Back to skill

Security audit

Douyin Comment Reply

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly aligned with Douyin comment automation, but it grants public-reply and local-write authority with weak scoping, incomplete implementation, and unsafe state handling.

Review this skill before installing. It is not clearly malicious, but it can act through a logged-in Douyin creator account, store comment data in a fixed personal vault path, and apply model-produced moderation or reply decisions with weak validation. Use only with a dedicated account, constrained filesystem access, manual approval for replies, and corrected state-validation and retry logic.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
scripts/comment_process.py:119
Finding

Prompt injection through untrusted Douyin comment content

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/comment_process.py:220
Finding

Unvalidated LLM results allow path traversal and safety-policy bypass

Content
View full analysis
bool: fpath = os.path.join(STAGED_DIR, f"{cid}.json") if not os.path.exists(fpath): return False try: with open(fpath, "r", encoding="utf-8") as f: data = json.load(f) data.update(updates) with open(fpath, "w", encoding="utf-8") as f: json.dump(data, f, ensure_ascii=False, indent=2) return True ``` ### Technical Analysis The `apply` command parses JSON from standard input and passes its fields directly into persistent state-management functions. It does not validate that: - The top-level value is a list of valid result objects. - An ID is a 16-character lowercase hexadecimal comment hash. - An ID belongs to the current pending batch. - An action is authorized for that specifi ...[truncated 2221 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/comment_state.py:170
Finding

Retry handling serializes a function object and can corrupt staged records

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

This finding indicates the declared two-phase architecture does not match actual implementation, with missing fetch/queue/LLM stages and undeclared write access to a local Obsidian vault. That discrepancy is dangerous because hidden or undocumented persistence locations and altered logic can bypass user expectations, audit controls, and permission review, potentially leading to unauthorized local data modification.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This finding indicates the declared two-phase architecture does not match actual implementation, with missing fetch/queue/LLM stages and undeclared write access to a local Obsidian vault. That discrepancy is dangerous because hidden or undocumented persistence locations and altered logic can bypass user expectations, audit controls, and permission review, potentially leading to unauthorized local data modification.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/comment_process.py (reported line 191)May include surrounding context.

python
4. 不确定的评论选 "review" 而不是 "reply"
"""

    return prompt


def apply_llm_results(results: list):

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents file read/write behavior and operational scripts but does not declare any explicit tool scope or permissions boundary. This is dangerous because an agent or reviewer cannot verify what filesystem access is intended, increasing the risk of over-broad local file access, especially given the writes to /tmp and a local Obsidian vault path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description and the operational instructions are written as if the skill always operates in Chinese for comment handling and reply generation, including fixed Chinese persona responses and notification content. The policy requires flagging language or locale constraints when a skill forces a specific language without user choice or an explicit documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language instructions and outputs that require the skill to operate in Chinese, including the persona description, usage text, and later prompt content. Under the policy rule, forcing a specific language without user choice is a locale/language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented policy says comments asking for real name, school, or address should go to manual review, but the hard-coded blocklist includes “地址”, causing those comments to be auto-blocked instead. This policy/implementation mismatch can lead to incorrect moderation outcomes, lost legitimate interactions, and bypass of intended human oversight for sensitive-but-ambiguous content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest frames the skill as a two-phase Douyin comment monitoring and auto-reply workflow using browser fetch and JSON staging, but this file also reads a hard-coded Markdown record file from an external Obsidian vault and migrates its contents into the current state system. That behavior is not an obvious implementation detail of comment fetching and indicates functionality beyond the described fetch/process pipeline.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring claims the script monitors Douyin creator-center comments and performs automatic replies, but the code only defines local safety/classification helpers and writes records to a local Obsidian markdown file. There is no browser automation, Douyin API interaction, comment retrieval, or reply submission logic anywhere in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module docstring and core principles require all replies to be written from the perspective of a 5-year-old girl named 琪琪, and all example content is fixed in Chinese. This imposes a specific language/persona behavior without any indication that the user can choose or opt into that locale/style, which matches the policy category for forced language or locale behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes 'Fetch + Process', including LLM intelligent classification, safety review, per-comment replies, and a retry queue. In this file, classification is a deterministic keyword scan, safety review is a static blocklist, and records are appended to a markdown file; there is no LLM invocation, JSON staging, or retry-queue handling.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script persistently stores usernames, raw comment text, video titles, and reply content in a plain markdown file under a fixed local path. This creates a privacy and data-handling risk because personal data is retained without minimization, access control, redaction, or retention limits, and it contradicts the stated rule not to disclose personal information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language text entirely in Chinese in the module docstring and later CLI-facing messages, with no indication that the skill is intentionally limited to Chinese-speaking users. Under the policy, forcing a specific language without user opt-in or clear justification is a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The command-line output and usage text are user-facing natural-language strings in Chinese only. Because the file does not offer an alternate language or explain a justified region-specific limitation, this is a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes comment monitoring and auto-reply, but this fetch phase instructs the browser to collect account overview metrics such as fans, likes, video count, and following, and later persists them via update_account. Those analytics are not necessary to fetch comments or stage replies, so this is broader capability than the stated purpose justifies.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.