douyin-comments
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Chrome DevTools Protocol (CDP)
Runtime.evaluatemethod to execute large, dynamically generated JavaScript blocks within the context of the user's browser. - Evidence:
scripts/fetch_douyin_comments.pyandscripts/fetch_douyin_comments_cdp.mjsboth construct and send JS strings to the browser via the bridge or direct websocket connection. - [PRIVILEGE_ESCALATION]: By connecting to the Chrome
DevToolsActivePort, the skill gains full programmatic control over the browser session. This includes the ability to read all page content, access cookies, and perform actions as the logged-in user. - Evidence:
scripts/douyin_cdp_bridge.mjssearches for and reads theDevToolsActivePortfile to locate the browser's debugging websocket. - [DYNAMIC_EXECUTION]: The
douyin_cdp_bridge.mjsscript creates a local HTTP server that exposes an/evalendpoint, which accepts and executes arbitrary JavaScript code in the browser without authentication. - Evidence: The
/evalroute inscripts/douyin_cdp_bridge.mjspasses theexpressionbody directly toRuntime.evaluate. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest untrusted data (Douyin comments) from the web.
- Ingestion points: Douyin comment API responses fetched via the browser (
scripts/fetch_douyin_comments.py). - Boundary markers: None identified. The content is saved directly to JSON/JSONL files.
- Capability inventory: The agent has the ability to write to the local filesystem, spawn processes (
douyin_cdp_bridge.mjs), and execute code in the browser. - Sanitization: No sanitization of comment text is performed before saving to local files, creating a risk if the agent later reads these files as instructions.
Audit Metadata