Back to skill

Security audit

抖音账号诊断宗师

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Douyin account-analysis purpose, but it ships and automatically uses a shared RedFox API key while sending account lookup data to RedFox with limited user consent controls.

Review before installing. Use this only if you are comfortable sending queried Douyin nicknames or IDs to RedFox and receiving/displaying returned profile and work metadata. Remove or rotate the embedded default key, require a user-provided REDFOX_API_KEY, avoid passing secrets with --api-key, and add an explicit confirmation step before external lookups.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/douyin_diagnosis.py:27
Finding

Hardcoded Shared API Credential

Content
View full analysis
环境变量 REDFOX_API_KEY > 内置默认密钥""" return cli_key or os.environ.get("REDFOX_API_KEY") or DEFAULT_API_KEY ``` ### Technical Analysis The source contains an operationally formatted RedFox API key and automatically selects it whenever neither a command-line key nor the `REDFOX_API_KEY` environment variable is present. Anyone who can download or inspect the Skill can extract and reuse the credential independently. This also directly contradicts the security guidance in `README.en.md`, which states that keys must not be hardcoded or exposed in source code. Source-repository history and redistributed copies may preserve the credential even after it is removed from the current version. The key is sent to `https://redfox.hk/story/api/dyUser/queryData` through the `X-API-KEY` request header. The audit could not determine the server-side permissions or current validity of the key, so the maximum impact depends on its configured scope. ### Attack Path 1. An attacker downloads the Skill or reads its public source. 2. The attacker extracts `DEFAULT_API_KEY` from `scripts/douyin_diagnosis.py`. 3. The attacker constructs requests to the documented RedFox API endpoint with the extracted value in the `X-API-KEY` header. 4. If the key remains active, the attacker consumes its quota or invokes any other API operations permitted by its server-side scope. 5. Requests may be attributed to the credential owner or the Skill, potentially causing quota exhaustion, service disruption, or unexpected charges. ### Impact Assessment No local operating-system privileges are obtained through this issue. The exposed privilege ...[truncated 373 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/douyin_diagnosis.py:805
Finding

API Secret Accepted Through Command-Line Arguments

Content
View full analysis
2. 使用命令行参数 `--api-key` ``` ### Technical Analysis Passing an API key as `--api-key ` places the secret in the process argument vector before the Python program can remove it from its local `args` list. Depending on the operating system and execution environment, command arguments can be exposed through: - Process inspection utilities and process-monitoring agents - Shell history - CI/CD command logs - Terminal session recording - Job schedulers and orchestration metadata - Crash diagnostics or support bundles Removing the value from the Python list does not erase it from the original process metadata or from logs created before or during process startup. ### Attack Path 1. A user follows the documented usage and launches the script with `--api-key`. 2. The shell records the command, or the runtime exposes the argument vector to local process inspection. 3. A local user, monitoring agent, CI log reader, or support-system operator obtains the argument value. 4. The observer reuses the captured key against RedFox endpoints allowed by that key. 5. If active, the captured key can be used until it expires or is revoked. ### Impact Assessment This issue does not provide direct local privilege escalation. It exposes the remote privileges associated with the user's RedFox API key. Potential impact includes unauthorized API queries, credit or quota consumption, attribution of attacker traffic to the victim, and access to any other operations within the key ...[truncated 121 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/douyin_api_client.py:406
Finding

Partial API Credential Disclosure in Console Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_diagnosis_report.py:390
Finding

Unescaped External API Data Embedded in Markdown Reports

Content
View full analysis
16: create_time = create_time[:16] digg = format_number(w.get("diggCount", 0)) comment = format_number(w.get("commentCount", 0)) share = format_number(w.get("shareCount", 0)) interactive = format_number(w.get("interactiveCount", 0)) digg_count = w.get("diggCount", 0) or 0 share_count = w.get("shareCount", 0) or 0 spread = f"{share_count / digg_count * 100:.1f}%" if digg_count > 0 else "-" # \u524d3\u540d\u7528\u5956\u724c emoji\uff0c\u5176\u4f59\u7528\u6570\u5b57 medal = {1: "\U0001f947", 2: "\U0001f948", 3: "\U0001f949"} rank_display = medal.get(i, str(i)) rows.append(f"| {rank_display} | {create_time} | {title} | {digg} | {comment} | {share} | {interactive} | {spread} |") ``` Related profile fields are also interpolated directly into Markdown in `_section_basic_info`, including nickname, account ID, location, signature, and crawl time. ### Technical Analysis Report fields returned by the external API are treated as trusted strings and inserted directly into Markdown tables and prose. The code truncates the title but does not escape or remove Markdown-sensitive content such as: - Pipe characters that create additional table columns - Newline characters that create new rows or sections - Link and image syntax - Inline HTML accepted by some Markdown renderers - Bidirectional or other control characters An attacker who controls a Douyin profile or cont ...[truncated 1640 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

声明描述的是一个完整的“账号诊断/体检”能力,包含多维度量化评估、总分、风险预警和优化建议。但代码中实际实现的核心能力仅为:1)调用红狐API查询账号资料、作品、相似账号;2)提取基础字段;3)计算少量作品统计;4)打印结果摘要。虽然这与“抖音账号分析”方向相关,且确实使用了红狐数据服务,但缺少声明中最关键的诊断逻辑和输出能力,因此描述明显高于代码实际能力,属于实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

