huashu-douyin-script
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The
install.shscript installs dependencies by downloading and piping remote shell scripts to the local system. Specifically, it fetches theuvinstaller fromastral.shand pipes it tosh. It also provides instructions to execute its own installation script directly from the author's GitHub repository using bash process substitution. - [DATA_EXFILTRATION]: The script
scripts/download_douyin.pyis configured to useyt-dlpwith the--cookies-from-browserflag. This allows the tool to access and extract sensitive authentication cookies from the user's local web browsers (Chrome, Edge, or Firefox) to authenticate requests to the Douyin platform. Access to browser cookies is a sensitive operation that grants the script access to authenticated session data. - [COMMAND_EXECUTION]: The
scripts/download_douyin.pyfile usessubprocess.runto call theyt-dlpbinary. Although the script attempts to sanitize user input by using a regular expression to extract specific Douyin URLs, this pattern involves executing system-level commands with arguments partially derived from external input. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Douyin videos which is then transcribed or summarized by the Gemini API and presented back to the agent for script generation. This creates a vulnerability surface where adversarial instructions embedded within the processed videos could influence the agent's output.
- Ingestion points:
scripts/analyze_video.py(via external API analysis) andscripts/download_douyin.py(via video downloads). - Boundary markers: None identified in the prompt templates or script interactions.
- Capability inventory: The skill has the ability to perform network requests, write files to the local system, and execute shell commands.
- Sanitization: The script uses a regular expression to filter and extract Douyin URLs from user-provided text.
Recommendations
- HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh, https://raw.githubusercontent.com/alchaincyf/Write-Prompt/master/.claude/skills/douyin-viral-script/install.sh - DO NOT USE without thorough review
Audit Metadata