Back to skill

Security audit

快手达人数据 SocialDataX 达人作品

Security checks for vulnerabilities and agentic risk

Overview

The skill is for read-only SocialDataX Kuaishou creator-video lookup, but it runs a mutable npm package at runtime while using an API key.

Review this before installing. Use it only in an environment where npm execution is acceptable, limit the environment variables exposed to the command, prefer a pinned reviewed package version if available, and avoid --all unless you intend unbounded pagination and related API usage.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Execution of an Unpinned Remote npm Package

Content
View full analysis
" --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-kuaishou-creator-videos npx -y socialdatax-skills@latest kuaishou user-posts \ --profile-url "" --pretty \ --source-client socialdatax-skills --source-platform clawhub \ --source-skill socialdatax-kuaishou-creator-videos ``` Related directives include: ```yaml metadata: {"openclaw":{"requires":{"env":["SOCIALDATAX_API_KEY"],"bins":["node","npm"]},"primaryEnv":"SOCIALDATAX_API_KEY","install":[{"kind":"node","package":"socialdatax-skills","bins":[]}],"emoji":"🗂️","homepage":"https://socialdatax.com/ai?from=clawhub"}} ``` ```text If the current environment has permission, install or restore automatically. ``` ### Technical Analysis The Skill instructs the Agent to use `npx -y socialdatax-skills@latest`. The `@latest` version selector is mutable and does not bind execution to the specific package release that was reviewed. The `-y` option also suppresses the normal installation confirmation. Consequently, the effective executable code is downloaded at invocation time and may differ from the code available when the Skill was audited. No lockfile, exact version constraint, integrity hash, bundled implementation, or other mechanism is provided to verify the downloaded package. The instruction to install or restore dependencies automatically further reduces user oversight. The package executes as a local Node.js process under the Agent's operating-system identity. It is expected to receive `SOCIALDATAX_API_KEY`, creator identifiers or profile-share data, and pagination tokens ...[truncated 2940 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill instructs the agent to execute npx -y socialdatax-skills@latest ..., which pulls and runs the newest package version at execution time rather than a reviewed, pinned release. This creates a supply-chain risk: a compromised publisher account, malicious update, or breaking release could cause arbitrary code execution in the agent environment whenever the skill is used.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This is a second executable example using npx -y socialdatax-skills@latest, so it has the same core issue: unpinned remote code is fetched and executed on demand. In an agent context, that is especially risky because the command may run with access to environment secrets such as SOCIALDATAX_API_KEY and potentially broader local permissions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.