douyin-comments

Warn

Audited by Socket on Sep 29, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/douyin_cdp_bridge.mjs

This is a local Chrome DevTools bridge, not clear malware. Its unauthenticated endpoints expose arbitrary browser JavaScript execution and navigation to clients that can access the loopback service, creating a significant local security risk. Restrict access or add authentication and request protections if used outside a tightly controlled environment.

Confidence: 98%Severity: 78%
Audit Metadata
Analyzed At
Sep 29, 2026, 12:31 AM
Package URL
pkg:socket/skills-sh/dragon-hh%2Fai-boshu-crawler%2Fdouyin-comments%2F@1048118326219a84dd52120b351af53e3755a26d24f6a32f5f4136496ad80abb
Security Audit — socket — douyin-comments