Back to skill

Security audit

douyin-publisher

Security checks for vulnerabilities and agentic risk

Overview

This Douyin publishing skill is mostly purpose-aligned, but it can publish through a saved logged-in browser session and downloads arbitrary video URLs without meaningful safety limits.

Review this before installing if the agent host has access to private networks or valuable Douyin accounts. Use only trusted local video files or trusted HTTPS video URLs, confirm every post carefully, and prefer changes that add URL validation, download size/time limits, cleanup, dependency pinning, and an in-script --confirm gate before publishing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/publish.py:72
Finding

Unrestricted and Unbounded Download of User-Supplied Video URLs

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Playwright and Browser Dependencies

Content
View full analysis
=1.40.0 ``` Installation instructions in `SKILL.md`: ```bash pip install playwright playwright install chromium ``` ### Technical Analysis The requirement specifies only a minimum Playwright version. As a result, installations performed at different times can resolve to different future versions without a new review of this project. The documented `pip install playwright` command is even less restrictive and installs the latest version available from the configured package source. The subsequent `playwright install chromium` command downloads an executable browser artifact selected by the installed Playwright version. Neither the Python package nor the browser artifact is pinned or verified by a project-supplied lockfile or hash. This does not demonstrate that the current Playwright package is malicious. The vulnerability is the absence of reproducible dependency controls: compromise of the package source, publication process, configured index, or a later compatible release could introduce code that executes during installation or when the publishing script imports and launches Playwright. ### Attack Path 1. The dependency source, configured Python package index, Playwright release channel, or a future eligible release is compromised or serves an unsafe artifact. 2. A user follows the documented installation commands or installs `requirements.txt`. 3. The open-ended constraint resolves to the affected Playwright version. 4. `playwright install chromium` retrieves the browser build associated with that version. 5. The package code executes when `scripts/publish.py` imports Playwright, and the downloaded browser executable runs when the persistent browser context is launched. 6. Malicious dependency cod ...[truncated 751 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs the agent to run a publishing script that uses Playwright to access an external website, but the manifest does not declare any explicit tool scope or permissions. This creates a permission-transparency gap: a caller or runtime may not realize the skill performs networked browser automation against Douyin, increasing the risk of unintended external actions and weakening review and policy enforcement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The trigger phrase '发布内容到抖音' is broad and lacks constraints indicating that it should only activate for intentional Douyin publishing requests. Overly broad triggering can cause the skill to activate in ambiguous contexts, which is more sensitive here because the skill can launch a browser, use a persisted login session, and perform real content publication.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes automatic Douyin publishing with video, title, description, and tags, which implies taking provided content and posting it. At L031 the CLI explicitly accepts a video 'path or URL', and L171-L185 implement downloading remote content into a local workspace, adding a content-retrieval capability not stated in the manifest description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The automation clicks the final publish button immediately once fields are filled, with no explicit confirmation gate, dry-run default, or preview verification step. In a publishing skill tied to a logged-in account, this can cause accidental public posting, reputational damage, or posting of incorrect or unauthorized content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The script downloads arbitrary user-supplied URLs to local storage without validating scheme, host, content type, size, or destination safety. This can be abused for unexpected network access, local disk consumption, and retrieval of internal or sensitive resources in environments where the agent has broader network reach than the user.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency is specified with a lower-bound only (playwright>=1.40.0), which allows any newer release to be installed, including unreviewed major or minor versions that may introduce breaking changes or a compromised upstream package. In an automation skill that publishes content to Douyin, Playwright is a high-privilege browser automation dependency, so unexpected dependency changes could affect account actions or reliability.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
playwright>=1.40.0

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language description and user-facing text force a specific language/locale experience, which may violate language-choice policy when no opt-in or justification is provided. Nothing in the file states that the skill is intentionally limited to Chinese-speaking users or a China-specific deployment context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.