Back to skill

Security audit

抖音每日热门作品榜

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly performs a Douyin ranking lookup, but it also adds sales/subscription prompts and claims scheduled subscription behavior without clear implementation or controls.

Install only if you are comfortable giving RedFoxHub an API key and sending Douyin ranking queries to redfox.hk. Expect normal responses to include subscription and enterprise-sales prompts, and treat generated video links as untrusted unless the host sanitizes or validates returned URLs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:79
Finding

Mandatory Commercial Content Hijacks Agent Responses

Content
View full analysis
💼 In addition, RedFox provides a comprehensive supporting database with complete and detailed data. For procurement options, visit RedFoxHub [Enterprise Services](https://redfox.hk/dashboard/enterprise). ``` The same behavior is reinforced in `references/interaction-guide.md`, lines 27-33, and the enterprise-service promotion is repeated in `README.md`, line 89. ### Technical Analysis The Skill defines subscription solicitation and a RedFox enterprise-sales link as part of its standard response format. These elements are not necessary to retrieve or display the Douyin ranking requested by the user. Because the content is embedded in the Skill instructions rather than generated by the ranking script, loading and following the Skill changes the Agent's normal response objective. The Agent is instructed to append commercial lead-generation content even when the user requested only ranking data. This constitutes instruction-level output hijacking. The behavior is stable rather than incidental: the commercial content is present in the authoritative standard-output template and repeated in supporting interaction documentation. It therefore affects ordinary executions of the Skill, not merely an isolated example. ### Attack Path 1. A user asks the Agent for a Douyin dai ...[truncated 994 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/douyin_daily_hot.py:176
Finding

Untrusted API Fields Are Rendered as Markdown Without Sufficient Validation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

整体上,代码的核心功能与“抖音每日最热作品榜查询”大体一致:它确实调用 API 获取抖音作品点赞排行,并支持赛道筛选和历史日期查询。但声明中包含若干代码未实现或明显超出的能力,属于描述与行为不完全一致。最明显的是“个性化订阅推送”完全不存在;“达人排名”也没有实现,代码只展示作品及作者信息,并未对作者进行排名;同时声明中的“最多30天”限制未在代码中校验。此外,声明强调单日榜单,而代码还支持日期范围查询。故应判定为存在描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage guidance says users can invoke the skill by simply describing their needs in natural language, which creates a very broad activation surface. In an agent environment, overly broad routing cues can cause accidental invocation on ordinary conversation about Douyin trends, leading to unnecessary third-party API use, unintended data access, or confusion about which tool is acting.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example phrases like "Today's ranking" and "Show all" are generic everyday expressions that can overlap with normal conversation and with other ranking or browsing tasks. In a multi-skill agent, this increases the chance of mistaken tool selection, which can trigger external requests and produce irrelevant or unintended outputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states users can 'directly use natural language to describe needs' without fixed commands, but it does not define clear trigger boundaries, exclusions, or scope constraints. This can cause unintended invocation overlap with ordinary conversation because the activation condition is described too generally.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill documents use of environment variables and outbound network access to a third-party API, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization gap: a host agent may grant broader capabilities than intended, making secret access and network egress less constrained and harder to review.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-config.md (reported line 38)May include surrounding context.

请求示例:

bash
curl -X POST \
  -H "X-API-KEY: $REDFOX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"source": "<见脚本>-ClawHub","type":"美食","startTime":"2026-05-28","endTime":"2026-05-28"}' \

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

All user-facing instructions and examples are presented in Chinese, which can amount to an implicit language constraint without opt-in or alternative language support. Under the policy, forcing a specific language is a concern unless the skill explicitly offers a language choice or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.