Back to skill

Security audit

抖音七日点赞飙升榜

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Douyin ranking query tool that uses a RedFox API key and network request for its stated purpose, with some install-time cautions around subscriptions and untrusted links.

Install only if you trust RedFoxHub with the REDFOX_API_KEY and the ranking queries you make. Treat generated video links as third-party content, and only enable any recurring subscription or push feature if the host platform clearly shows how it stores preferences and how to cancel it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/douyin_weekly_surge.py:175
Finding

Unsanitized API-Controlled Data Rendered as Trusted Markdown

Content
View full analysis

Vulnerability Details

File Location: scripts/douyin_weekly_surge.py, lines 175-181
Vulnerability Type: Markdown injection and unvalidated external URL rendering
Risk Level: Medium

Vulnerable Code

python
work_url = item.get("share_url", "")
if work_url:
    title = f"[{raw_title}]({work_url})"
else:
    title = raw_title
author = item.get("user_nickname", "-")
cat = item.get("category") or "-"

Technical Analysis

The share_url, user_nickname, and category values originate from the remote API response. They are inserted into Markdown output without validating the URL scheme or destination domain and without consistently escaping Markdown and table-control characters.

Although raw_title receives limited substitutions earlier in the function, the URL is accepted verbatim, while author and category fields are not escaped. A compromised or malicious API response could therefore:

  • Supply a phishing or otherwise untrusted destination as share_url.
  • Use Markdown metacharacters in the URL to alter the generated link structure.
  • Insert pipe characters or line breaks through author or category fields to create fabricated rows, columns, or surrounding content.
  • Present injected content as if it were a legitimate ranking result generated by the Skill.

Exploitation requires control over, or compromise of, the configured API response. No evidence shows that ordinary local user input directly controls these response fields.

Attack Path

  1. An attacker compromises the RedFox API, its upstream data source, or a ranking record returned by that service.
  2. The attacker places a malicious URL or Markdown/table syntax in share_url, user_nickname, or category.
  3. The Skill retrieves the record over the expected API connection and treats the response fields as trusted.
  4. print_table() interpolates those fields directly into Markdown.
  5. The consuming agent or interface ...[truncated 681 chars]
Remediation
View remediation

Remediation Suggestions

  1. Parse each returned URL with a standard URL parser before rendering it.
  2. Allow only HTTPS URLs and explicitly permit expected Douyin hostnames, such as approved douyin.com and iesdouyin.com domains.
  3. Reject URLs containing credentials, unexpected ports, control characters, or disallowed schemes such as javascript:, data:, and file:.
  4. Escape Markdown-sensitive characters in link labels and URL destinations.
  5. Normalize and escape every API-controlled table field, including pipes, carriage returns, line feeds, brackets, backticks, and other formatting characters.
  6. Replace invalid links with plain text rather than attempting to render them.
  7. Add tests using malicious URLs, embedded line breaks, pipe characters, closing parentheses, and Markdown link syntax.
  8. Treat all remote API fields as untrusted even when the API is authenticated, because authentication does not guarantee response integrity at the data-source level.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README says users can 'Simply describe what you need in natural language — no commands to memorize,' which does not define clear activation boundaries or exclusions. For a markdown file, this is an ambiguous trigger description because it suggests very open-ended invocation without specifying required phrasing, scope limits, or negative examples.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README says users can 'directly use natural language to describe needs, no need to remember commands,' but it does not define clear trigger boundaries, exclusions, or a constrained invocation context. This broad phrasing increases the chance that ordinary conversation about Douyin trends could unintentionally invoke the skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs use of environment-sourced credentials and outbound network access to a third-party API, but it does not declare any explicit tool scope or permissions boundaries. This creates a capability/authorization mismatch: an agent runtime may allow broader-than-expected access, making secret handling and external requests less auditable and easier to misuse if the skill is invoked unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description lists activation phrases such as “周度飙升排名” and “周榜飙升,” which are generic enough to match ordinary discussion of weekly rankings rather than a narrowly scoped request for this specific skill. The file does not provide negative examples or clear boundaries for when the skill should not activate, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-config.md (reported line 37)May include surrounding context.

请求示例:

bash
curl -X POST \
  -H "X-API-KEY: $REDFOX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"source": "<见脚本>-ClawHub","type":"美食","startTime":"2026-05-28"}' \

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all user and agent interaction guidance exclusively in Chinese, including headings, prompts, and response templates. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The interaction guide adds a subscription/push workflow that expands the skill from a read-only ranking query tool into a persistent notification service. This scope mismatch can mislead the orchestrating agent or platform into collecting scheduling preferences or creating recurring actions that were not declared, reviewed, or permission-gated in the manifest.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.