T08 · Insecure Dependencies
- Location
README.md:11- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Feishu workflow for collecting public YouTube/X content, analyzing it, and storing results, with disclosed integration risks but no evidence of deception or harmful behavior.
Before installing, use a dedicated environment, avoid sudo where possible, pin or review yt-dlp versions, and review the Feishu OAuth permissions. Treat configured channel names, usernames, fetched posts, generated analysis, and Feishu records as data that may pass through YouTube, Nitter mirrors, the configured LLM provider, web search, and Feishu. Enable cron only after confirming the target table and data sources are correct.
README.md:11Unpinned Third-Party Dependency Installation
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
### 2. 配置数据源
The README says the system will use AI to analyze scraped YouTube and Twitter content, but it does not clearly warn users that third-party platform content may be transmitted to an external LLM service. This creates a real transparency and data-handling risk because users may unknowingly send content, metadata, or derived records to an external processor with different retention, logging, or compliance characteristics.
The description does not clearly disclose that fetched YouTube/Twitter content and derived analysis may be sent to third-party services, including LLM APIs and possibly public scraping endpoints like nitter.net. This creates privacy, compliance, and data-governance risk because users may not realize external services will receive collected content and metadata.
The description does not clearly disclose that fetched YouTube/Twitter content and derived analysis may be sent to third-party services, including LLM APIs and possibly public scraping endpoints like nitter.net. This creates privacy, compliance, and data-governance risk because users may not realize external services will receive collected content and metadata.
The trigger phrases are short and broad, such as '抓取选题' and '分析选题', without requiring confirmation, namespace prefixes, or explicit target scope. This increases the chance of accidental activation in normal conversation, which could cause unintended scraping, analysis runs, and writes to Feishu tables.
The skill declares a generic exec dependency to run tools like yt-dlp, which introduces command-execution capability beyond narrowly scoped Feishu/topic-analysis operations. If user-controlled source values or future prompt flows are passed into shell commands without strict allowlisting, this can enable arbitrary command execution, SSRF, local file access, or abuse of the agent runtime.
The manifest uses a Chinese-only description and Chinese trigger phrases, with no indication that users can choose another language or that the skill is intentionally restricted to a Chinese-speaking or China-specific environment. This creates a natural-language policy concern because the skill appears to require a specific language/locale by default.
The manifest declares a generic exec capability even though the skill’s stated purpose is topic discovery, web search, and Feishu Bitable updates. Generic command execution greatly expands the attack surface because any prompt-influenced workflow or downstream instruction could invoke arbitrary local commands, enabling data exfiltration, filesystem access, or execution of untrusted binaries.
The script silently contacts third-party Nitter instances and sends the requested username and client metadata without any user-facing disclosure or consent step. In an agent skill context, undisclosed network egress can leak user interests or targets of investigation to external services, which is a real privacy and trust issue even if it is not a code-execution bug.
The script launches an external subprocess to perform the fetch, but the runtime path provides no warning, prompt, or explanatory output that a shell utility will be invoked. For safety auditing, subprocess execution should be disclosed unless it is clearly surfaced to the user through logs, prompts, or surrounding documentation.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
url = f"https://{instance}/{username}"
# 使用 curl 抓取 HTML
result = subprocess.run(
["curl", "-sL", "-A", "Mozilla/5.0", url],
capture_output=True,
text=True,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
]
try:
result = subprocess.run(
cmd,
capture_output=True,
text=True,
The README describes automatic creation of Feishu tables and automatic writing of scraped/analyzed data, but it does not provide a prominent warning about the scope of writes, persistence of collected content, or the possibility of overwriting/replicating data into a shared workspace. In an automation skill that stores external content, lack of clear disclosure can lead to unintended data exposure or governance issues, especially in team-owned Feishu environments.
This YAML file’s human-readable instructions, section headers, and inline comments are presented entirely in Chinese, which imposes a specific language choice on users. Under the policy, language constraints should either offer a user choice or be clearly documented as region-specific and justified; neither is present here.
The file-level description and function docstrings are written in Chinese, which imposes a specific language for user-facing instructions and developer guidance. The file does not offer an opt-in language choice or explain that the tool is intentionally limited to a Chinese-speaking audience.
No suspicious patterns detected.