T09 · Insecure Skill Coding Practices
- Location
SKILL.md:14- Finding
Shell Command Injection Through Agent-Constructed Search Commands
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a Douyin scraping helper, but it asks agents to turn user text into shell commands and recommends logged-in browser or cookie-based scraping, which needs careful review before use.
Install only if you are comfortable running a browser automation scraper with network access and local file writes. Do not pass cookies or use a logged-in Douyin session unless you understand the account and privacy risks, and invoke the scraper with structured arguments rather than letting an agent build shell strings from free-form user text. Treat output as potentially mock or incomplete unless you verify it came from live page extraction.
SKILL.md:14Shell Command Injection Through Agent-Constructed Search Commands
install_playwright_docker.py:29Unpinned Dependencies and Unverified Browser Downloads From Third-Party Mirrors
The documentation claims real Douyin scraping and extraction, but also states the script may return simulated or hardcoded data and supports export behavior not reflected in the manifest. This mismatch is dangerous because agents and users may trust outputs as real data, make decisions on fabricated results, or grant broader access based on inaccurate capability descriptions.
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
def mode_native() -> None:
env = os.environ.copy()
env.setdefault("PLAYWRIGHT_DOWNLOAD_HOST", "https://npmmirror.com/mirrors/playwright")
env.setdefault("PLAYWRIGHT_CHROMIUM_DOWNLOAD_HOST", "https://cdn.npmmirror.com/binaries/chrome-for-testing")
venv_python = Path("venv/bin/python")
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill instructs the agent to execute shell commands and implies file read/write and environment use, but it declares no explicit tool scope or permissions. That increases the chance of unintended command execution or broader-than-expected access because the agent cannot constrain itself to the minimum required capabilities.
The natural-language activation rules are broad and map common phrases directly into shell command execution with extracted user text as parameters. Overly broad triggers increase the risk of accidental activation, unintended scraping actions, and unsafe command construction paths if later implementations handle quoting or parsing incorrectly.
The example trigger phrases overlap with ordinary conversation, making unintentional invocation more likely in unrelated contexts. In an agent setting, that can cause the skill to launch browser or shell actions without sufficiently explicit user consent or awareness.
The skill says single-video parsing is unsupported, yet later documents authenticated cookie-based access and browser-assisted flows that suggest broader scraping capability than initially stated. This inconsistency can conceal expanded authenticated access paths and makes it harder to assess what data the skill may access or automate.
The documentation explicitly instructs use of logged-in browser sessions and imported cookies to access Douyin, even though the stated purpose is scraping public search and trending data. Handling authenticated sessions and cookies introduces account/session theft, unauthorized access, privacy exposure, and terms-of-service evasion risks that are materially more sensitive than public scraping.
This shell script presents user-facing installation status, errors, and usage instructions entirely in Chinese. The file does not offer any language opt-in or indicate that the skill is intentionally limited to a Chinese-speaking or region-specific audience, which can violate language/locale policy requirements.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run(cmd: list[str], cwd: str | None = None, env: dict[str, str] | None = None) -> None:
print("\n>>>", " ".join(cmd))
subprocess.run(cmd, cwd=cwd, env=env, check=True)
def mode_official() -> None:
The function is presented as performing real Douyin scraping, but it returns fabricated sample records derived from user input instead of page-extracted data. This is dangerous because downstream users or agents may trust the output as authentic market or content intelligence, leading to silent integrity failures, bad decisions, or misuse in automated pipelines.
The hot-list path similarly claims to fetch trending Douyin data but produces invented records rather than scraped content from the site. In a data-collection skill, this undermines output integrity and can poison analytics, reports, or decisions that assume the data reflects the actual platform state.
The module docstring is written as a Chinese-only description, and the rest of the user-facing CLI/help strings in the file are also Chinese-only. This creates a language/locale restriction without any user opt-in or explanation that the skill is intentionally region- or language-specific.
The entire skill documentation is presented only in Chinese, with no indication that users may choose another language or that the locale restriction is required for a region-specific purpose. The policy for this audit flags language or locale constraints when they are imposed without user opt-in or explicit justification.
All example invocations are written only in Chinese, which indicates a language-specific interaction pattern without offering users any language or locale choice. The file provides no justification that the skill is region-specific or limited to Chinese-speaking contexts.
This code creates or overwrites a local file named Dockerfile.generated, which is a file-modifying operation. Although the script prints subprocess commands, there is no comparable user-facing disclosure, comment, or docstring warning that it will write a file into the working directory.
These commands install Python packages and download Chromium using network resources, potentially transmitting environment-derived configuration such as custom download hosts. The script echoes commands, but it does not explicitly warn users in comments, docstrings, or messaging that it will fetch and install external software over the network.
The dependency is specified with a lower-bound only (playwright>=1.40.0), which allows future major or minor releases to be installed without review. This can introduce breaking changes or, more importantly, pull in a compromised or vulnerable upstream version through the supply chain, reducing build reproducibility and making security posture harder to control.
playwright>=1.40.0
The manifest describes searching, fetching hot lists, and extracting video/caption data, but this file also implements persistent export of results to JSON/CSV files via helper functions and CLI options. Local file export is adjacent to scraping, but it is still additional behavior not mentioned in the stated description.
No suspicious patterns detected.