代码的核心用途确实是抖音账号诊断,且数据来源也与声明一致(红狐API数据)。因此不存在完全不同目的或明显越权能力问题。但声明中的关键功能细节与实现存在实质偏差:描述强调六个维度(账号基础画像、内容生产力、互动健康度、内容质量、内容趋势、粉丝质量),而代码明确定义并计算的是四个维度评分体系;描述还承诺‘六类风险预警’,代码仅生成优势、短板和建议,没有结构化的六类风险预警输出。由于这些都是产品核心输出内容而非实现细节,因此应判定为描述与实际行为不一致。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README says users can invoke the skill by simply describing the account they want to diagnose in natural language, without defining narrow activation boundaries. In an agent environment, this can cause over-triggering on ordinary conversation about Douyin accounts, leading to unintended external data retrieval and analysis actions the user did not explicitly request as a tool invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example trigger phrases are broad enough to overlap with normal discussion, especially phrases like evaluating an account or asking to analyze data. In a tool-using agent, ambiguous triggers increase the chance of accidental activation, unnecessary third-party API calls, and processing of potentially sensitive account information without sufficiently explicit user consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly instructs users to invoke the skill with broad, natural-language phrases such as '直接用自然语言说出要诊断的账号即可' and multiple loosely bounded examples. In an agent environment, this increases the chance of over-triggering on ordinary conversation, causing unintended external data lookups or disclosure of third-party account analysis when the user did not clearly intend to run this skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill advertises automatic integration with an external backend and references API keys, but it does not declare any explicit tool scope or permissions despite requiring network access and environment-variable use. This creates a transparency and least-privilege problem: an agent may invoke external requests or access secrets without the user or host platform having a clear, reviewable permission boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Overly broad trigger phrases can cause the skill to activate unexpectedly during ordinary conversation, leading to unintended external lookups or disclosure of queried account identifiers to the backend service. In a skill that contacts third-party services and returns account/work data, accidental invocation increases privacy and consent risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description does not clearly warn that supplied account names/IDs will be sent to an external Redfox service and that returned recent-work details will be displayed. This weakens informed consent and may expose third-party account data, usage patterns, or sensitive competitive-research activity to an external provider without sufficient disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The API reference documents transmission of potentially sensitive account/profile data to an external service and the return of user attributes such as UID, location, gender, age, signature, and recent works, but it provides no user-facing warning, consent guidance, or data-minimization expectations. In the context of an agent skill that analyzes Douyin accounts on demand, this increases the risk of silent third-party data sharing and privacy violations, especially when analyzing accounts belonging to people other than the requesting user.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow explicitly permits fallback to an embedded default API key when no user-supplied key or environment variable is present. Embedding reusable credentials in a distributed skill enables unauthorized use, key leakage through source exposure, abuse of the upstream RedFox account, and makes requests attributable to the skill author rather than the end user. In this context, the skill performs paid external API access, so silent credential substitution is especially risky and unnecessary for least-privilege operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow instructs collection and display of sensitive profile attributes such as UID, region, IP location, gender, age, avatar, and recent content metadata without any user-facing notice, consent check, or minimization step. Even if the data is obtainable from a third-party service, presenting it by default can expose personal information about a target account and creates privacy/compliance risk, especially when the queried account may belong to someone other than the requesting user.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/douyin_api_client.py (reported line 80)May include surrounding context.

python
}

        try:
            response = requests.post(url, json=payload, headers=self.headers, timeout=30)
            result = response.json()

            code = result.get("code")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script sends the queried Douyin nickname/account ID to a third-party RedFox API without any explicit user-facing disclosure or consent step. In this skill context, users may reasonably think they are invoking a local analysis tool, so transmitting identifiers to an external service can create a privacy and data-handling risk, especially for non-public or sensitive account lookups.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill quantifies six dimensions—账号基础画像、内容生产力、互动健康度、内容质量、内容趋势、粉丝质量—and outputs dimension score details plus six categories of risk warnings. This file instead documents and implements a four-dimension scoring model based on 账号体量、内容表现、运营活跃度、平台指数, and the generated report only includes strengths, weaknesses, and optimization suggestions without any six-class risk warning output.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The top-level docstring explicitly states '四维度评估' and the class docstring repeats the same four-dimension framework. That active documentation conflicts with the skill's declared purpose of diagnosing across six dimensions, creating an intent-code divergence between the stated skill scope and the code's own documentation and behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring and the generated report content are written entirely in Chinese, and methods throughout the file hard-code Chinese report labels and narrative text. Because the skill does not offer a language selection or explain that it is intentionally region-specific, it appears to impose a specific language/locale by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The main report assembly calls section generators that all emit fixed Chinese headings, labels, and guidance, producing a single-language experience for all users. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language content in this file is entirely Chinese, and there is no statement that the skill supports multiple languages or that Chinese output is optional. Under SQP-3, forcing a specific language without user opt-in can violate language or locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document is written entirely in Chinese and presents the scoring rules in that single language, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code resolves credentials from CLI, environment, or a built-in default API key, but provides no user-facing warning about which credential source is being used or that a shared embedded key may be involved. This reduces transparency, can cause accidental use of someone else's credentials/quota, and increases the chance of improper key handling or unintentional billing/account exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, and there is no indication that the user opted into that language or that the skill is intentionally limited to a Chinese-language or region-specific context. Under the policy rule, forcing a specific language without opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The disclaimer says the diagnosis is based on works published '上周' and multiple report sections label metrics as '近7天作品'. However, the code simply uses self.data['works'] and len(self.works) throughout scoring and reporting without any date filtering against createTime, so the actual analysis depends entirely on whatever records were supplied.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code performs a filesystem write by creating or overwriting douyin_diagnosis_report_v3.md. Although there is a success message after the write, there is no prior confirmation, warning comment, or disclosure near the operation that the script will modify local files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.