Back to skill

Security audit

快手数据助手 SocialDataX

Security checks for vulnerabilities and agentic risk

Overview

The skill is for read-only Kuaishou research, but it repeatedly tells agents to run an unpinned npm package that can change at runtime while exposing the SocialDataX API key.

Install only if you are comfortable trusting the current and future npm releases of `socialdatax-skills`. Prefer a pinned, reviewed package version and expose only `SOCIALDATAX_API_KEY` needed for SocialDataX calls in a restricted environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:25
Finding

Unpinned npm Package Is Downloaded and Executed Without Confirmation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:25-27 (the same pattern recurs at lines 29-92; related unversioned installation metadata appears at line 7, and automatic dependency restoration is encouraged at line 130)
Vulnerability Type: T08: Insecure Dependencies
Risk Level: High

Vulnerable Code:

bash
npx -y socialdatax-skills@latest kuaishou hot-search \
  --pretty --source-client socialdatax-skills --source-platform clawhub \
  --source-skill socialdatax-kuaishou

Related configuration and instructions:

yaml
metadata: {"openclaw":{"requires":{"env":["SOCIALDATAX_API_KEY"],"bins":["node","npm"]},"primaryEnv":"SOCIALDATAX_API_KEY","install":[{"kind":"node","package":"socialdatax-skills","bins":[]}],"emoji":"⚡","homepage":"https://socialdatax.com/ai?from=clawhub"}}
text
If the current environment has permission, install or restore automatically.

Technical Analysis

The Skill repeatedly invokes socialdatax-skills@latest through npx -y. The latest npm tag is mutable and can resolve to a different package version after the Skill has been reviewed. The -y option suppresses the normal installation confirmation, causing the resolved package to be downloaded and executed automatically.

The package implementation is not included in the audited project, so its behavior, network access, credential handling, and installation lifecycle scripts cannot be verified from this artifact. The metadata also specifies the package without an exact version, while the troubleshooting instructions encourage automatic installation or restoration.

This creates a supply-chain execution path in which code that was not present during the audit can run with the Agent's operating-system permissions. Exploitation would require compromise of the package, its maintainer account, the npm distribution path, or another mechanism that causes the package name or mutable tag to resolve to malicious c ...[truncated 1639 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace socialdatax-skills@latest with an audited, exact package version, for example socialdatax-skills@X.Y.Z.
  2. Pin the dependency in package.json and commit a lockfile containing integrity hashes rather than downloading a mutable release for every operation.
  3. Use npm ci --ignore-scripts where package lifecycle scripts are unnecessary. If scripts are required, review and explicitly authorize them.
  4. Remove -y from ad hoc remote package execution or require explicit approval before downloading and executing a previously unavailable version.
  5. Add an exact version to the Skill installation metadata instead of using an unversioned package reference.
  6. Do not automatically restore dependencies without verifying the expected version, integrity hash, registry, and package provenance.
  7. Configure npm to use a trusted registry and enable provenance or signature verification where supported.
  8. Run the CLI in a restricted environment with minimal filesystem access, limited outbound network access, and only the required API key exposed.
  9. Establish an update process in which new dependency versions are reviewed, tested, and deliberately pinned before deployment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (17)

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill instructs the agent to execute code fetched at runtime via npx -y socialdatax-skills@latest. Using @latest means the exact package version is uncontrolled and can change between runs; if the npm package or publisher account is compromised, the agent could execute attacker-supplied code with access to the runtime environment, including SOCIALDATAX_API_KEY.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This command uses npx with socialdatax-skills@latest, causing unpinned remote code execution at invocation time. Any future malicious or broken release would be automatically trusted and run by the agent, which is especially risky because the skill expects a sensitive API key in the environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The documented CLI invocation pulls and runs the latest npm package version instead of a fixed release. That creates a supply-chain risk where package compromise, typosquatting, or an unsafe new release can immediately affect users of this skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Because the skill encourages direct execution of socialdatax-skills@latest, the trust boundary extends to npm publication state at runtime. An attacker controlling the package distribution path could execute arbitrary code and potentially exfiltrate environment variables or alter returned data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This example is another instance of unpinned package execution through npx. The danger is not the specific Kuaishou action, but the generic ability for any changed upstream package contents to run with the agent's privileges and network access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill's command line fetches executable code on demand without version pinning, exposing users to npm supply-chain compromise. Since the skill advertises using SOCIALDATAX_API_KEY, compromise could lead to credential theft or silent misuse of the external data service.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Executing npx -y socialdatax-skills@latest delegates code trust to the most recent npm publish event. If the upstream package changes maliciously or unexpectedly, the agent will run arbitrary code before performing the read-only data query described by the skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This command uses an unpinned latest tag for executable package resolution, which is a real supply-chain vulnerability pattern. The surrounding 'read-only' description does not mitigate that the fetched code itself could perform arbitrary local actions or network exfiltration.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The latest-tag npx invocation allows upstream package drift to change what code runs over time. In an agent environment, that materially increases risk because the command may inherit credentials, filesystem access, and network permissions beyond what the skill text implies.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This is another true instance of runtime execution of an unpinned npm package. Even though the feature is comment retrieval, compromise of the CLI package could lead to arbitrary code execution, false data, or credential leakage independent of the nominal business function.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The command resolves to whatever package version npm marks as latest at the time of execution. That is unsafe for a skill because it removes reproducibility and creates a direct path for malicious updates or account compromise to affect every user automatically.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This example shares the same supply-chain weakness: unpinned remote code execution through npx. The skill context increases concern because it explicitly relies on an environment-stored API key, which untrusted package code could read and exfiltrate.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Using socialdatax-skills@latest means the code path is mutable and controlled by the upstream package publisher at runtime. A compromised or malicious release could abuse the host environment despite the skill being described as read-only at the application level.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The risk here is a standard but important npm supply-chain issue: dynamically executing an unpinned package. Because the command may process attacker-controlled URLs/share text and run with agent privileges, any package compromise could have broad impact beyond the intended data lookup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This invocation also relies on @latest, making the executed code non-deterministic and externally mutable. In practice, that can enable arbitrary code execution, data tampering, or secret exfiltration if the npm package supply chain is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The final CLI example repeats the same unpinned npx pattern, so it remains a true vulnerability. The skill's repeated recommendation of this pattern amplifies exposure by normalizing unsafe execution across many workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.