T09 · Insecure Skill Coding Practices
- Location
scripts/douyin_daily_hot.py:176- Finding
Untrusted API Response Fields Rendered as Active Markdown
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it says for Douyin ranking lookup, but it advertises recurring subscription push behavior and renders remote data as clickable Markdown without enough scoping or safeguards.
Install only if you trust RedFox with the API key and are comfortable with outbound ranking lookups. Treat subscription/push claims as under-specified until the publisher documents explicit opt-in, cancellation, storage, and scheduler behavior, and be cautious with clickable links returned from the API.
scripts/douyin_daily_hot.py:176Untrusted API Response Fields Rendered as Active Markdown
The skill description promises capabilities that are not implemented or enforced, including subscription/push delivery, a 30-day historical limit, and '达人排名' despite only describing a work-like ranking query. These mismatches are dangerous because they can mislead users and orchestrators about data handling and safety boundaries, causing over-trust, incorrect automation decisions, or unbounded parameter use against the backend service.
The README encourages invocation through very broad natural-language phrases such as 'Today's ranking' and 'Show all', which are common conversational expressions not uniquely tied to this skill. In agent environments that auto-route based on user utterances, this can cause unintended activation and data access or external API usage when the user did not explicitly intend to use this tool.
The skill instructs users to 'directly use natural language' without defining a constrained invocation pattern, which increases the chance of accidental activation from ordinary conversation. In an agent environment, broad activation can cause the skill to run when the user did not clearly intend to query this external data source, leading to unnecessary outbound requests or context confusion.
The example trigger phrases are short, generic expressions like '今日榜单' and '看看美食赛道' that overlap with normal user speech. In a multi-skill agent, these common phrases can spuriously trigger this skill instead of a safer or more appropriate response path, creating unintended tool use and possible data leakage through external API calls.
The skill instructs use of an environment-sourced API key and outbound network access to a third-party endpoint, but does not declare any explicit tool scope or permissions. This creates a least-privilege and transparency gap: hosts or reviewers cannot reliably constrain what capabilities the skill needs, increasing the risk of unintended secret exposure or unauthorized external requests if the skill is executed in a permissive runtime.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
请求示例:
curl -X POST \
-H "X-API-KEY: $REDFOX_API_KEY" \
-H "Content-Type: application/json" \
-d '{"source": "<见脚本>-ClawHub","type":"美食","startTime":"2026-05-28","endTime":"2026-05-28"}' \
This markdown file instructs users to configure REDFOX_API_KEY and shows it being sent in an HTTP header, but it does not include any caution about keeping the key secret or avoiding exposure in shared terminals, logs, or screenshots. For markdown files, network behavior and credential use should include a brief warning when they may affect privacy or security.
The skill introduces a recurring subscription/push feature without clearly disclosing that notifications will continue automatically or what user data and preferences will be stored to support that behavior. While this is not a code-execution issue, it is a real consent and transparency weakness that can lead to unexpected ongoing messaging and privacy complaints.
The guide specifies a default daily 06:00 push time when the user does not provide one, but it does not require an explicit confirmation that a recurring schedule will be created. This can cause the agent to set up ongoing notifications based on ambiguous intent, creating unwanted contact and weak consent handling.
No suspicious patterns detected.