Back to skill

Security audit

Douyin Text Extractor

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent Douyin transcription purpose, but it can download and execute unverified FFmpeg binaries and sends media to external speech services, so users should review it carefully before installing.

Install only if you are comfortable with the skill downloading video content, uploading extracted audio to transcription providers, and running local FFmpeg. Prefer manually installing FFmpeg from a trusted package manager, pinning dependencies, and avoiding private or sensitive videos until the auto-installer, URL validation, referral output, and privacy disclosures are corrected.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
src/douyin_extractor.py:413
Finding

Persistent Referral Advertising Injected into Skill Output

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install_ffmpeg.py:20
Finding

Mutable and Unverified FFmpeg Payload Is Downloaded and Executed

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/install_ffmpeg.py:119
Finding

Unsafe Archive Extraction Permits Path Traversal and Link-Based File Writes

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/douyin_extractor.py:256
Finding

User-Controlled URLs Permit Server-Side Request Forgery

Content
View full analysis
str: """解析短链接重定向""" try: response = self.session.get( share_url, allow_redirects=False ) if response.status_code in [301, 302]: return response.headers.get("Location", share_url) except Exception as e: print(f"解析链接失败:{e}") return share_url def _fetch_video_data(self, url: str) -> Dict: """获取视频页面数据""" headers = { "User-Agent": ( "Mozilla/5.0 (iPhone; CPU iPhone OS 14_0 like Mac OS X) " "AppleWebKit/605.1.15" ), "Accept": ( "text/html,application/xhtml+xml,application/xml;q=0.9," "*/*;q=0.8" ), } response = self.session.get(url, headers=headers) response.raise_for_status() html = response.text json_match = re.search(r'\{.*"aweme_id".*\}', html) if json_match: return json.loads(json_match.group()) raise ValueError("无法解析视频数据,请检查链接是否有效") ``` The MCP implementation also requests the caller-supplied URL before normalizing it: ```python urls = re.findall( r'http[s]?://(?:[a-zA-Z]|[0-9]|[$-_@.&+]|' r'[!*\(\),]|(?:%[0-9a-fA-F][0-9a-fA-F]))+', share_text ) if not urls: raise ValueError("未找到有效的分享链接") share_url = urls[0] try: response = requests.get( share_url, headers=HEADERS, allow_redirects=False ) if response.status_code in [301, 302]: share_url = response.headers.get("Location", share_url) except: pass ``` ### Technical Analysis The code accepts a caller-controlled URL and sends an HTTP request before confirming that the destination belongs to Douyin. In the CLI extractor, an u ...[truncated 1689 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:26
Finding

Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
=3.10", "requests": "*", "ffmpeg-python": "*" } ``` The MCP server also permits runtime resolution without exact versions: ```python mcp = FastMCP( "Douyin MCP Server", dependencies=["requests", "ffmpeg-python", "dashscope"] ) ``` The Skill metadata declares additional unpinned packages: ```json "requirements": { "python": ">=3.10", "system": ["ffmpeg (auto-installable)"], "packages": [ "requests", "ffmpeg-python", "mcp>=1.0.0", "dashscope", "tqdm" ] } ``` ### Technical Analysis Wildcard and unversioned dependency declarations cause installation or runtime environments to resolve whatever package release is current at that time. The project provides no reviewed lock file with cryptographic hashes. This means the code that ultimately runs can change without changes to the audited Skill repository. A compromised package release, malicious transitive dependency, or incompatible future version can therefore affect installation and execution. Runtime dependency resolution in the MCP configuration increases this exposure by potentially resolving packages when the server is launched. ### Attack Path 1. A user installs the Skill or starts the MCP server in an environment that resolves declared dependencies. 2. The package manager queries its configured package index. 3. Because exact versions and hashes are absent, the resolver selects currently available versions and their transitive dependencies. 4. An upstream account compromise, malicious release, or dependency-resolution attack causes an unsafe package version to be selected. 5. Package installation hooks or imported module code exe ...[truncated 558 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (33)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented behavior goes beyond simple Douyin parsing and transcription by describing automatic FFmpeg download, platform detection, archive extraction, permission changes, and local executable installation. Downloading and installing binaries at runtime materially increases supply-chain and local-execution risk, especially when those system-modifying behaviors are not the core expected function of a text-extraction skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented behavior goes beyond simple Douyin parsing and transcription by describing automatic FFmpeg download, platform detection, archive extraction, permission changes, and local executable installation. Downloading and installing binaries at runtime materially increases supply-chain and local-execution risk, especially when those system-modifying behaviors are not the core expected function of a text-extraction skill.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/install_ffmpeg.py (reported line 284)May include surrounding context.

python
# 10. 验证安装
    print("\n🧪 验证安装...")
    test_env = os.environ.copy()
    test_env["PATH"] = str(ffmpeg_bin_dir) + os.pathsep + test_env["PATH"]
    
