huashu-douyin-script

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS。技能目标与主要能力基本一致:下载抖音视频并做脚本分析是其宣称用途的一部分,安装来源也主要是官方文档支持的包管理器路径,不像明显恶意分发。但其要求浏览器Cookie、依赖未审计的本地脚本、且允许将 Gemini API key 与视频内容发送到任意自定义代理端点,这些都超出了低风险文档技能的范围。未见确认恶意行为证据,因此更适合判定为中等风险、可疑而非恶意。

Confidence: 83%Severity: 57%
AnomalyLOW
scripts/download_douyin.py

The code is primarily a Douyin video downloader and does not show clear malware, persistence, reverse-shell behavior, or deliberate data exfiltration. The main security concerns are sensitive browser-cookie access, disabling TLS certificate verification, forcibly bypassing proxy settings, and weak hostname validation. Use of yt-dlp with browser cookies should be limited to trusted environments, and certificate checking and proxy configuration should not be disabled. The provided fragment is syntactically incomplete at the end.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:56 AM
Package URL
pkg:socket/skills-sh/alchaincyf%2Fhuashu-skills%2Fhuashu-douyin-script%2F@ba9b3026569f45a7ea2c61e4a874fb6ee7467657c7612c8b9c163e504cc73f9c
Security Audit — socket — huashu-douyin-script