douyin-comments
Warn
Audited by Socket on Sep 29, 2026
1 alert found:
SecuritySecurityscripts/douyin_cdp_bridge.mjs
MEDIUMSecurityMEDIUM
scripts/douyin_cdp_bridge.mjs
This is a local Chrome DevTools bridge, not clear malware. Its unauthenticated endpoints expose arbitrary browser JavaScript execution and navigation to clients that can access the loopback service, creating a significant local security risk. Restrict access or add authentication and request protections if used outside a tightly controlled environment.
Confidence: 98%Severity: 78%
Audit Metadata