Back to skill

Security audit

快手数据分析 SocialDataX 作品研究

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned and read-only, but it asks agents to run a mutable unpinned npm package at runtime, which warrants Review before installation.

Review this before installing in sensitive environments. Prefer a pinned, reviewed version of socialdatax-skills or preinstalled tooling, expose only SOCIALDATAX_API_KEY, and run it in a sandbox with limited filesystem and network access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Unpinned Third-Party Package Download and Execution

Content
View full analysis
" --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-kuaishou-search npx -y socialdatax-skills@latest kuaishou search \ --keyword "" --pages 3 --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-kuaishou-search ``` The troubleshooting instructions also state: ```text If the current environment has permission, install or restore automatically. ``` ### Technical Analysis The Skill instructs the Agent to run `socialdatax-skills@latest` through `npx -y`. The `@latest` version selector allows the retrieved package to change after the Skill has been reviewed, while `-y` suppresses the normal installation confirmation. The additional instruction to install or restore dependencies automatically increases the likelihood that remotely supplied code will be executed without meaningful user review. The project contains no copy of the npm package source, pinned package version, lockfile, integrity hash, or signature. Consequently, the effective code executed by this Skill cannot be verified from the audited artifact. This is a supply-chain risk rather than evidence that the current package is malicious. Exploitation would require compromise or malicious publication of the package or one of its transitive dependencies. ### Attack Path 1. An attacker compromises the npm publisher account, package release process, registry resolution path, or a transitive dependency. 2. The attacker publishes a malicious release that becomes the version selected by `socialdatax-skills@latest`. 3. A user requests Kuaishou research and the Agent follows the documented `npx ...[truncated 1416 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill instructs the agent to execute npx -y socialdatax-skills@latest ..., which fetches and runs the latest package version at runtime without pinning to a reviewed release. If the npm package or one of its dependencies is compromised, the agent could execute attacker-controlled code with access to environment variables such as SOCIALDATAX_API_KEY and local agent permissions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This second example repeats the same unsafe execution pattern by invoking npx -y socialdatax-skills@latest directly from the registry. Using @latest makes behavior nondeterministic and expands the supply-chain attack surface, allowing a malicious or hijacked upstream release to run arbitrary code during skill execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.