Back to skill

Security audit

抖音自动发布

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to automate Douyin publishing as described, but it handles platform credentials and Douyin session files in ways users should review carefully before installing.

Review this skill before installing. Use it only if you trust the EasyClaw/Chanjing platform, understand that it may deduct points and report publish outcomes, and can ensure the platform API URL is HTTPS. Treat CHANJING credentials and Douyin cookie JSON files like passwords, keep them out of shared folders and source control, and rotate any credentials that may have been used over plaintext HTTP.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/platform_client.py:13
Finding

Platform credentials and publishing metadata are transmitted over plaintext HTTP

Content
View full analysis
str: base_url = os.environ.get("CHANJING_PLATFORM_BASE_URL", "").strip() or DEFAULT_PLATFORM_BASE_URL base_url = base_url.rstrip("/") if base_url.endswith("/api"): return base_url return f"{base_url}/api" def default_headers(content_type: str | None = None) -> dict[str, str]: platform_token = os.environ.get("CHANJING_PLATFORM_API_TOKEN", "").strip() if platform_token: headers = {"X-API-Token": platform_token} else: api_key = os.environ.get("CHANJING_PLATFORM_API_KEY", "").strip() api_secret = os.environ.get("CHANJING_PLATFORM_API_SECRET", "").strip() if not api_key or not api_secret: raise PlatformClientError(f"Platform key is not configured. {KEY_SETUP_HINT}") headers = { "X-API-Key": api_key, "X-API-Secret": api_secret, } if content_type: headers["Content-Type"] = content_type return headers ``` ```python def request_json(method: str, path: str, payload: dict | None = None): body = None headers = default_headers() if payload is not None: body = json.dumps(payload, ensure_ascii=False).encode("utf-8") headers["Content-Type"] = "application/json" request = urllib.request.Request( build_url(path), data=body, headers=headers, method=method.upper(), ) try: with urllib.request.urlopen(request) as response: return parse_response(response) ``` ...[truncated 2930 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get_cookie.py:70
Finding

Douyin authentication state is stored without explicitly restrictive filesystem permissions

Content
View full analysis
:"/\\|?*') def resolve_cookie_file(cookie_name: str = "") -> Path: COOKIE_DIR.mkdir(parents=True, exist_ok=True) raw_name = (cookie_name or "").strip() if not raw_name: return DEFAULT_COOKIE_FILE safe_name = "".join( "_" if char in INVALID_COOKIE_NAME_CHARS or ord(char) < 32 else char for char in raw_name ).rstrip(" .") if not safe_name: raise ValueError("Cookie 名称不能为空,且不能只包含非法文件名字符。") return COOKIE_DIR / f"douyin-{safe_name}.json" ``` ```python async def get_douyin_cookie(cookie_file: Path) -> None: # ... async with async_playwright() as playwright: browser = await playwright.chromium.launch(headless=False) context = await browser.new_context() page = await context.new_page() # Login flow omitted await page.pause() await context.storage_state(path=str(cookie_file)) ``` The authenticated state is subsequently rewritten after publication: ```python # 保存更新的 Cookie await context.storage_state(path=str(self.cookie_file)) ``` ### Technical Analysis Playwright storage-state files can contain authentication cookies and other browser-origin state sufficient to reuse an authenticated Douyin session. The code creates the cookie directory and writes the storage-state JSON but does not explicitly apply owner-only permissions to either the directory or file. Effective permissions therefore depend on the host operating system, inherited access control lists, and the user's process umask. On a shared system with permissive defaults, another local account or process may be ab ...[truncated 1356 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/get_cookie.py:11
Finding

Installation guidance uses an unpinned third-party dependency and browser artifact

