Back to skill

Security audit

抖音账号视频批量下载器

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Douyin downloader, but it explicitly promotes bulk no-watermark copying and reuse of third-party content without adequate authorization or platform-policy guardrails.

Install only if you intend to use it for content you own, are authorized to archive, or otherwise have rights to download and store. Before use, verify the RedFox API key source and revocation options, expect account/video metadata and links to be sent to redfox.hk, and be careful with batch downloads of third-party or no-watermark content.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation guidance tells users to 'just describe what you need in natural language' and provides broad examples like downloading an account's videos, which can cause the agent to trigger on ordinary conversational requests without clear consent or confirmation boundaries. In a skill that fetches and batch-downloads third-party content, overly broad activation increases the chance of unintended collection, parsing, and local storage of external media.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README promotes downloading and storing videos from third-party Douyin accounts locally, including competitor analysis and due diligence use cases, but does not warn users about privacy, copyright, authorization, or platform-terms implications. In this context, omission of a warning materially increases the risk of misuse because the skill is explicitly designed for bulk acquisition of others' content and watermark-free copies.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases in the Agent integration section are broad enough to match ordinary user requests such as '抖音下载' or '帮我下载 xxx 的抖音视频', which can cause the skill to activate unexpectedly. Unintended activation is risky here because the skill performs external API calls and can proceed toward bulk local downloading of third-party content without strong scoping or confirmation barriers.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The top-level description includes many generic trigger terms like '抖音视频下载', '抖音视频保存', and '抖音去水印', making the skill likely to match a wide range of normal user prompts. Because this skill is designed to fetch all works from an account and obtain no-watermark download links, overbroad invocation increases the chance of unintended content extraction and misuse.

Natural-Language Policy Violations

High
Confidence
98% confidence
Finding
The description explicitly promotes uses like '批量搬运素材二次剪辑创作' and obtaining '无水印源文件', which encourage unauthorized copying, republishing, and reuse of third-party content. The skill's core workflow—enumerating all videos for an account and generating no-watermark download links—materially lowers the barrier to copyright infringement and platform policy evasion.

Static analysis

No suspicious patterns detected.