Back to skill

Security audit

抖音七日点赞飙升榜

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Douyin ranking purpose, but it asks for scheduled subscription behavior without clear storage or opt-out controls and renders remote API content as clickable Markdown links without adequate validation.

Install only if you trust RedFoxHub with your API-key-backed ranking queries and are comfortable with clickable links returned from that service. Treat subscription or daily push claims cautiously until the publisher documents consent, storage, cancellation, and delivery controls; avoid enabling automatic scheduled behavior without those details.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/douyin_weekly_surge.py:163
Finding

Untrusted API Response Fields Rendered as Active Markdown

Content
View full analysis

Vulnerability Details

File Location: scripts/douyin_weekly_surge.py:163-182
Vulnerability Type: Markdown output injection and unsafe URL rendering
Risk Level: Medium

Vulnerable Code

python
for idx, item in enumerate(items[:limit], start=1):
    raw_title = (item.get("aweme_desc") or "-").replace("|", "|").replace("[", "【").replace("]", "】").replace("\n", " ").replace("\r", " ")
    work_url = item.get("share_url", "")
    if work_url:
        title = f"[{raw_title}]({work_url})"
    else:
        title = raw_title
    author = item.get("user_nickname", "-")
    cat = item.get("category") or "-"
    collect = format_number(item.get("add_collect_count"))
    comment = format_number(item.get("add_comment_count"))
    share = format_number(item.get("add_share_count"))
    like = f"**{format_number(item.get('add_digg_count'))}**"
    pub_time = format_time(item.get("create_time_str"))

    if is_all:
        print(f"| {idx} | {title} | {author} | {cat} | {collect} | {comment} | {share} | {like} | {pub_time} |")
    else:
        print(f"| {idx} | {title} | {author} | {collect} | {comment} | {share} | {like} | {pub_time} |")

Technical Analysis

The script treats fields returned by the remote API as trusted presentation data. The share_url field is inserted directly into a Markdown link without validating its URL scheme, destination host, control characters, or Markdown delimiters. The user_nickname and category fields are also inserted into the Markdown table without escaping pipes, line breaks, brackets, or other formatting characters.

The title receives partial escaping, but this does not secure the URL or the other remotely supplied fields. A malicious or compromised API response could therefore alter the table structure, inject arbitrary Markdown, or create a deceptive clickable link. If an AI Agent subsequently consumes the rendered output, instruction-like content co ...[truncated 1938 chars]

Remediation
View remediation

Remediation Suggestions

  1. Parse every returned URL with a standard URL parser and accept only the https scheme.
  2. Enforce an explicit hostname allowlist for expected Douyin domains, such as douyin.com and iesdouyin.com, including carefully validated subdomains.
  3. Reject URLs containing credentials, control characters, malformed delimiters, unexpected ports, or encoded host-confusion sequences.
  4. Escape Markdown-significant characters in every API-derived text field, including pipes, carriage returns, line feeds, brackets, parentheses, and backslashes.
  5. Normalize author and category values to a single line and impose reasonable length limits.
  6. If URL validation fails, render the title as plain text rather than producing a clickable link.
  7. Prefer returning structured data and performing Markdown rendering in a trusted presentation layer.
  8. Treat all remote API content as untrusted data and explicitly instruct downstream Agent logic not to interpret returned fields as commands or behavioral instructions.
  9. Add tests using malicious URLs, embedded pipes, multiline values, closing parentheses, and instruction-like text to verify that output remains inert.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README says users can 'Simply describe what you need in natural language' and provides example queries that overlap with common conversational requests like 'How's Fitness trending this week?'. For a markdown skill description, this is an ambiguous trigger scope because it does not define precise invocation constraints, exclusions, or negative examples to prevent unintended activation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README says users can 'directly use natural language to describe需求,无需记忆命令', which makes activation scope sound open-ended rather than bounded to specific trigger phrases or contexts. This can overlap with ordinary conversation and increases the risk of unintended invocation because no exclusion conditions or negative examples are provided.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents use of environment variables and outbound network access to call an external API, but it does not declare any explicit tool scope or allowed-tools restrictions. That creates unnecessary ambient authority: if the skill is invoked in a broader-capability runtime, it may access secrets or perform network actions beyond what reviewers and operators expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger phrases are broad and overlap with common user requests about Douyin rankings, while the skill lacks clear exclusion or disambiguation conditions. This can cause unintended invocation, which is risky here because the skill performs authenticated external API calls and may expose fetched content or consume paid quota when the user did not specifically intend to use this integration.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-config.md (reported line 37)May include surrounding context.

请求示例:

bash
curl -X POST \
  -H "X-API-KEY: $REDFOX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"source": "<见脚本>-ClawHub","type":"美食","startTime":"2026-05-28"}' \

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The interaction guide instructs the agent to offer a subscription and scheduled push capability even though the skill is described as a query-only leaderboard lookup tool. This scope expansion can cause the agent to collect scheduling preferences or imply background messaging capabilities that were not declared, increasing the risk of unauthorized data handling, misleading behavior, or unexpected downstream integrations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly claims support for user subscriptions with scheduled delivery, which exceeds the declared purpose of on-demand leaderboard retrieval. Even without executable code in this file, such instructions can lead an agent to misrepresent its capabilities, solicit persistent preferences, or trigger platform features outside the approved trust boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Examples like '看看今天的抖音七日飙升榜' and '帮我订阅美食赛道的七日飙升榜' are natural conversational phrases, but the README does not define whether these are the exhaustive triggers or merely examples. Without explicit scope boundaries or negative examples, the skill's invocation conditions remain ambiguous.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.