    try:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README promotes transcript extraction but does not clearly warn that shared Douyin links, downloaded media, extracted audio, and resulting transcript data may be sent to external speech-recognition providers. In this skill context, users may submit copyrighted, private, or regulated content, so the missing disclosure increases the risk of unintended third-party data sharing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README states that the API key 'will not be uploaded to any server', but the tool's documented transcription workflow necessarily sends authenticated requests and media-derived content to external speech-recognition services. This is a misleading security/privacy claim that can cause users to process sensitive content under false assumptions about data exposure and trust boundaries.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documentation exposes capabilities that imply access to environment variables, file read/write, network, and shell execution, but it does not declare any explicit tool scope or permissions boundary. In an agent/MCP context, this makes the effective privilege set opaque to users and reviewers, increasing the chance that the skill can access secrets or modify the local system beyond what users expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly states that FFmpeg will be automatically downloaded and installed on first use, but does not provide a clear warning that this modifies the local system and may execute downloaded software. In a skill intended for agent-driven use, silent system modification is risky because users may trigger it indirectly and may not realize they are allowing software installation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The package description is written entirely in Chinese and does not indicate any user language choice or that the skill is limited to a Chinese-only audience for compliance or regional reasons. Under the stated policy, forcing a specific language or locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains its title, description, prompts, and status messages entirely in Chinese, starting with the module docstring. The policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in, and this file does not offer any alternative language or justify a Chinese-only audience.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The installer downloads archives from external URLs, extracts them, changes permissions, and later executes the resulting binaries, creating a software supply-chain risk. In the context of a text-extraction skill, bundling an auto-installer for third-party executables increases attack surface significantly, especially because mirror URLs use mutable 'latest' release endpoints rather than immutable pinned artifacts.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
87% confidence
Finding

This code executes a freshly downloaded external binary from the local skill directory after download and extraction, but the script does not verify signatures, checksums, or pinned release artifacts before execution. If the download source, mirror, network path, or extracted contents are compromised, the script will grant execute permission and run attacker-controlled code.

Content

Scanner excerpt · scripts/install_ffmpeg.py (reported line 288)May include surrounding context.

python
test_env["PATH"] = str(ffmpeg_bin_dir) + os.pathsep + test_env["PATH"]
    
    try:
        result = subprocess.run(
            [str(ffmpeg_bin_dir / "ffmpeg"), "-version"],
            capture_output=True,
            text=True,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description in L04 is entirely in Chinese, and the environment variable descriptions in L42 and L47 also assume Chinese-language use. For a general-purpose skill manifest, this effectively forces a specific language for users without any stated opt-in or justification, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/install_ffmpeg.py (reported line 63)May include surrounding context.

python
def check_ffmpeg():
    """检查 FFmpeg 是否可用"""
    try:
        result = subprocess.run(
            ["ffmpeg", "-version"],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · src/douyin_extractor.py (reported line 27)May include surrounding context.

python
def check_ffmpeg():
    """检查 FFmpeg 是否可用"""
    try:
        result = subprocess.run(
            ["ffmpeg", "-version"],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · src/mcp_server.py (reported line 32)May include surrounding context.

python
def check_ffmpeg():
    """检查 FFmpeg 是否可用"""
    try:
        result = subprocess.run(
            ["ffmpeg", "-version"],
            capture_output=True,
            text=True,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

A Douyin text extraction tool is not expected to install system software automatically, and doing so materially increases host-side risk. This capability is more dangerous in this context because users may run the skill for simple extraction and not realize it can launch local installation code.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
91% confidence
Finding

The skill can automatically execute a local installer script, which expands its behavior from media processing into code execution on the host. If the repository or scripts/install_ffmpeg.py is modified, replaced, or supplied from an untrusted source, the tool will run arbitrary Python code with the user's privileges.

Content

Scanner excerpt · src/douyin_extractor.py (reported line 59)May include surrounding context.

python
if install_script.exists():
            print("\n🚀 启动 FFmpeg 自动安装...")
            subprocess.run([sys.executable, str(install_script)])
            
            # 验证安装
            installed, version = check_ffmpeg()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/douyin_extractor.py (reported line 92)May include surrounding context.

python
"""抖音文案提取器"""
    
    # 硅基流动 API 配置
    SILICONFLOW_API_URL = "https://api.siliconflow.cn/v1/audio/transcriptions"
    SILICONFLOW_MODEL = "FunAudioLLM/SenseVoiceSmall"
    
    # 邀请码信息

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

During extraction, the workflow can trigger FFmpeg installation logic without prominent advance warning in the primary execution path. Even though there is an interactive prompt, the capability to move from content processing to software installation is security-relevant and easy for users to underestimate.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · src/douyin_extractor.py (reported line 332)May include surrounding context.

python
"-y", str(audio_file)
        ]
        
        subprocess.run(cmd, capture_output=True, check=True)
        return str(audio_file)
    
    def _get_audio_info(self, audio_file: str) -> Tuple[float, int]:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · src/douyin_extractor.py (reported line 403)May include surrounding context.

python
"-y", str(audio_file)
        ]
        
        subprocess.run(cmd, capture_output=True, check=True)
        return str(audio_file)
    
    def _get_audio_info(self, audio_file: str) -> Tuple[float, int]:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · src/douyin_extractor.py (reported line 344)May include surrounding context.

python
audio_file
        ]
        
        result = subprocess.run(cmd, capture_output=True, text=True, check=True)
        duration = float(result.stdout.strip())
        file_size = os.path.getsize(audio_file)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool uploads extracted audio to a third-party transcription API, which transmits potentially sensitive spoken content off-device. This is especially relevant because the skill handles user media and the main workflow does not present a clear consent/privacy warning at the moment of upload.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module docstring and later user-facing guidance/messages are presented only in Chinese, which effectively forces a specific language experience. The file does not indicate that the skill is China-specific only, nor does it offer any opt-in or alternative locale handling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a Douyin text extractor and MCP server for extracting watermark-free video and transcribing speech. This code invokes a local executable via subprocess to inspect FFmpeg, which is a host-level execution capability beyond the core stated purpose and not explicitly declared in the manifest.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
README.md:69

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:98