Back to skill

Security audit

Douyin Hot Scraper

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Douyin scraping skill, but its browser mode uses an unsafe Chromium configuration and the install steps pull unpinned dependencies.

Review before installing. Use the API-only mode where possible, avoid browser mode unless isolated, and do not run it as a privileged user. Pin and verify Playwright/Chromium before installation, and require explicit Douyin-specific user intent before invoking the scraper.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:42
Finding

Unpinned Playwright and Chromium Installation

Content
View full analysis
Remediation
View remediation
--hash=sha256: ``` 2. Install dependencies with hash enforcement: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 3. Record and verify the expected Chromium revision installed by Playwright. 4. Use a trusted, explicitly configured Python package index and require TLS certificate validation. 5. Commit a reproducible dependency lockfile and use automated dependency scanning. 6. Run installation and browser execution as an unprivileged user in an isolated environment. 7. Document a controlled update process requiring review and integrity verification before dependency versions are changed. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/scraper.py:117
Finding

Chromium Sandbox Explicitly Disabled for Remote Web Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README presents broad natural-language triggers like '搜索一下海鲜视频' and '看看抖音热榜' without defining clear activation boundaries, confirmation requirements, or command parsing constraints. In an agent setting, such examples can cause unintended skill activation from ordinary conversation, leading to unexpected web requests, scraping actions, or data collection when the user did not explicitly intend to invoke the skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises capabilities that can perform outbound network access and write files, but it does not declare any explicit tool scope or permissions boundaries. This creates ambiguity for the host agent and users about what side effects are allowed, increasing the chance of unintended scraping, downloads, or file creation without clear consent or policy enforcement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to 'directly call' the scraper for broad, ordinary-language phrases like '看看抖音热榜' or '帮我搜一下美食'. Because these phrases are common in normal conversation, the skill may trigger browser automation and network requests when a user did not intend to invoke a tool, causing unexpected external access and data collection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The natural-language invocation section encourages automatic execution but does not warn that a request may start browser automation, access third-party sites, or make outbound API calls. This undermines informed user consent and can surprise users with network activity, login-dependent browsing behavior, or file output side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example phrases are very generic everyday requests like '搜一下美食' and '看看抖音热榜', which can cause the skill to activate on broad, ambiguous user input not clearly intended for this specific tool. In an agent environment, this increases the risk of overbroad routing, unintended data fetching, and conflict with other search-capable skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description advertises very broad natural-language triggers such as '搜索一下海鲜视频' and '看看抖音热榜', which can cause the skill to activate on loosely related user messages rather than explicit invocation. In an agent environment, overbroad triggers increase the chance of unintended scraping actions, privacy-impacting requests, or invocation conflicts with other skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring and later CLI/help/output strings are written exclusively in Chinese, indicating the skill is designed to operate in a single language. The policy allows locale constraints only when the user is offered a choice or the restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

All user-facing natural-language examples and instructions are presented only in Chinese, and the skill description states it supports natural-language invocation without indicating any language choice or opt-in. This can violate language/locale policy when a skill implicitly requires a specific language for use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.