Back to skill

Security audit

快手评论分析 SocialDataX 评论洞察

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent read-only SocialDataX purpose, but it tells agents to execute a mutable npm package at runtime with access to the user's API key.

Review before installing. Use only in an environment where running the SocialDataX npm client is acceptable, preferably with a pinned package version and a minimal environment containing only SOCIALDATAX_API_KEY. Avoid exposing unrelated credentials to the agent process.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:32
Finding

Unpinned Third-Party Package Download and Execution

Content
View full analysis
" --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-kuaishou-comments npx -y socialdatax-skills@latest kuaishou comments \ --url "" --pretty \ --source-client socialdatax-skills --source-platform clawhub \ --source-skill socialdatax-kuaishou-comments npx -y socialdatax-skills@latest kuaishou replies \ --photo-id "" --comment-id "" --pretty \ --source-client socialdatax-skills --source-platform clawhub \ --source-skill socialdatax-kuaishou-comments ``` The troubleshooting instructions also state: ```text If the current environment has permission, install or restore automatically. ``` ### Technical Analysis The Skill directs the Agent to execute `socialdatax-skills@latest` through `npx -y`. The `@latest` specifier downloads and runs whichever package release is current at invocation time, so the effective executable can change after the Skill has been reviewed. The `-y` option suppresses the normal installation confirmation. No exact package version, lockfile, integrity hash, vendored implementation, or reviewable client source is included in the project. Consequently, the behavior of the downloaded package—including its network destinations and handling of sensitive data—cannot be verified from this artifact. The package executes with the Agent process's operating-system privileges and can potentially access its in ...[truncated 2268 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs the agent to run npx -y socialdatax-skills@latest ..., which pulls and executes the newest package version at runtime without pinning to a known-good release. This creates a supply-chain risk: if the package is compromised or a breaking/malicious version is published, the agent may execute attacker-controlled code with access to environment variables such as SOCIALDATAX_API_KEY and local system permissions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This command also uses npx -y socialdatax-skills@latest, causing unreviewed code to be downloaded and executed on demand. In the context of an agent skill, that is especially risky because the runtime may expose secrets, network access, and shell execution privileges to whatever version is resolved at execution time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The replies command repeats the same unsafe pattern of executing socialdatax-skills@latest through npx. Because this is an executable package invocation rather than a passive dependency reference, exploitation could immediately result in arbitrary code execution and possible exfiltration of the configured API key or other accessible data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.