrounding context.

text
<#
.SYNOPSIS
    Doubao CLI Toolkit - based on opencli doubao
.DESCRIPTION

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/doubao_podcast_gen.ps1 (reported line 1)May include surrounding context.

text
<#
.SYNOPSIS
    Doubao CLI Toolkit - based on opencli doubao
.DESCRIPTION

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/doubao_ppt_gen.ps1 (reported line 1)May include surrounding context.

text
<#
.SYNOPSIS
    Doubao CLI Toolkit - based on opencli doubao
.DESCRIPTION

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/doubao_toolkit.ps1 (reported line 1)May include surrounding context.

text
<#
.SYNOPSIS
    Doubao CLI Toolkit - based on opencli doubao
.DESCRIPTION

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly advertises a backup function for all conversations, but the documentation does not warn that this may export sensitive chat history to local storage. Because the skill reuses an already authenticated browser session, users may back up more data than intended, including personal, confidential, or regulated content, increasing privacy and data retention risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The podcast generation feature accepts URLs and PDF files and sends their contents to Doubao for remote processing, but the skill description does not clearly warn users that supplied content leaves the local machine and is disclosed to a third-party service. This can cause unintentional disclosure of proprietary, personal, or regulated information if users assume processing is local automation only.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script sends the user-supplied prompt to doubao.com through browser automation without any explicit notice that the content leaves the local machine and is disclosed to a third-party service. This is risky because users may provide sensitive prompts, credentials, internal data, or regulated content under the assumption that the script is only performing local automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script writes the raw prompt and generated image URLs to timestamped files on disk without explicitly warning the user that their input and output metadata will be persisted locally. This can expose sensitive business data, personal information, or proprietary prompts to other local users, backups, endpoint monitoring tools, or later unintended disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script supports sending user-supplied text, URLs, and PDF files to doubao.com for processing, but it does not present an explicit privacy or consent warning before transmitting potentially sensitive content to a third-party service. In an automation context, users may unintentionally upload confidential documents or internal URLs because the workflow abstracts the transmission behind browser automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script reads the full contents of a user-supplied draft file and injects that content into doubao.com via browser automation, but it does not present an explicit privacy warning or require confirmation before transmitting potentially sensitive local data to a third-party service. In this skill context, that is materially relevant because the script is designed for automation and batch use, making accidental external disclosure of internal documents more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The backup action exports all conversation history and detailed content to a local JSON file without any warning, consent prompt, retention control, or access protection. Because Doubao conversations may contain sensitive prompts, personal data, meeting notes, or proprietary information, this creates a real confidentiality risk if the workstation is shared, compromised, or the output directory is later synced or exfiltrated.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This functionality is intentionally designed to collect all available conversation contents and persist them locally, which materially increases the exposure surface for user data. Even if intended for backup, bulk aggregation of historical chat data into a single file makes accidental disclosure, unauthorized access, or later exfiltration much easier and more damaging.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation describes automatic downloads and moving files into local output directories, but does not clearly warn that running the skill changes the filesystem. While this is expected for a content-generation automation skill, lack of notice can still surprise users, overwrite expectations about disk usage, or create unintended local copies of sensitive generated content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Natural-language user-facing strings, parameter descriptions, and examples are entirely in Chinese, which effectively forces a specific language for use and troubleshooting. The file does not indicate that Chinese is optional, user-selected, or required for a justified region-specific purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code reads from the user's Downloads folder, creates an output directory, copies downloaded files, and later deletes/replaces the original output file during trimming. While these actions are partly visible through progress messages, there is no upfront warning in the documentation that local filesystem contents will be monitored and modified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest and script documentation frame this skill as using opencli browser bridging to automate Doubao features. In addition to browser automation, the code invokes local ffmpeg/ffprobe commands through PowerShell to rewrite downloaded files, which is a separate host-command execution capability not clearly justified by a Doubao CLI/browser skill description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description says the PPTX is automatically saved to Downloads, which implies the download destination behavior. In practice, the script additionally creates an output directory, writes logs there, and copies the downloaded file from Downloads into that directory, which is extra persistence behavior not described in the documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The script automatically triggers a PPTX download to the user's Downloads folder and later copies that file into the configured output directory. While the header describes the behavior, the executable flow performs these file write operations without an explicit runtime warning or confirmation, which may surprise users in automation contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The meeting summary command automatically writes retrieved summary content to disk without notifying the user that potentially sensitive meeting content will be persisted locally. While narrower than full backup, meeting summaries commonly contain confidential business discussions, so silent export still poses a privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Ssd 3

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The batch feature stores raw user questions and model responses together in a plaintext markdown file, effectively creating an audit log of potentially sensitive user inputs. This is a legitimate feature, but without notice or safeguards it can leak private prompts, secrets pasted into questions, or regulated data through local files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.