Back to skill

Security audit

douyin-downloader-pro

Security checks for vulnerabilities and agentic risk

Overview

The skill’s downloader behavior is mostly coherent, but it needs Review because it advises users to place browser session cookies directly into source code.

Install only if you are comfortable with a Python downloader making Douyin and media-host network requests and writing downloaded files to your chosen output path. Do not put long-lived browser cookies into the source file; if authentication is unavoidable, use short-lived credentials, keep them outside version control, remove them after use, and revoke or rotate them if exposed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Note
Location
README.md:12
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: README.md:12-14
Vulnerability Type: Supply-chain dependency risk
Risk Level: Low

bash
pip install requests

Technical Analysis

The installation instructions request the latest package version available under the requests name without a version constraint or integrity hash. This produces non-reproducible installations and leaves future deployments exposed to compromised releases, unexpected transitive dependency changes, or incompatible updates.

No malicious or typosquatted dependency was identified in the audited project. The risk arises from resolving an uncontrolled future package version rather than from a currently confirmed malicious package.

Attack Path

  1. A user follows the documented installation command.
  2. The package installer queries its configured package index.
  3. An uncontrolled current or future version of requests and its transitive dependencies is selected.
  4. If a selected release or configured package index is compromised, malicious package installation or import behavior executes with the privileges of the user running pip.
  5. The malicious dependency could access files, credentials, and network resources available to that user.

Impact Assessment

Successful supply-chain exploitation could execute code with the privileges of the account or environment performing the installation. In a user-level virtual environment, access would generally be limited to that user's accessible files and resources. Running package installation as an administrator would significantly increase the impact. The project itself does not request elevated installation privileges.

Remediation
View remediation

Remediation Suggestions

  • Declare a reviewed, exact dependency version in a dedicated requirements file.
  • Pin all transitive dependencies where reproducible builds are required.
  • Generate and verify cryptographic hashes, then install with pip install --require-hashes -r requirements.txt.
  • Use an isolated virtual environment rather than a global Python installation.
  • Configure trusted package indexes explicitly and avoid unreviewed mirrors.
  • Periodically update pinned versions after vulnerability and compatibility review.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/douyin_dl.py:50
Finding

Authentication Cookies May Be Stored in Source Code

Content
View full analysis

Vulnerability Details

File Location: scripts/douyin_dl.py:50-53; related guidance in SKILL.md:59-61 and README.md:50
Vulnerability Type: Insecure plaintext credential handling
Risk Level: Medium

python
EXTRA_HEADERS: dict[str, str] = {
    # "Cookie": "ttwid=...; sessionid=...",
}

Technical Analysis

The source provides a configuration point for placing authenticated browser cookies directly in the script, while the documentation recommends using it when public requests encounter platform risk controls. A user following that guidance may insert live session credentials into a file inside the Skill or project directory.

Source files are commonly committed to version control, copied into archives, included in support bundles, synchronized to backups, or shared with other users. This makes source code an inappropriate storage location for reusable authentication material. The script does not automatically collect, print, or transmit cookies to unrelated services; the issue is insecure storage and lifecycle management rather than malicious credential exfiltration.

Attack Path

  1. Public metadata retrieval fails because of platform access controls.
  2. The user exports authenticated browser cookies.
  3. Following the documentation, the user inserts those values into EXTRA_HEADERS.
  4. The modified script is committed, backed up, archived, published, or shared.
  5. An unauthorized party reads the embedded cookie values.
  6. If the cookies remain valid and are sufficient for authentication, the party replays them against the corresponding service to impersonate the session.

Impact Assessment

Exposure may permit unauthorized use of the affected Douyin session within the permissions and lifetime granted by the leaked cookies. Depending on the specific cookie values and server-side protections, this could expose account-accessible content or enable actions available to that authenticated se ...[truncated 215 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove instructions that tell users to edit authentication cookies into source code.
  • Accept credentials at runtime through a protected environment variable or a permission-restricted configuration file outside the project directory.
  • Ensure credential files are excluded from version control and backups where appropriate.
  • Validate file ownership and restrictive permissions before loading a credential file.
  • Never print cookie values in logs, exceptions, or diagnostic output.
  • Request only the minimum cookie scope necessary and recommend short-lived credentials.
  • Document session revocation and rotation procedures if accidental disclosure occurs.
  • Prefer a supported authentication mechanism over copied browser cookies whenever the platform provides one.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Natural-language policy issues apply to all file types, and this skill documentation appears to force a specific language without offering the user an alternative or noting that the skill is Chinese-only by design. That can violate language/locale choice expectations when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill clearly instructs the agent to invoke a Python script that performs outbound network access to Douyin-related domains, but the manifest does not declare any tool scope such as allowed-tools or permissions. This creates a governance gap: an agent or reviewer cannot reliably constrain or audit network use from the skill definition, increasing the risk of unintended external requests, data exfiltration, or use in environments with stricter tool policies.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The session is configured to prefer zh-CN for all requests, which imposes a specific locale behavior without offering user opt-in or explaining why it is required. Under the policy, hard-coded language/locale constraints should be user-selectable unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file documents operations that save videos, image sets, and ZIP files to user-specified output paths, but it does not include any warning that the skill will create files and directories on disk. Under the markdown-specific warning rule, behaviors affecting user data or system state should be disclosed to the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This code creates directories and writes downloaded images/videos to disk, including optional ZIP archive creation. While progress is logged, the file does not include a clear user-facing warning in comments or docstrings that running it will persist remote content locally under the chosen output path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.