Back to skill

Security audit

快手数据分析 SocialDataX 作品详情

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its Kuaishou data-lookup purpose, but it relies on automatically running the latest remote npm package, which makes installation and execution worth review.

Review this skill before installing in sensitive environments. It appears purpose-aligned for Kuaishou detail retrieval, but you should prefer a pinned, reviewed version of socialdatax-skills and avoid exposing unrelated environment variables or broad filesystem access when running it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:29
Finding

Unpinned Remote npm Package Installation and Execution

Content
View full analysis
" --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-kuaishou-detail npx -y socialdatax-skills@latest kuaishou detail \ --url "" --pretty \ --source-client socialdatax-skills --source-platform clawhub \ --source-skill socialdatax-kuaishou-detail ``` ```text When the user wants to save Kuaishou media after detail, pass each returned `images[].url`, `video.play_url`, or `cover_image_url` to `npx -y socialdatax-skills@latest kuaishou download-media --url "" --output-dir --pretty`; this local save command does not require `SOCIALDATAX_API_KEY`. ``` ```text If the current environment has permission, install or restore automatically. ``` ### Technical Analysis The Skill directs the agent to fetch and execute `socialdatax-skills@latest` through `npx -y`. The `@latest` selector is mutable, so the code executed at runtime may differ from the code available when the Skill was audited. No exact version, package-lock entry, or integrity hash constrains the retrieved package. The `-y` option also suppresses the normal installation confirmation. The installation metadata similarly identifies `socialdatax-skills` without an exact version. The troubleshooting instructions encourage automatic dependency installation or restoration when permission is available, increasing the likelihood that unreviewed ...[truncated 2123 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill instructs the agent to execute npx -y socialdatax-skills@latest ..., which fetches and runs the newest package version at runtime. This creates a supply-chain risk: if the package is compromised or a breaking/malicious release is published, the agent could execute attacker-controlled code with access to the user's environment, including SOCIALDATAX_API_KEY.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This command again uses npx -y socialdatax-skills@latest, causing code to be downloaded and executed dynamically at runtime. In an agent environment, that materially increases the blast radius because any malicious update can run shell-level code and potentially access environment variables or exfiltrate user-supplied URLs and returned data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The media download guidance also relies on npx -y socialdatax-skills@latest, extending the same unpinned remote-code-execution risk to another workflow. Because this path handles arbitrary returned media URLs and writes files locally, compromise of the fetched package could lead to broader abuse such as data exfiltration or malicious file operations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.