Back to skill

Security audit

快手达人数据 SocialDataX 达人信息

Security checks for vulnerabilities and agentic risk

Overview

The skill is a read-only Kuaishou creator lookup helper, but it asks agents to run an unpinned remote npm package with the user's API key, so it belongs in Review.

Install only if you are comfortable letting an npm package fetched at runtime use your SocialDataX API key. Prefer a pinned, reviewed package version or a preinstalled trusted MCP tool, and run it with only the required API key exposed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:29
Finding

Unpinned npm Package Download and Execution

Content
View full analysis
" --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-kuaishou-creator-profile npx -y socialdatax-skills@latest kuaishou user-search \ --keyword "" --pages 3 --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-kuaishou-creator-profile npx -y socialdatax-skills@latest kuaishou user-info \ --user-id "" --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-kuaishou-creator-profile npx -y socialdatax-skills@latest kuaishou user-info \ --profile-url "" --pretty \ --source-client socialdatax-skills --source-platform clawhub \ --source-skill socialdatax-kuaishou-creator-profile ``` The metadata also declares the same package without an exact version: ```yaml metadata: {"openclaw":{"requires":{"env":["SOCIALDATAX_API_KEY"],"bins":["node","npm"]},"primaryEnv":"SOCIALDATAX_API_KEY","install":[{"kind":"node","package":"socialdatax-skills","bins":[]}],"emoji":"👤","homepage":"https://socialdatax.com/ai?from=clawhub"}} ``` ### Technical Analysis The documented commands use `npx -y socialdatax-skills@latest`. The `@latest` tag resolves dynamically to whichever release is currently designated as latest in the npm registry. Consequently, the code that will execute can change after this Skill has been reviewed, without any corresponding modification to `SKILL.md`. The `-y` flag automatically accepts package installation, removing an interactive confirmation that could otherwise alert the operator to a new download. No exact ...[truncated 2365 chars]
Remediation
View remediation
... ``` Do not use a range, tag, or floating version. 2. Maintain a lockfile and verify the package artifact against an approved integrity hash. Retrieve dependencies from a trusted registry with controlled configuration. 3. Remove automatic acceptance through `-y` where interactive operation is possible. In automated environments, enforce dependency approval through policy rather than accepting arbitrary new releases. 4. Install the reviewed dependency during a controlled build or provisioning phase instead of downloading executable code each time the Skill runs. 5. Execute the CLI in a sandbox with: - Only `SOCIALDATAX_API_KEY` exposed to the process. - No unrelated environment variables. - Read-only or narrowly scoped filesystem access. - Restricted subprocess capabilities. - An outbound network allowlist limited to documented SocialDataX endpoints and the minimum required package infrastructure during controlled installation. 6. Separate package installation from API execution so runtime environments do not need npm registry access. 7. Review each dependency update before changing the pinned version, including package contents, installation scripts, transitive dependencies, publisher provenance, and required network destinations. 8. Rotate `SOCIALDATAX_API_KEY` and investigate API activity if an untrusted package version has already been executed. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation sentence says to use the skill when the user wants terms like "account basics" or "profile information," which are broad phrases that can overlap with common requests outside this specific Kuaishou lookup context. The file does not provide negative examples or explicit exclusion conditions to narrow when the skill should not activate.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill instructs the agent to execute npx -y socialdatax-skills@latest ..., which fetches and runs the newest package version at execution time rather than a reviewed, fixed version. This creates a supply-chain risk: a compromised publisher account, malicious update, or dependency hijack could lead to arbitrary code execution in the agent environment and access to environment variables such as SOCIALDATAX_API_KEY.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This command repeats the same unsafe pattern of executing npx -y socialdatax-skills@latest, causing the runtime to trust whatever package version is current at the time of use. Because npx downloads and executes code, an attacker controlling the package or its dependencies could run arbitrary code and potentially exfiltrate secrets or tamper with results.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The unpinned npx invocation allows remote code changes outside the repository author's review boundary, which is especially risky because the skill is meant to be executed directly by an agent. If the upstream package is modified maliciously, the agent may execute attacker-controlled code with the same privileges as the user session.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This is another direct example of executing an unpinned remote package via npx, which materially increases supply-chain exposure. Even though the skill describes itself as read-only, a malicious package version could ignore that intent and perform arbitrary filesystem, network, or credential-access actions at runtime.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.