douyin-downloader-hardened
Warn
Audited by Snyk on Apr 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's script scripts/douyin_download.py queries the third‑party TikHub API (https://api.tikhub.io/api/v1/douyin/web/fetch_one_video), parses resp.text returned from that public service (which relays user-generated Douyin content) to extract a play URL and then uses that URL to drive downloads, so untrusted third‑party content is ingested and directly influences subsequent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata