Back to skill

Security audit

下载抖音视频到本地文件(免费+无水印)

Security checks for vulnerabilities and agentic risk

Overview

The Douyin downloader mostly does what it says, but it needs Review because weak URL validation can make it contact non-Douyin or internal URLs and downloads have no size limit.

Install only if you are comfortable running a local script that makes outbound web requests and writes video files. Use it only with trusted Douyin links, avoid passing arbitrary short links or untrusted share text, and save output to a dedicated download folder with enough free space.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/douyin_download.py:29
Finding

Insufficient URL Validation Enables Arbitrary Outbound Requests

Content
View full analysis
str: """Extract the first URL from shared text.""" m = re.search(r'https?://[^\s]+', text) if not m: raise ValueError("No valid URL found") return m.group(0) def resolve_short_url(url: str) -> str: """Follow redirects and obtain the final URL.""" req = urllib.request.Request(url, headers={"User-Agent": MOBILE_UA}) try: resp = urllib.request.urlopen(req, timeout=10) return resp.url except urllib.error.HTTPError as e: return e.url or url ``` ```python # Resolve short URLs first. if 'v.douyin.com' in url or len(url) < 50: print(f"[2/4] Resolving short URL...") url = resolve_short_url(url) print(f" Expanded: {url}") else: print(f"[2/4] Skipping short URL resolution") ``` ### Technical Analysis The script extracts any HTTP or HTTPS URL from user-controlled input without validating its hostname or resolved IP address. It then sends a request when either of these weak conditions is satisfied: 1. The URL contains the substring `v.douyin.com`; or 2. The complete URL is shorter than 50 characters. The length condition allows arbitrary short URLs such as `http://127.0.0.1:8000/` to be requested. The substring condition can also be bypassed with attacker-controlled hostnames or URL components containing `v.douyin.com`. `urllib.request.urlopen()` follows HTTP redirects by default, but neither the initial URL nor redirect destinations are checked. Consequently, an attacker-controlled public endpoint can redirect the request to a loopback, private-network, link-local, or cloud metadata address. The response body from this particular request is not exposed to the caller, and later video-ID extraction will generally fail for a non-Douyin URL ...[truncated 1517 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/douyin_download.py:114
Finding

Unbounded Video Download Can Exhaust Local Storage

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents a script that performs outbound network access to douyin.com/iesdouyin.com, but the skill metadata does not declare any tool scope, permissions, or allowed-tools constraints. This creates a transparency and governance gap: an agent or reviewer cannot easily enforce least privilege, and networked behavior can be invoked without explicit declaration or review boundaries.

Content

No source excerpt is available for this finding.

Tainted flow: 'output_path' from urllib.request.urlopen (line 178, network input) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/douyin_download.py (reported line 122)May include surrounding context.

python
print(f"下载地址: {play_url}")
    req = urllib.request.Request(play_url, headers={"User-Agent": MOBILE_UA})

    with urllib.request.urlopen(req, timeout=60) as resp, open(output_path, 'wb') as f:
        total = int(resp.headers.get('Content-Length', 0))
        downloaded = 0
        chunk = 64 * 1024

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language content that effectively forces a specific language for usage, errors, and progress output. Under the policy, language restrictions should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.