douyin-video-analyst
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill targets sensitive configuration files at
~/.cursor/mcp.jsonand~/.claude.json, which are standard locations for storing plain-text API keys and Model Context Protocol (MCP) server settings. - [DATA_EXFILTRATION]: Troubleshooting scripts in the skill (specifically in
references/troubleshooting.md) extract and print full server configurations, including raw API keys from environment variables, directly into the agent's output history. - [COMMAND_EXECUTION]: The skill relies on executing shell commands via
mcporterandpython3heredocs to interact with the local filesystem and invoke external tool functions. - [EXTERNAL_DOWNLOADS]: Setup instructions recommend global installation of the
mcporterutility vianpmand runtime execution ofdouyin-mcp-serverfrom external sources. - [REMOTE_CODE_EXECUTION]: The skill uses
uvxto dynamically download and execute thedouyin-mcp-serverpackage, which constitutes execution of external code from a remote registry in the shell environment. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted transcription data from external videos without proper isolation.
- Ingestion points: Video text enters the context via the
douyin-mcp.extract_douyin_texttool output. - Boundary markers: No delimiters or 'ignore' instructions are used to separate transcription data from the agent's logic.
- Capability inventory: The agent has access to
browsertools andmcportershell execution. - Sanitization: There is no evidence of validation or sanitization of the extracted video text before the agent summarizes it.
Recommendations
- AI detected serious security threats
Audit Metadata