douyin-scraper

Warn

Audited by Socket on Aug 29, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the core scraping and Lark writeback behavior is coherent, but the skill goes beyond passive collection by enabling automated public commenting from a logged-in browser. Its data flows are mostly aligned, yet video analysis can transmit scraped content to MiniMax, and the browser/CDP access materially increases impact if misused.

Confidence: 89%Severity: 68%
AnomalyLOW
scripts/scrape-douyin.py

This module appears to be a Douyin scraper that collects metadata via Playwright, optionally downloads and analyzes video frames using ffmpeg and an external 'mmx vision' tool, and can optionally post comments using a live logged-in browser session. No clear malicious payload (exfiltration/backdoor/reverse shell) is present in the shown code. However, it disables TLS certificate verification globally (high security risk), executes external binaries on network-downloaded content, and supports CDP attachment and authenticated comment posting, which are powerful capabilities and warrant careful trust boundaries and hardening.

Confidence: 72%Severity: 62%
Audit Metadata
Analyzed At
Aug 29, 2026, 12:01 PM
Package URL
pkg:socket/skills-sh/csfuwwc%2Fmd-skills%2Fdouyin-scraper%2F@b3dc6ae85b955f79603724a6e6a69070bc654a1d0c03f0aa3ab6ffae216c63eb
Security Audit — socket — douyin-scraper