Back to skill

Security audit

HotBee 抖音数据采集

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned for Douyin data collection, but it asks the agent to run unaudited remote GitHub code that may receive a local API key.

Review this before installing. Use it only if you trust the GitHub repository and the `smsz.xyz` API operator, and prefer running it in a restricted environment with only `HOTBEE_API_KEY` exposed. Rotate the API key if you suspect it was logged or sent somewhere unintended.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:12
Finding

Automatic Retrieval and Execution of Mutable Remote Code

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:12-16
Additional Locations: references/api.md:40-48
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Code Snippet:

markdown
Use the package CLI:

```bash
npx -y github:shanye1402-hash/hotbee-social-data-skills#v1.1.0 call douyin --text "解析这个视频的播放量和评论 https://v.douyin.com/xxxx/"
text

Additional documented execution examples:

```bash
npx -y github:shanye1402-hash/hotbee-social-data-skills#v1.1.0 call douyin --dry-run --text "解析这个视频的播放量和评论 https://v.douyin.com/xxxx/"
bash
npx -y github:shanye1402-hash/hotbee-social-data-skills#v1.1.0 call douyin --dry-run --text "分析这个达人主页的作品和粉丝画像 https://www.douyin.com/user/xxxx"

Technical Analysis

The skill instructs the agent to use npx -y to retrieve and execute a package directly from an external GitHub repository. The -y option suppresses the interactive installation confirmation. The repository contents and executable implementation are not included in the audited project, so the actual package code, lifecycle scripts, transitive dependencies, and runtime behavior cannot be verified from this artifact.

The reference #v1.1.0 identifies a Git tag rather than an immutable, locally verified artifact. Unless external controls guarantee that the tag cannot be moved and that the downloaded archive is integrity-checked, the effective payload may change after this skill has been reviewed. The remote process also executes in the agent's local security context and may inherit environment variables, including HOTBEE_API_KEY.

Attack Path

  1. An attacker compromises the referenced GitHub account, repository, release process, or a transitive dependency.
  2. The attacker modifies the content resolved by the v1.1.0 reference or causes malicious dependency code to be installed.
  3. A user invokes the skill for a Douyin data request.
  4. The agent runs ...[truncated 836 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not automatically execute code directly from a mutable Git repository.
  • Vendor the CLI source into the reviewed project or distribute it through a controlled registry with an audited release process.
  • Pin the dependency to an immutable commit or content-addressed artifact and verify a trusted cryptographic digest before execution.
  • Generate and verify a lockfile for all transitive dependencies.
  • Disable package lifecycle scripts unless they are explicitly required and audited.
  • Remove -y so unexpected installation requires explicit approval.
  • Execute the CLI in a sandbox with a minimal environment, restricted filesystem access, and outbound-network access limited to approved API domains.
  • Provide HOTBEE_API_KEY only to the subprocess and endpoint that require it rather than exposing the complete parent environment.
  • Audit the referenced CLI and all transitive dependencies before treating this skill as trusted.

T09 · Insecure Skill Coding Practices

Warning
Location
references/api.md:3
Finding

API Key May Be Transmitted in Request Query Parameters

Content
View full analysis

Vulnerability Details

File Location: references/api.md:3-20
Related Control: SKILL.md:9-10
Vulnerability Type: Sensitive credential exposure through request parameters
Risk Level: Medium

Code Snippet:

markdown
Base: `https://www.smsz.xyz/prod-api`

The CLI uses `POST` with request/query parameters for Douyin endpoints.
markdown
| 视频核心数据 | `/tool/douyin/Dy_video_info_VIP` | `url`, `key` | Yes |
| 视频精简信息 | `/tool/douyin/Dy_video_info_VIP2` | `url`, `key` | Yes |
| 视频全部评论 | `/tool/douyin/Dy_video_all_comments_VIP` | `video_url`, `page`, `key` | Yes |
| 达人资料 | `/tool/douyin/Dy_user_profile_VIP` | `userUrl`, `url`, `key` | Yes |
| 达人作品列表 | `/tool/douyin/Dy_user_post_videos_Vip2` | `userUrl`, `url`, `maxCursor`, `key` | Yes |
| 粉丝画像 | `/tool/douyin/Dy_fans_portrai_VIP` | `url`, `key` | Yes |
| 话题详情 | `/tool/douyin/Dy_hashtag_detail_VIP` | `ch_id`, `key` | Yes |
| 话题视频列表 | `/tool/douyin/Dy_hashtag_video_list_VIP` | `ch_id`, `maxCursor`, `sortType`, `key` | Yes |

Related credential-handling instruction:

markdown
Read `HOTBEE_API_KEY` from the local environment only; never echo it or persist it in output. Redact request query parameters from errors.

