douyin-video-analyst

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill targets sensitive configuration files at ~/.cursor/mcp.json and ~/.claude.json, which are standard locations for storing plain-text API keys and Model Context Protocol (MCP) server settings.
  • [DATA_EXFILTRATION]: Troubleshooting scripts in the skill (specifically in references/troubleshooting.md) extract and print full server configurations, including raw API keys from environment variables, directly into the agent's output history.
  • [COMMAND_EXECUTION]: The skill relies on executing shell commands via mcporter and python3 heredocs to interact with the local filesystem and invoke external tool functions.
  • [EXTERNAL_DOWNLOADS]: Setup instructions recommend global installation of the mcporter utility via npm and runtime execution of douyin-mcp-server from external sources.
  • [REMOTE_CODE_EXECUTION]: The skill uses uvx to dynamically download and execute the douyin-mcp-server package, which constitutes execution of external code from a remote registry in the shell environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted transcription data from external videos without proper isolation.
  • Ingestion points: Video text enters the context via the douyin-mcp.extract_douyin_text tool output.
  • Boundary markers: No delimiters or 'ignore' instructions are used to separate transcription data from the agent's logic.
  • Capability inventory: The agent has access to browser tools and mcporter shell execution.
  • Sanitization: There is no evidence of validation or sanitization of the extracted video text before the agent summarizes it.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 05:46 PM
Security Audit — agent-trust-hub — douyin-video-analyst