扫描报告
45 /100
抖音视频无水印下载器
Douyin video watermark-free downloader using undisclosed third-party proxy
Skill implements a Douyin video downloader with undocumented third-party proxy API and undeclared required permissions, lacking transparency about data handling despite plausible benign functionality.
谨慎使用
Declare required network and filesystem permissions in SKILL.md. Investigate the undocumented lvhomeproxy2.dpdns.org proxy service — either replace with documented API or disclose its role. Add allowedTools section specifying requests and file I/O usage.
安全发现 3 项
| 严重性 | 安全发现 | 位置 |
|---|---|---|
| 高危 | Undocumented third-party proxy API 文档欺骗 | scripts/douyin-no-watermark-downloader.py:18 |
| 中危 | Missing allowed-tools declaration 权限提升 | SKILL.md:1 |
| 低危 | Hardcoded User-Agent and Referer headers 敏感访问 | scripts/douyin-no-watermark-downloader.py:83 |
| 资源类型 | 声明权限 | 推断权限 | 状态 | 证据 |
|---|---|---|---|---|
| 文件系统 | NONE | WRITE | ✗ 越权 | scripts/douyin-no-watermark-downloader.py:66 writes to Desktop path via open() |
| 网络访问 | NONE | READ | ✗ 越权 | scripts/douyin-no-watermark-downloader.py:18 uses requests.get() to lvhomeproxy2… |
1 高危 9 项发现
高危 IP 地址 硬编码 IP 地址
120.0.0.0 scripts/douyin-no-watermark-downloader.py:83 中危 外部 URL 外部 URL
https://v.douyin.com/1A4yExNduOU/ SKILL.md:30 中危 外部 URL 外部 URL
https://v.douyin.com/8B9xYz789/ SKILL.md:31 中危 外部 URL 外部 URL
https://v.douyin.com/XIkH2hGDnw/ SKILL.md:40 中危 外部 URL 外部 URL
https://lvhomeproxy2.dpdns.org/api/hybrid/video_data scripts/douyin-no-watermark-downloader.py:18 中危 外部 URL 外部 URL
https://www.douyin.com/ scripts/douyin-no-watermark-downloader.py:84 中危 外部 URL 外部 URL
https://v.douyin.com/xxxxx scripts/douyin-no-watermark-downloader.py:113 中危 外部 URL 外部 URL
https://v\.douyin\.com/[^\s scripts/douyin-no-watermark-downloader.py:121 中危 外部 URL 外部 URL
https://v.douyin.com/XIkH2hGDHnw/ scripts/douyin-no-watermark-downloader.py:141 目录结构
2 文件 · 7.9 KB · 227 行 Python 1f · 167L
Markdown 1f · 60L
├─
▾
scripts
│ └─
douyin-no-watermark-downloader.py
Python
└─
SKILL.md
Markdown
依赖分析 1 项
| 包名 | 版本 | 来源 | 已知漏洞 | 备注 |
|---|---|---|---|---|
requests | * | pip | 否 | Version not pinned; library widely used, low supply chain risk |
安全亮点
✓ No shell execution or subprocess usage — script only uses Python standard library and requests
✓ No credential harvesting or environment variable iteration for secrets
✓ No obfuscation (base64, eval, anti-analysis techniques)
✓ No persistence mechanisms (no cron, startup scripts, or backdoors)
✓ No data exfiltration beyond standard video download operation
✓ No suspicious imports (only sys, requests, time, logging, os, datetime, re)
✓ No downloads of external scripts at runtime