Technical Analysis

The API contract describes the secret key as an ordinary endpoint parameter and states that the CLI uses request/query parameters. If the credential is placed in the URL query string, TLS protects it in transit but does not prevent disclosure through application access logs, reverse proxies, gateways, monitoring platforms, browser or client histories, exception telemetry, and upstream error reporting.

The instruction to redact query parameters from errors is a useful local safeguard, but it does not control logging performed by the remote server, intermediate infrastructure, or the externally downloaded CLI. Because the CLI implementation was not present in the artifact, the audit could not ve ...[truncated 1053 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove API credentials from URL query parameters.
  • Require an authorization header, such as Authorization: Bearer ..., or another dedicated secret-bearing header supported by the service.
  • If the service contract cannot be changed immediately, place the key in the encrypted POST body rather than the URL and configure all infrastructure to suppress sensitive-body logging.
  • Ensure the CLI never includes credentials in command-line arguments, because process listings and shell histories may expose them.
  • Implement structured redaction for URLs, headers, bodies, stack traces, debug output, and telemetry.
  • Configure reverse proxies, API gateways, and server access logs not to record secrets.
  • Use short-lived, narrowly scoped credentials with rotation and revocation support.
  • Add automated tests that intercept requests and verify that the key never appears in the URL, logs, errors, or standard output.

other

Note
Location
references/api.md:1
Finding

User-Supplied Douyin Identifiers Are Sent to an Insufficiently Disclosed Third-Party Domain

Content
View full analysis

Vulnerability Details

File Location: references/api.md:1-5
Related Locations: SKILL.md:2-3, 7-9, 18-22
Vulnerability Type: Third-party data disclosure
Risk Level: Low

Code Snippet:

markdown
# Douyin API

Base: `https://www.smsz.xyz/prod-api`

The CLI uses `POST` with request/query parameters for Douyin endpoints.

Related branding and operational instructions:

markdown
name: hotbee-douyin-collect
description: Use when a user wants to parse or collect verified Douyin video, comment, creator, fan portrait, or hashtag data through HotBee APIs using Chinese natural-language instructions and Douyin links.
markdown
Only process public Douyin links or public identifiers the user explicitly provides.

Technical Analysis

The skill is presented as a HotBee capability, but its documented API base is the unrelated-looking domain www.smsz.xyz. The audited files do not explain the relationship between this domain and HotBee, identify its operator, or disclose its privacy and retention practices.

Although the skill limits processing to public Douyin links and identifiers explicitly supplied by the user, sending those values to the API also reveals request metadata such as the caller's IP address, timing, requested subject, and usage patterns. Public source data is not equivalent to informed consent for transmission to an insufficiently identified service provider.

Attack Path

  1. A user supplies a public Douyin video, profile, or hashtag identifier to the branded HotBee skill.
  2. The agent invokes the external CLI.
  3. The CLI sends the supplied identifier and request metadata to https://www.smsz.xyz/prod-api.
  4. The operator of that domain, its infrastructure providers, or a party with access to its logs can observe and retain the request.
  5. The observed identifiers and metadata may be correlated with the caller or their activity.

Impact Assessment

...[truncated 430 chars]

Remediation
View remediation

Remediation Suggestions

  • Clearly identify the owner and operator of smsz.xyz and explain its relationship to HotBee.
  • Prefer an official, brand-aligned API hostname with verifiable organizational ownership.
  • Disclose before execution that supplied Douyin identifiers and request metadata will be transmitted to this domain.
  • Link to applicable privacy, retention, and data-processing terms.
  • Obtain explicit user approval before the first third-party request, not only before quota-consuming requests.
  • Minimize submitted data and avoid transmitting unrelated conversation content.
  • Define retention limits and prevent unnecessary request logging.
  • Restrict the CLI's outbound network access to the reviewed API hostname and required Git hosting infrastructure.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description states the skill should be used with Chinese natural-language instructions, which imposes a language constraint. There is no opt-in, alternative language support, or justification that this skill must be Chinese-only, so this appears to violate the language/locale policy.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs use of npx -y github:...#v1.1.0, which pulls and executes remote code directly from a GitHub repository rather than from a tightly controlled, immutable package source. Even with a tag specified, this pattern expands the supply-chain attack surface because the fetched code and its install-time behavior are not locally vetted, and compromise of the repository or ref resolution path could lead to arbitrary code execution in the agent environment, potentially exposing HOTBEE_API_KEY or other local secrets.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language description and default prompt explicitly require processing based on Chinese requests ("通过中文需求解析" / "根据中文需求解析"), which imposes a language constraint. The file does not offer an alternative language option or document that the locale restriction is optional or justified.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.