Back to skill

Security audit

抖音作品查询

Security checks for vulnerabilities and agentic risk

Overview

The skill’s Douyin search function is coherent, but its daily subscription instructions can persist unsafe shell commands built from user keywords.

Install only if you are comfortable sending Douyin search keywords and date filters to Redfox and storing a REDFOX_API_KEY locally. Avoid confirming daily subscriptions until the scheduler command is changed to use structured arguments or safe quoting, and review any created scheduled task so it can be removed later.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:143
Finding

Shell Command Injection Through User-Controlled Subscription Keywords

Content
View full analysis
` - 执行频率:每天 10:00(cron `0 10 * * *`) - 执行命令:`python3 <脚本路径>/search_douyin.py "<关键词>"`(有时间参数则附加 `--start-date`/`--end-date`) - 通用 crontab:`0 10 * * * python3 /path/to/search_douyin.py "<关键词>"` ``` Related execution templates: ```bash python3 ~/.qoderwork/skills/douyin-search/scripts/search_douyin.py "<关键词>" python3 ~/.qoderwork/skills/douyin-search/scripts/search_douyin.py "<关键词>" --start-date --end-date ``` ### Technical Analysis The Skill instructs the Agent to interpolate a user-derived search keyword directly into a shell command and, for subscriptions, into a persistent crontab entry. Enclosing the keyword in double quotes does not make it safe for shell evaluation. Shell command substitution using `$()` or backticks remains active inside double quotes, and an embedded quote can terminate the quoted argument and introduce additional shell operators. The Python script itself does not invoke a shell and safely serializes its received keyword into JSON. The vulnerability arises before Python starts, when the Agent or scheduling platform constructs and executes the documented shell command. The scheduled task is relevant to the declared daily-subscription functionality and requires an explicit confirmation response, so persistence is not inherently unauthorized. Nevertheless, unsafe interpolation allows attacker-controlled shell instructions to be installed persistently. In addition, the supplied Python script only prints JSON and contains no notification-delivery implementation, meaning the documented cron command does not independently fulfill the promised push-notification behavior. ...[truncated 1883 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Promoting 'casual, conversational input' as sufficient for activation increases the chance of unintended tool use, especially because the skill also performs keyword expansion and subscription actions. In an agent environment, vague routing criteria can lead to privacy-impacting or unwanted outbound API calls when a user is only making general conversation or asking for analysis rather than requesting this specific tool.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage guide explicitly says users can invoke the skill with natural-language, non-specific everyday phrasing rather than clear trigger terms. That can cause over-broad activation, where unrelated user requests are mistakenly routed to this skill and external searches or subscriptions are performed without sufficiently clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README says users can 'directly use natural language to say what you want to search' and '无需记忆固定命令', which does not define clear trigger boundaries or exclusion conditions. This broad phrasing overlaps with ordinary conversation and makes it unclear when the skill should activate versus when casual discussion about Douyin content should not invoke it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The sample utterances include broad colloquial phrases such as '帮我看看旅行类在抖音火不火' and '最近搞笑视频挺火的', and the feature list states '口语化输入也能获得有效结果'. These examples encourage activation from common speech but do not provide specificity, allowed contexts, or negative examples to prevent accidental invocation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to use networked functionality and read an API key from environment or local config, but it does not declare an explicit tool/permission scope. That makes the skill harder to sandbox and review, and can allow broader-than-necessary access if the runtime grants default capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include very common terms like ‘搜索’, ‘热门’, and ‘视频’, which can cause the skill to activate in unrelated conversations. Overbroad activation increases the chance of unintended tool execution, external API calls, and unnecessary exposure of user queries to third-party services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The credential setup tells users to store or export an API key but does not warn about shell history, file permissions, shared machines, or secret leakage through logs and process environments. This can lead to accidental disclosure of the REDFOX_API_KEY, enabling unauthorized API usage or account abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script's user-facing description, argument help, and error messages are all written in Chinese, which effectively enforces a single language for interaction. There is no indication that the tool is region-specific or that users may opt into another language, so this appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script sends user-supplied search keywords and optional date filters to a third-party external API, but it does not clearly disclose that transfer to the end user at runtime. This can create a privacy and transparency issue, especially if users enter sensitive topics or proprietary search terms assuming local-only processing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.