Back to skill

Security audit

抖音每日热门作品榜

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says for Douyin ranking lookup, but it advertises recurring subscription push behavior and renders remote data as clickable Markdown without enough scoping or safeguards.

Install only if you trust RedFox with the API key and are comfortable with outbound ranking lookups. Treat subscription/push claims as under-specified until the publisher documents explicit opt-in, cancellation, storage, and scheduler behavior, and be cautious with clickable links returned from the API.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/douyin_daily_hot.py:176
Finding

Untrusted API Response Fields Rendered as Active Markdown

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill description promises capabilities that are not implemented or enforced, including subscription/push delivery, a 30-day historical limit, and '达人排名' despite only describing a work-like ranking query. These mismatches are dangerous because they can mislead users and orchestrators about data handling and safety boundaries, causing over-trust, incorrect automation decisions, or unbounded parameter use against the backend service.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README encourages invocation through very broad natural-language phrases such as 'Today's ranking' and 'Show all', which are common conversational expressions not uniquely tied to this skill. In agent environments that auto-route based on user utterances, this can cause unintended activation and data access or external API usage when the user did not explicitly intend to use this tool.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs users to 'directly use natural language' without defining a constrained invocation pattern, which increases the chance of accidental activation from ordinary conversation. In an agent environment, broad activation can cause the skill to run when the user did not clearly intend to query this external data source, leading to unnecessary outbound requests or context confusion.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example trigger phrases are short, generic expressions like '今日榜单' and '看看美食赛道' that overlap with normal user speech. In a multi-skill agent, these common phrases can spuriously trigger this skill instead of a safer or more appropriate response path, creating unintended tool use and possible data leakage through external API calls.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs use of an environment-sourced API key and outbound network access to a third-party endpoint, but does not declare any explicit tool scope or permissions. This creates a least-privilege and transparency gap: hosts or reviewers cannot reliably constrain what capabilities the skill needs, increasing the risk of unintended secret exposure or unauthorized external requests if the skill is executed in a permissive runtime.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-config.md (reported line 38)May include surrounding context.

请求示例:

bash
curl -X POST \
  -H "X-API-KEY: $REDFOX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"source": "<见脚本>-ClawHub","type":"美食","startTime":"2026-05-28","endTime":"2026-05-28"}' \

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file instructs users to configure REDFOX_API_KEY and shows it being sent in an HTTP header, but it does not include any caution about keeping the key secret or avoiding exposure in shared terminals, logs, or screenshots. For markdown files, network behavior and credential use should include a brief warning when they may affect privacy or security.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill introduces a recurring subscription/push feature without clearly disclosing that notifications will continue automatically or what user data and preferences will be stored to support that behavior. While this is not a code-execution issue, it is a real consent and transparency weakness that can lead to unexpected ongoing messaging and privacy complaints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide specifies a default daily 06:00 push time when the user does not provide one, but it does not require an explicit confirmation that a recurring schedule will be created. This can cause the agent to set up ongoing notifications based on ambiguous intent, creating unwanted contact and weak consent handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.