douyin-batch-download

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Based on the provided SKILL.md (documentation only, no script source code), the skill's stated capabilities align with its requirements (Playwright for login, httpx for requests, ffmpeg for compression). The main security concerns are the sensitive nature of browser cookies/playwright profiles and broad filesystem access (downloading and storing media, DB files). These are proportionate to the declared purpose but represent a moderate risk: if the actual scripts mishandle credentials (e.g., upload cookies to third-party endpoints, read unrelated sensitive files, or execute unsanitized shell commands), that would be a severe supply-chain/security issue. To reduce risk, reviewers should inspect the actual Python scripts for any network calls to non-official domains, any instructions that forward credentials, any use of pipe-to-shell or untrusted downloads, and ensure Playwright uses a dedicated profile rather than the user's full browser profile.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 2, 2026, 11:43 AM
Package URL
pkg:socket/skills-sh/cat-xierluo%2Flegal-skills%2Fdouyin-batch-download%2F@b5bd47289343185a3fb72bd8e69fb9347f5590cc