space-video-topic

Fail

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill specifically instructs the agent to execute yt-dlp --cookies-from-browser chrome to bypass Douyin's authentication checks. This flag allows the tool to read sensitive session cookies and credentials directly from the user's local Chrome browser database. While the stated goal is to fetch video tokens, this provides the agent/tool with access to the user's entire browser session data across all logged-in websites.
  • [COMMAND_EXECUTION]: The skill's primary functionality is built around executing shell commands such as yt-dlp, ffmpeg, and uvx. The instructions include placeholders like "<URL>" and "<抖音短链或 video URL>" which are directly interpolated into shell commands. If the agent does not strictly sanitize these inputs, it could lead to command injection vulnerabilities where a malicious URL string executes arbitrary system commands.
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from external, third-party platforms (Douyin, YouTube, Bilibili) and encourages the use of external APIs (TikHub, AgentKey). These interactions involve downloading binary data and metadata from remote servers to the local environment.
  • [PROMPT_INJECTION]: The skill operates on untrusted external data (video transcripts, descriptions, and subtitles). By ingesting this data to generate "选题与钩子" (Topics and Hooks) or "撰写标题" (Writing Titles), it creates a surface for indirect prompt injection. A malicious video or transcript could contain instructions designed to influence the agent's output or downstream actions.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 5, 2026, 08:28 AM
Security Audit — agent-trust-hub — space-video-topic