Back to skill

Security audit

抖音下载器-douyin_downloader

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Douyin downloader that uses a TikHub API token, with some disclosure gaps but no evidence of hidden, destructive, persistent, or unrelated behavior.

Before installing, understand that this skill depends on TikHub: your Douyin modal_id and TikHub bearer token are sent to api.tikhub.io, and downloaded video files may be written to the current directory. Store the token carefully, restrict access to ~/.openclaw/config.json, and invoke the skill only for explicit Douyin download requests.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill description overstates what it does and omits material behavior such as dependence on a third-party API, local token loading, limited link parsing, and the fact that default behavior may return a URL rather than download content. This mismatch can mislead users and reviewers into granting trust or permissions under false assumptions, increasing the risk of unintended data disclosure or unsafe execution paths.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares no explicit tool scope while its documented behavior requires local file reads for config access and network access to a third-party API. In an agent setting, missing scope declarations weakens least-privilege controls and can cause the skill to be invoked with broader capabilities than users or reviewers expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase "帮我下载这个视频" is broad everyday language and can unintentionally activate the skill in contexts where the user did not specifically intend to use this downloader. Over-broad activation is dangerous for a skill with network and file-read behavior because it can cause unexpected third-party requests or credential use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The activation condition "提供modal_id" is ambiguous because a numeric ID could appear in many unrelated conversations or data-processing tasks. In context, this makes accidental invocation more likely and could trigger network requests using stored credentials without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs users to place an API token in a local config file but gives no warning about credential sensitivity, storage risks, or access controls. This encourages insecure secret handling and increases the chance that tokens are exposed to other tools, logs, backups, or over-broad file access within the agent environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/douyin_download.py (reported line 13)May include surrounding context.

python
import re
import sys

TIKHUB_VIDEO_URL = "https://api.tikhub.io/api/v1/douyin/web/fetch_one_video"

def load_config():
    """加载配置文件"""

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script sends a user-provided Douyin identifier together with a bearer token to the third-party TikHub API during normal operation, but it does not clearly warn users that their input and credential will be disclosed to an external service. This is a real privacy and data-handling issue because users may reasonably expect local parsing/downloading behavior from the skill description, while the implementation depends on a remote intermediary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The code accesses ~/.openclaw/config.json and retrieves tikhub_api_token, which is a credential. While the exception message explains how to configure the token if missing, the normal path does not disclose that a local credential will be read and used for outbound requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.