T09 · Insecure Skill Coding Practices
- Location
scripts/douyin_weekly_surge.py:175- Finding
Unsanitized API-Controlled Data Rendered as Trusted Markdown
- Content
View full analysis
Vulnerability Details
File Location:
scripts/douyin_weekly_surge.py, lines 175-181
Vulnerability Type: Markdown injection and unvalidated external URL rendering
Risk Level: MediumVulnerable Code
python work_url = item.get("share_url", "") if work_url: title = f"[{raw_title}]({work_url})" else: title = raw_title author = item.get("user_nickname", "-") cat = item.get("category") or "-"Technical Analysis
The
share_url,user_nickname, andcategoryvalues originate from the remote API response. They are inserted into Markdown output without validating the URL scheme or destination domain and without consistently escaping Markdown and table-control characters.Although
raw_titlereceives limited substitutions earlier in the function, the URL is accepted verbatim, while author and category fields are not escaped. A compromised or malicious API response could therefore:- Supply a phishing or otherwise untrusted destination as
share_url. - Use Markdown metacharacters in the URL to alter the generated link structure.
- Insert pipe characters or line breaks through author or category fields to create fabricated rows, columns, or surrounding content.
- Present injected content as if it were a legitimate ranking result generated by the Skill.
Exploitation requires control over, or compromise of, the configured API response. No evidence shows that ordinary local user input directly controls these response fields.
Attack Path
- An attacker compromises the RedFox API, its upstream data source, or a ranking record returned by that service.
- The attacker places a malicious URL or Markdown/table syntax in
share_url,user_nickname, orcategory. - The Skill retrieves the record over the expected API connection and treats the response fields as trusted.
print_table()interpolates those fields directly into Markdown.- The consuming agent or interface ...[truncated 681 chars]
- Supply a phishing or otherwise untrusted destination as
- Remediation
View remediation
Remediation Suggestions
- Parse each returned URL with a standard URL parser before rendering it.
- Allow only HTTPS URLs and explicitly permit expected Douyin hostnames, such as approved
douyin.comandiesdouyin.comdomains. - Reject URLs containing credentials, unexpected ports, control characters, or disallowed schemes such as
javascript:,data:, andfile:. - Escape Markdown-sensitive characters in link labels and URL destinations.
- Normalize and escape every API-controlled table field, including pipes, carriage returns, line feeds, brackets, backticks, and other formatting characters.
- Replace invalid links with plain text rather than attempting to render them.
- Add tests using malicious URLs, embedded line breaks, pipe characters, closing parentheses, and Markdown link syntax.
- Treat all remote API fields as untrusted even when the API is authenticated, because authentication does not guarantee response integrity at the data-source level.
