Back to skill

Security audit

抖音作品搜索

Security checks for vulnerabilities and agentic risk

Overview

This Douyin search skill is mostly purpose-aligned, but its daily subscription instructions create a persistent scheduled command with unsafe keyword interpolation that needs review before use.

Install only if you are comfortable sending search keywords and date filters to RedFox with your REDFOX_API_KEY. Do not use the documented crontab subscription template with arbitrary keywords; subscriptions should use a platform scheduler or fixed runner with safe argument handling, clear removal steps, and least-privilege execution.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:150
Finding

Persistent Shell Command Injection Through Unsanitized Cron Keyword

Content
View full analysis
` - Execution frequency: Daily at 10:00 (`0 10 * * *`) - Execution command: `python3 /search_douyin.py ""` (append `--start-date`/`--end-date` when applicable) - Generic crontab: `0 10 * * * python3 /path/to/search_douyin.py ""` ``` The displayed labels are English translations of the original documentation. The vulnerable command templates are unchanged in substance: ```bash python3 /search_douyin.py "" 0 10 * * * python3 /path/to/search_douyin.py "" ``` ### Technical Analysis The Skill instructs the agent to interpolate a user-derived keyword directly into a shell command stored in a crontab entry. Wrapping the value in double quotes does not make it safe: a keyword containing a double quote can terminate the quoted argument, after which shell separators, command substitutions, redirections, or additional commands can be injected. For example, the following malicious keyword: ```text "; touch /tmp/cron-injection; # ``` would produce a command equivalent to: ```bash python3 /path/to/search_douyin.py ""; touch /tmp/cron-injection; #" ``` When cron invokes its configured shell, the search script runs with an empty keyword and the injected `touch` command is then executed separately. This flaw is especially consequential because the unsafe command is placed in a persistent scheduled task. The daily subscription feature is explicitly documented and requires confirmation, so scheduling by itself is not treated as unauthorized persistence. Nevertheless, unsafe interpolation lets an attacker transform a legitimate subscription into recurring arbitrary command execution. ### Attack Path 1. An attacker persuades a user or an in ...[truncated 1488 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

These instructions explicitly tell the agent to create scheduled tasks or crontab entries, which is a privileged automation capability beyond a simple search tool. If followed, the skill could establish persistence, run unattended commands daily, and continue accessing local environment credentials or network resources after the original interaction ends.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The feature set combines casual conversational input with automatic keyword expansion into multiple niche terms, but does not describe limits, consent, or guardrails. This increases the chance that vague user text is transformed into broader searches than intended, amplifying accidental invocation, over-collection of third-party results, and unintended use of the configured API key.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly encourages natural-language, casual phrasing as sufficient to invoke the skill, without defining a clear activation boundary. In agent ecosystems, overly broad invocation rules can cause unintended tool activation from ordinary conversation, leading to unnecessary external API calls, data exposure to third-party services, or surprising subscription actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README says users can 'directly use natural language' and do not need fixed commands, but it does not define clear trigger boundaries, exclusions, or negative examples. This makes activation scope ambiguous and increases the risk that common conversational requests could unintentionally invoke the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Example utterances such as '帮我看看旅行类在抖音火不火' and '最近搞笑视频挺火的' are common conversational phrases rather than distinctive commands. Because the document provides these as invocation examples without clarifying boundaries, the trigger set overlaps with ordinary speech and may cause unintended activation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents capabilities that require environment access and outbound network use, but it does not declare any explicit tool scope or allowed-tools boundary. This weakens least-privilege controls and can let the skill operate with broader runtime capabilities than users or the platform expect, especially since it also references local config and external APIs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file defines activation phrases, so SQP-1 applies. The trigger list includes generic terms like “抖音搜索”, “热门视频”, and “爆款视频”, which are broad enough to overlap with ordinary user requests and the file does not provide exclusion conditions or negative examples to constrain when the skill should activate.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises a subscription/push capability in its feature list even though its stated purpose is search/query. Expanding a read-only search skill into a persistence or automation workflow increases authority and user expectations mismatch, making it easier to perform ongoing actions that were not clearly scoped in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill instructs users to place an API key in a local config file or environment variable but does not warn about credential sensitivity, access controls, rotation, or risks of accidental disclosure. In a skill that also invokes local scripts and discusses automation, poorly handled secrets increase the chance of leakage through logs, misconfiguration, inherited environments, or scheduled jobs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script's user-facing description, errors, and CLI help are entirely in Chinese, which imposes a specific language on users. There is no opt-in, alternate locale, or documentation that this skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

All user-facing instructions and examples are written in Chinese, and the document does not indicate that users can choose another language or that the Chinese-only presentation is a required regional constraint. This can violate language/locale policy when a skill implicitly forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The documentation states '支持订阅感兴趣的关键词,每天定时推送最新爆款数据', which is a concrete behavioral claim beyond ad hoc search. In the provided skill file, there is no implementation or operational detail showing scheduler, storage, or push delivery support, so the documentation appears to overstate what the skill actually does.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The feature list and highlights describe '订阅推送' and '一键订阅' as active capabilities, but the provided file contains only descriptive documentation and API-key setup. Because the stated behavior implies stateful background actions not otherwise evidenced here, the documentation is likely divergent from actual implemented functionality.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This line gives a specific user flow and delivery schedule ('每天 10:00 自动推送'), which is stronger than a general future-feature description. In the absence of corresponding code or configuration for scheduling, persistence, and outbound delivery, the README instruction likely contradicts the actual available behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code performs a network POST request to a third-party endpoint and includes user-supplied search content in the JSON payload. Although the script name and module docstring indicate it searches via Redfox API, there is no explicit disclosure at the call site or argument help that the provided query data will be transmitted off-system.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.