T09 · Insecure Skill Coding Practices
- Location
scripts/publish.py:72- Finding
Unrestricted and Unbounded Download of User-Supplied Video URLs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Douyin publishing skill is mostly purpose-aligned, but it can publish through a saved logged-in browser session and downloads arbitrary video URLs without meaningful safety limits.
Review this before installing if the agent host has access to private networks or valuable Douyin accounts. Use only trusted local video files or trusted HTTPS video URLs, confirm every post carefully, and prefer changes that add URL validation, download size/time limits, cleanup, dependency pinning, and an in-script --confirm gate before publishing.
scripts/publish.py:72Unrestricted and Unbounded Download of User-Supplied Video URLs
requirements.txt:1Unpinned Playwright and Browser Dependencies
The skill instructs the agent to run a publishing script that uses Playwright to access an external website, but the manifest does not declare any explicit tool scope or permissions. This creates a permission-transparency gap: a caller or runtime may not realize the skill performs networked browser automation against Douyin, increasing the risk of unintended external actions and weakening review and policy enforcement.
The trigger phrase '发布内容到抖音' is broad and lacks constraints indicating that it should only activate for intentional Douyin publishing requests. Overly broad triggering can cause the skill to activate in ambiguous contexts, which is more sensitive here because the skill can launch a browser, use a persisted login session, and perform real content publication.
The manifest describes automatic Douyin publishing with video, title, description, and tags, which implies taking provided content and posting it. At L031 the CLI explicitly accepts a video 'path or URL', and L171-L185 implement downloading remote content into a local workspace, adding a content-retrieval capability not stated in the manifest description.
The automation clicks the final publish button immediately once fields are filled, with no explicit confirmation gate, dry-run default, or preview verification step. In a publishing skill tied to a logged-in account, this can cause accidental public posting, reputational damage, or posting of incorrect or unauthorized content.
The script downloads arbitrary user-supplied URLs to local storage without validating scheme, host, content type, size, or destination safety. This can be abused for unexpected network access, local disk consumption, and retrieval of internal or sensitive resources in environments where the agent has broader network reach than the user.
The dependency is specified with a lower-bound only (playwright>=1.40.0), which allows any newer release to be installed, including unreviewed major or minor versions that may introduce breaking changes or a compromised upstream package. In an automation skill that publishes content to Douyin, Playwright is a high-privilege browser automation dependency, so unexpected dependency changes could affect account actions or reliability.
playwright>=1.40.0
The natural-language description and user-facing text force a specific language/locale experience, which may violate language-choice policy when no opt-in or justification is provided. Nothing in the file states that the skill is intentionally limited to Chinese-speaking users or a China-specific deployment context.
No suspicious patterns detected.