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill also performs external authorization and result reporting to another platform, plus local logging and cookie-profile management, none of which are clear from the simple publishing description. This is dangerous because hidden reporting and local persistence can expose sensitive usage data and account artifacts beyond what a user expects from a posting utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill also performs external authorization and result reporting to another platform, plus local logging and cookie-profile management, none of which are clear from the simple publishing description. This is dangerous because hidden reporting and local persistence can expose sensitive usage data and account artifacts beyond what a user expects from a posting utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill also performs external authorization and result reporting to another platform, plus local logging and cookie-profile management, none of which are clear from the simple publishing description. This is dangerous because hidden reporting and local persistence can expose sensitive usage data and account artifacts beyond what a user expects from a posting utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill also performs external authorization and result reporting to another platform, plus local logging and cookie-profile management, none of which are clear from the simple publishing description. This is dangerous because hidden reporting and local persistence can expose sensitive usage data and account artifacts beyond what a user expects from a posting utility.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README and skill metadata describe simple Douyin publishing, but the documented flow also contacts an external platform for authorization, deducts user points, and reports execution results. This is a capability mismatch that can mislead users about off-platform data flows and account-impacting actions, increasing the risk of unauthorized charges or disclosure of usage metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states that publish requests are authorized through a remote service, points are deducted, and outcomes are reported back, but it does not clearly warn users that operational metadata and account-related actions will be sent externally. In a local browser automation skill, undisclosed network transmission and billing-related side effects materially increase user risk because the user may assume the process stays local and only interacts with Douyin.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Documenting that direct execution of the publish script still enforces the same external authorization and points flow confirms that the hidden behavior is not limited to a wrapper path. This broadens the mismatch between stated purpose and actual behavior, making it harder for users to avoid unintended billing or external reporting.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documents capabilities that imply shell execution, file writes, network access, and environment-variable use, but it declares no tool scope or permission boundaries. This is dangerous because consumers cannot reliably understand or constrain what the skill may do, increasing the chance of unintended execution, credential exposure, and unauthorized external communication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation does not clearly warn that the skill will perform automated actions on the user's Douyin account, potentially altering account state or published content. This is dangerous because users may run the automation without understanding the account, moderation, or reputational consequences of automated posting.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow states that the skill must use a guarded publishing entry so an external platform can deduct points first, but the manifest presents the tool as simple automated Douyin publishing. This is dangerous because the operational dependency on a third-party authorization/billing flow is materially relevant to user consent and trust.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Requiring external platform API tokens, keys, or secrets for a video-publishing skill introduces sensitive credentials that are not obviously necessary for the core local task. This is dangerous because users may provide high-value secrets to a skill whose stated purpose does not justify that level of access, increasing the blast radius of compromise or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation lists sensitive environment variables for tokens, API keys, and secrets without explicit handling guidance. This is dangerous because it normalizes passing secrets into scripts without warning about leakage through shell history, logs, screenshots, or misconfigured environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language strings in the module docstring and startup messages are entirely in Chinese, and the script does not provide any user opt-in or alternative locale. Under the policy rules, forcing a specific language without choice is a language/locale policy violation unless the regional constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function reads API token, key, and secret values from environment variables and uses them for authentication, but the file provides no user-facing notice, comment, or docstring explaining this credential access. Accessing sensitive credentials is in scope for missing-warning review on code files when there is no visible disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The client sends API requests, including authentication headers, to a default base URL over plain HTTP rather than HTTPS. This exposes platform keys, secrets, and request data to interception or modification by any on-path attacker, enabling credential theft, request tampering, and account compromise. In the context of an automation skill that uploads content to a third-party platform, this is especially dangerous because the credentials can be reused to control publishing operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring and all user-facing messages are written in Chinese, framing the skill as a Chinese-only publishing workflow. Under the policy, language constraints should not be forced without opt-in or a clearly documented justification; this file provides no user choice or explicit region-specific rationale in the text.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/publish_guarded.py (reported line 53)May include surrounding context.

python
command = build_publish_command(args)
    try:
        result = subprocess.run(command, check=False)
    except Exception as exc:  # noqa: BLE001
        print(f"Failed to start local publish: {exc}", file=sys.stderr)
        return 1

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README instructs users to provide Douyin login cookies and platform API credentials but gives no handling guidance or warning that these are sensitive authentication artifacts. Even in documentation, normalizing unsafe treatment of cookies and secrets can lead to leakage through shell history, shared screenshots, copied environment files, or insecure storage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The file name/description are in Chinese while the main instructions are in English, but there is no statement about intended language audience or user choice. This can be a natural-language policy issue when a skill imposes or assumes language behavior without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.