douyin-downloader

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
douyin.js

No direct evidence of intentional malware/backdoor behavior in this module. The dominant security concerns are (1) possible path traversal/arbitrary file write due to insufficient validation of the derived video_id used in filesystem paths, and (2) SSRF-adjacent behavior from unrestricted redirect following to arbitrary redirect targets. Additional non-malicious but material risks include privacy-sensitive upload of full audio to an external transcription API and operational exposure from running ffmpeg/ffprobe on untrusted downloaded media.

Confidence: 63%Severity: 68%
Audit Metadata
Analyzed At
Apr 14, 2026, 07:57 AM
Package URL
pkg:socket/skills-sh/freestylefly%2Fcanghe-skills%2Fdouyin-downloader%2F@b0b3925942f0b95ddab65cf1263ba083c146ef20