T09 · Insecure Skill Coding Practices
- Location
scripts/douyin_scraper.js:36- Finding
Chromium Browser Sandbox Disabled During Remote Page Processing
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a Douyin scraping helper, but it recommends logged-in browser use and its advertised real scraping paths can return fabricated sample records as if they were collected data.
Review before installing. Use an isolated browser profile or test account instead of your primary logged-in Douyin session, treat outputs as sample data unless live extraction is fixed, avoid running the browser unsandboxed on a sensitive machine, and pin or verify dependencies before installation.
scripts/douyin_scraper.js:36Chromium Browser Sandbox Disabled During Remote Page Processing
requirements.txt:1Mutable Dependency Installation and Unverified Third-Party Browser Mirrors
scripts/scraper.py:77Real Scraping Mode Returns Fabricated Records Without Reliable Provenance Marking
The skill claims natural-language understanding and real Douyin content extraction, but the described implementation appears limited to simple keyword/CLI handling and may not actually parse or extract live platform data. Security-relevant documentation mismatches are dangerous because they obscure the true operational boundaries of the skill and can cause users to trust outputs or permissions that are not warranted.
The skill claims natural-language understanding and real Douyin content extraction, but the described implementation appears limited to simple keyword/CLI handling and may not actually parse or extract live platform data. Security-relevant documentation mismatches are dangerous because they obscure the true operational boundaries of the skill and can cause users to trust outputs or permissions that are not warranted.
Referenced artifact was not completely inspected
node scripts/douyin_scraper.js search "海鲜" 10
Referenced artifact was not completely inspected
node scripts/douyin_scraper.js search "海鲜" 10
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
def mode_native() -> None:
env = os.environ.copy()
env.setdefault("PLAYWRIGHT_DOWNLOAD_HOST", "https://npmmirror.com/mirrors/playwright")
env.setdefault("PLAYWRIGHT_CHROMIUM_DOWNLOAD_HOST", "https://cdn.npmmirror.com/binaries/chrome-for-testing")
venv_python = Path("venv/bin/python")
The README explicitly recommends using a logged-in profile="user" browser session to bypass Douyin anti-bot protections, which causes the automation to operate with the user's authenticated cookies, account context, and potentially broader personal data visibility. In an agent skill context, this is dangerous because the skill may access account-scoped content or trigger actions under the user's identity without a clear consent boundary, privacy warning, or least-privilege guidance.
The skill advertises browser and script-based scraping behavior but does not declare explicit tool scope or permissions, despite requiring shell, environment, and file-writing capabilities. Undeclared capabilities make it harder for users or the platform to understand what the skill may access or modify, increasing the risk of overbroad execution and unintended data exposure.
The auto-activation triggers are broad everyday phrases, which increases the chance the skill will run in contexts where the user did not intend browser automation or scraping activity. Because this skill may invoke logged-in browsing or scripts, overbroad triggering raises the risk of accidental access to account-scoped content and unnecessary execution of sensitive capabilities.
The skill encourages use of browser profile="user" to reuse an existing logged-in Douyin session, but it does not prominently warn that this may access account-scoped data or perform actions in the user's authenticated context. Reusing a live login session materially increases privacy and account-risk exposure, especially if activation is broad or the browser automation is not tightly constrained.
The example triggers are very broad natural-language requests such as searching trending content or arbitrary video links, without any stated guardrails, scope limits, or exclusions. In a browser-automation scraping skill, this can cause the agent to invoke scraping behavior on loosely specified requests, increasing the chance of unauthorized data collection, policy violations, or use beyond the operator’s intended scope.
This shell script presents all user-facing output and usage guidance in Chinese, which effectively forces a specific language on users. The file does not offer an opt-in language choice or explain that the skill is intentionally limited to a Chinese-language audience.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run(cmd: list[str], cwd: str | None = None, env: dict[str, str] | None = None) -> None:
print("\n>>>", " ".join(cmd))
subprocess.run(cmd, cwd=cwd, env=env, check=True)
def mode_official() -> None:
The manifest and file header describe a scraper that obtains Douyin hot-video and text data, but both scraping paths populate hard-coded example fields after merely visiting the page. This means the implemented behavior is generating mock results rather than actually collecting Douyin data, which materially differs from the stated skill purpose.
The getHotVideos path is documented and exposed as fetching Douyin hot-list data, but the code constructs generic records like "热榜视频 1" and invented metrics. That behavior does not satisfy the manifest's promise to scrape real hot-video and copy data.
The script accepts an arbitrary output path from command-line arguments and writes to it with writeFileSync, which will create or overwrite files without confirmation. In an agent or automation context, untrusted or mistaken inputs could clobber important local files or place data in sensitive locations, increasing the risk beyond a normal manual CLI workflow.
The skill advertises scraping Douyin hot-video/copy data, but both live-code paths merely open a page, sleep, and then always return fabricated mock records. This is dangerous because downstream users or agents may trust the output as real collected data, leading to silent integrity failures, bad business decisions, or deceptive automation behavior.
The README is entirely in Chinese and the natural-language examples are only Chinese phrases, with no indication that other languages are supported or that the Chinese-only behavior is a deliberate, documented locale restriction. This can amount to a language policy issue if the skill forces a specific language without user opt-in.
All natural-language instructions and trigger examples are written in Chinese, and the file does not indicate that the skill is region-specific or that users may choose another language. This can amount to a language policy issue if the organization expects skills not to force a specific language without opt-in.
This code writes Dockerfile.generated to disk, which is a file-modifying operation covered by the missing-warning rule for code files. While subprocess commands are printed, there is no user-facing disclosure, prompt, or explanatory comment/docstring warning that the script will create or overwrite a local file.
The dependency is specified with a lower-bound only (playwright>=1.40.0), which allows future major or minor releases to be installed without review. This creates supply-chain and reliability risk because a compromised, vulnerable, or breaking upstream release could be pulled automatically into the skill environment.
playwright>=1.40.0
This code file contains natural-language comments and CLI help text that force a specific language/locale experience. Under the policy, language constraints should either offer user choice or be clearly justified as region-specific; this file provides neither.
The script generates user-visible text and sample data descriptions exclusively in Chinese, and later prints those values to the console. Because there is no option to select another language or explicit documentation that the skill is intentionally Chinese-only, this is a natural-language locale policy concern.
No suspicious patterns detected.