huashu-douyin-script

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The install.sh script installs dependencies by downloading and piping remote shell scripts to the local system. Specifically, it fetches the uv installer from astral.sh and pipes it to sh. It also provides instructions to execute its own installation script directly from the author's GitHub repository using bash process substitution.
  • [DATA_EXFILTRATION]: The script scripts/download_douyin.py is configured to use yt-dlp with the --cookies-from-browser flag. This allows the tool to access and extract sensitive authentication cookies from the user's local web browsers (Chrome, Edge, or Firefox) to authenticate requests to the Douyin platform. Access to browser cookies is a sensitive operation that grants the script access to authenticated session data.
  • [COMMAND_EXECUTION]: The scripts/download_douyin.py file uses subprocess.run to call the yt-dlp binary. Although the script attempts to sanitize user input by using a regular expression to extract specific Douyin URLs, this pattern involves executing system-level commands with arguments partially derived from external input.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Douyin videos which is then transcribed or summarized by the Gemini API and presented back to the agent for script generation. This creates a vulnerability surface where adversarial instructions embedded within the processed videos could influence the agent's output.
  • Ingestion points: scripts/analyze_video.py (via external API analysis) and scripts/download_douyin.py (via video downloads).
  • Boundary markers: None identified in the prompt templates or script interactions.
  • Capability inventory: The skill has the ability to perform network requests, write files to the local system, and execute shell commands.
  • Sanitization: The script uses a regular expression to filter and extract Douyin URLs from user-provided text.
Recommendations
  • HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh, https://raw.githubusercontent.com/alchaincyf/Write-Prompt/master/.claude/skills/douyin-viral-script/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 02:55 AM
Security Audit — agent-trust-hub — huashu-douyin-script