Back to skill

Security audit

douyin-to-text

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it runs an unpinned npm CLI that handles a stored API key and video links.

Review before installing. The data flow to Videosays is disclosed, but use a pinned and reviewed `videosays` version or a locked local install, and run it with least privilege because the CLI can access the saved API key and local environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/dytext.sh:7
Finding

Unpinned npm Package Is Downloaded and Executed at Runtime

Content
View full analysis

Vulnerability Details

File Location: scripts/dytext.sh:7
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

Vulnerable Code

bash
#!/bin/bash
# dytext.sh - Videosays compatible Skill script
# Invokes videosays through npx and handles registration, login, and transcription

set -e

exec npx videosays "$@"

Related unpinned commands also appear in SKILL.md:25 and SKILL.md:31-41:

bash
npx videosays setup
npx videosays transcribe "https://v.douyin.com/xxxxx/"
npx videosays transcribe "6.44 ... https://v.douyin.com/xxxxx/" zh-CN
npx videosays balance
npx videosays history

Technical Analysis

The wrapper executes npx videosays without specifying an exact package version. The project contains no lockfile, integrity hash, vendored dependency, or locally reviewed installation that fixes the executable to a known artifact. If the package is not already available locally, npx can retrieve executable code from the npm registry at invocation time.

Consequently, the code executed by the Skill can change after this repository has been audited. A compromised package release, npm maintainer account, or upstream supply-chain component could introduce arbitrary lifecycle or command-line code. The quoted "$@" expansion does not itself create shell injection; the weakness is the mutable executable dependency to which all arguments are delegated.

Attack Path

  1. An attacker compromises the videosays npm package, its maintainer account, or another part of its publication pipeline.
  2. The attacker publishes a malicious version under the package’s legitimate name.
  3. A user or Agent invokes scripts/dytext.sh, or follows one of the documented npx videosays commands.
  4. Because no exact version or integrity value is enforced, npx resolves and may download the affected package version.
  5. The malicious package code executes with the permis ...[truncated 877 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin videosays to a specific, reviewed version rather than resolving the latest available release:

    bash
    npx --yes videosays@1.2.3 "$@"
    

    Replace the example version with an audited release. Version pinning reduces unintended updates but does not independently verify package integrity.

  2. Prefer declaring the package in a package.json, committing a lockfile with registry integrity metadata, and installing dependencies during a controlled setup phase:

    bash
    npm ci --ignore-scripts
    

    Review whether the dependency legitimately requires installation scripts before allowing them.

  3. Invoke only the locally installed, locked executable at runtime, such as:

    bash
    exec npx --no-install videosays "$@"
    

    This prevents runtime package retrieval when the expected dependency is absent.

  4. Review package contents, transitive dependencies, lifecycle scripts, publisher history, and checksums before approving upgrades. Automate dependency alerts while keeping updates subject to review.

  5. Run the Skill with least privilege in a sandbox or container. Restrict filesystem access, environment variables, credential exposure, and outbound network destinations to those required for transcription.

  6. Update every command in SKILL.md and README.md to use the same controlled installation and pinned execution process so users do not bypass the hardened wrapper.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (18)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file’s natural-language instructions and usage guidance are exclusively in Chinese, while the skill advertises support for multiple languages. This can constitute a language/locale policy issue because users are not offered a language choice or informed that the documentation is intentionally Chinese-only.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Using npx videosays without a pinned version causes the latest package version to be fetched and executed at install/use time. If the npm package is compromised, typo-squatted, or a malicious update is published, users may run attacker-controlled code on their local machine with their user privileges and expose stored credentials such as the API key saved under ~/.videosays.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This invocation executes an unpinned npm package via npx, which introduces a supply-chain risk because resolution is not locked to a reviewed release. In the context of first-run setup that stores an API key locally, compromise of the package could immediately capture credentials or run arbitrary code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Documenting npx videosays transcribe ... without a version pin means users may execute whatever version npm currently serves, including a compromised release. Because this skill processes user-supplied video links and communicates with a remote API, arbitrary code execution or silent data exfiltration would be particularly impactful.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

An unpinned npx command allows remote package updates to change the code executed by users without any review gate. In a tool that handles transcription requests and user account state, a malicious package update could alter outputs, steal API keys, or execute local commands.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Running npx videosays balance without a pinned version exposes users to npm supply-chain compromise because the command may fetch and run a newer, unreviewed package. Since this operation likely accesses locally stored account credentials, a malicious package could exfiltrate them or tamper with account-related requests.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This npx usage is vulnerable for the same reason: it executes a package from the registry without version pinning, making users dependent on mutable upstream state. Because the command accesses history data and authenticated context, compromise could expose user activity and credentials.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Referencing the architecture around npx videosays normalizes a mutable execution path where the installed code is not fixed to a reviewed release. That increases the attack surface for supply-chain attacks and is more dangerous here because the skill explicitly states that API keys and video links are sent to a third-party service.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill declares a dependency on npx and elsewhere instructs users to run npx videosays without pinning an exact package version. This causes execution of whatever version is current in the npm registry at runtime, creating a supply-chain risk where a compromised upstream release or dependency could execute arbitrary code on the user's machine and access stored credentials such as the API key in ~/.videosays.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

npx videosays downloads and executes the latest published npm package if it is not already installed locally, but no version is pinned here. In this skill, that risk is amplified because the tool is explicitly entrusted with an API key and sends user-provided video links to a third-party service, so a malicious package update could steal tokens, exfiltrate content, or run arbitrary system commands.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This command asks the agent/user to execute npx videosays transcribe ... without specifying a fixed package version. Because npx may fetch and execute a mutable upstream package at runtime, an attacker who compromises the package or its dependency chain could gain code execution and harvest the API key and transcription inputs handled by this skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The unpinned npx videosays transcribe example for language-specific transcription has the same supply-chain execution issue as the other examples. Since this skill processes potentially sensitive user-submitted links and relies on a locally stored API key, a malicious upstream package release could exfiltrate both data and credentials or execute arbitrary payloads.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

npx videosays balance is also unpinned and can execute a newly fetched package version from npm. Even though this operation is lower sensitivity than transcription, the package still runs locally and may access the saved API key and environment, making arbitrary-code and credential-theft risks real.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The history command uses unpinned npx videosays, which exposes users to the same npm supply-chain risk. Because the command likely accesses account data and stored credentials, a compromised package could enumerate or exfiltrate transcription history as well as the API key.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Another unpinned npx videosays usage appears in the quick-start flow, again allowing execution of a mutable upstream npm artifact. Given the skill's explicit data flow to a third-party API and local credential storage, the context makes this more dangerous than a generic utility because both sensitive inputs and reusable authentication material are present.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The data-flow section states the skill uses npx videosays to call the remote API, confirming that the runtime path depends on an unpinned npm package. This is dangerous because compromise of that package would place attacker-controlled code directly in the path of API key handling and outbound data transmission, enabling silent interception or manipulation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using npx videosays without a pinned version allows resolution of whatever package version is current at execution time, which creates a supply-chain risk. A compromised upstream package, malicious takeover, or unexpected breaking update could cause arbitrary code execution in the environment running the skill, and this skill's purpose of handling external user-provided video links makes routine invocation likely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.