T01 · Skill Instruction Hijacking
- Location
scripts/comment_process.py:119- Finding
Prompt injection through untrusted Douyin comment content
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly aligned with Douyin comment automation, but it grants public-reply and local-write authority with weak scoping, incomplete implementation, and unsafe state handling.
Review this skill before installing. It is not clearly malicious, but it can act through a logged-in Douyin creator account, store comment data in a fixed personal vault path, and apply model-produced moderation or reply decisions with weak validation. Use only with a dedicated account, constrained filesystem access, manual approval for replies, and corrected state-validation and retry logic.
scripts/comment_process.py:119Prompt injection through untrusted Douyin comment content
scripts/comment_process.py:220Unvalidated LLM results allow path traversal and safety-policy bypass
scripts/comment_state.py:170Retry handling serializes a function object and can corrupt staged records
This finding indicates the declared two-phase architecture does not match actual implementation, with missing fetch/queue/LLM stages and undeclared write access to a local Obsidian vault. That discrepancy is dangerous because hidden or undocumented persistence locations and altered logic can bypass user expectations, audit controls, and permission review, potentially leading to unauthorized local data modification.
This finding indicates the declared two-phase architecture does not match actual implementation, with missing fetch/queue/LLM stages and undeclared write access to a local Obsidian vault. That discrepancy is dangerous because hidden or undocumented persistence locations and altered logic can bypass user expectations, audit controls, and permission review, potentially leading to unauthorized local data modification.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
4. 不确定的评论选 "review" 而不是 "reply"
"""
return prompt
def apply_llm_results(results: list):
The skill documents file read/write behavior and operational scripts but does not declare any explicit tool scope or permissions boundary. This is dangerous because an agent or reviewer cannot verify what filesystem access is intended, increasing the risk of over-broad local file access, especially given the writes to /tmp and a local Obsidian vault path.
The manifest description and the operational instructions are written as if the skill always operates in Chinese for comment handling and reply generation, including fixed Chinese persona responses and notification content. The policy requires flagging language or locale constraints when a skill forces a specific language without user choice or an explicit documented regional justification.
This code file contains natural-language instructions and outputs that require the skill to operate in Chinese, including the persona description, usage text, and later prompt content. Under the policy rule, forcing a specific language without user choice is a locale/language policy violation.
The documented policy says comments asking for real name, school, or address should go to manual review, but the hard-coded blocklist includes “地址”, causing those comments to be auto-blocked instead. This policy/implementation mismatch can lead to incorrect moderation outcomes, lost legitimate interactions, and bypass of intended human oversight for sensitive-but-ambiguous content.
The manifest frames the skill as a two-phase Douyin comment monitoring and auto-reply workflow using browser fetch and JSON staging, but this file also reads a hard-coded Markdown record file from an external Obsidian vault and migrates its contents into the current state system. That behavior is not an obvious implementation detail of comment fetching and indicates functionality beyond the described fetch/process pipeline.
The module docstring claims the script monitors Douyin creator-center comments and performs automatic replies, but the code only defines local safety/classification helpers and writes records to a local Obsidian markdown file. There is no browser automation, Douyin API interaction, comment retrieval, or reply submission logic anywhere in the file.
The module docstring and core principles require all replies to be written from the perspective of a 5-year-old girl named 琪琪, and all example content is fixed in Chinese. This imposes a specific language/persona behavior without any indication that the user can choose or opt into that locale/style, which matches the policy category for forced language or locale behavior.
The manifest describes 'Fetch + Process', including LLM intelligent classification, safety review, per-comment replies, and a retry queue. In this file, classification is a deterministic keyword scan, safety review is a static blocklist, and records are appended to a markdown file; there is no LLM invocation, JSON staging, or retry-queue handling.
The script persistently stores usernames, raw comment text, video titles, and reply content in a plain markdown file under a fixed local path. This creates a privacy and data-handling risk because personal data is retained without minimization, access control, redaction, or retention limits, and it contradicts the stated rule not to disclose personal information.
This code file contains natural-language text entirely in Chinese in the module docstring and later CLI-facing messages, with no indication that the skill is intentionally limited to Chinese-speaking users. Under the policy, forcing a specific language without user opt-in or clear justification is a locale-policy issue.
The command-line output and usage text are user-facing natural-language strings in Chinese only. Because the file does not offer an alternate language or explain a justified region-specific limitation, this is a natural-language locale policy violation.
The manifest describes comment monitoring and auto-reply, but this fetch phase instructs the browser to collect account overview metrics such as fans, likes, video count, and following, and later persists them via update_account. Those analytics are not necessary to fetch comments or stage replies, so this is broader capability than the stated purpose justifies.
No suspicious patterns detected.