Back to skill

Security audit

抖音作品实时搜索

Security checks for vulnerabilities and agentic risk

Overview

The skill is a Douyin search tool with an intended API client, but it also instructs agents to create recurring daily scheduled searches without enough scoping or cancellation guidance.

Install only if you are comfortable giving the skill a Redfox API key and letting it call redfox.hk for your Douyin search terms. Treat the daily subscription feature carefully: approve it only after confirming the exact keyword and schedule, and make sure you know how to remove the scheduled job if you no longer want recurring searches.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 181)May include surrounding context.

确认订阅」时执行)

优先使用平台内置定时任务能力,若无则提供通用方案:

平台内置定时任务(优先):

  • 任务名称:抖音实时搜索订阅 - <关键词>
  • 执行频率:每天 10:00(cron:0 10 * * *)
  • 执行内容:运行脚本并将结果按 Step 3~4 格式展示推送到当前对话

通用配置方案:

bash
# Linux/macOS crontab
0 10 * * * python3 ~/.agents/skills/douyin-realtime-search/scripts/search_douyin_realtime.py "<关键词>"

创建成功后告知用户:"已成功订阅关键词「<关键词>」的实时作品推送,每天 10:00 将自动查询最新数据并通知你。"

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises a daily subscription push feature even though the skill metadata frames the tool as a real-time, on-demand Douyin search utility. This kind of scope expansion can mislead users and integrators about what the skill is authorized to do, and it introduces persistent automated behavior beyond a single search request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README mentions subscription push capability without clearly warning that this schedules recurring automated updates and future notifications. Missing disclosure undermines informed consent and can cause users to authorize ongoing monitoring or messaging they did not fully expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Telling users to describe needs in plain language with no command constraints broadens activation semantics and increases the chance the agent invokes the skill unexpectedly. In a skill that can query external services and potentially establish ongoing subscriptions, ambiguous triggering raises the risk of unintended actions and data processing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage guide says that replying with a simple phrase can create a scheduled daily task, which exceeds an on-demand search skill's expected behavior. Users may believe they are performing a one-time action when they are actually authorizing future automated processing and notifications.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Using the generic phrase 'Confirm subscription' as an action trigger is too broad and can overlap with ordinary conversation, making accidental activation plausible. Because the action creates an ongoing automated task, the consequence of misfire is more serious than a normal search invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README says users can invoke the skill with arbitrary natural language, which makes routing boundaries too loose for a capability that performs external real-time searches and supports stateful actions like pagination and subscriptions. Overly broad activation increases the chance the agent triggers this skill unexpectedly from ambiguous user text, causing unintended external requests or follow-on actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Using vague examples like single keywords ('健身') and navigation-only phrases ('下一页', '上一页', '确认订阅') makes the skill easy to trigger without enough context that the user intended this specific capability. In a multi-skill agent, this can hijack generic conversation turns, continue prior state unexpectedly, or create subscriptions based on short ambiguous inputs.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill uses sensitive capabilities: it depends on an environment variable for an API key and instructs the agent to invoke an external Python script that performs network access, yet it declares no explicit tool scope or permission boundary. This weakens reviewability and least-privilege controls, making it easier for a host agent to grant broader capabilities than the skill's stated purpose requires.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest presents the skill as a real-time search utility, but the body adds a subscription/push workflow that changes the trust model from one-shot lookup to ongoing automation. That scope expansion can surprise operators and users, especially because recurring execution and notification behavior carry additional privacy, consent, and security implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill tells users to place an API key into config files or shell environment variables but gives no warning that the credential is sensitive, should never be shared in chat, and should be stored using least exposure. This increases the chance of accidental disclosure, insecure storage, or mishandling by users and integrators.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs creation of scheduled tasks for recurring execution, including a generic crontab example. Scheduled execution introduces persistence and unattended network activity that exceed a simple search tool's expected behavior; if misused, it can create unauthorized background jobs, repeated API calls, and ongoing data collection or message delivery.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

Policy review applies to all file types, including markdown. The document is explicitly an English-language skill description and does not mention that users may interact in other languages or choose their preferred locale, which may conflict with language-choice expectations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Earlier documentation says --sort supports comprehensive, latest, and most-liked ordering. However, the output table description states articles are returned '按点赞降序', which contradicts the idea that ordering depends on the selected sort mode.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.