Back to skill

Security audit

guaikei-douyin-author-posts

Security checks across malware telemetry and agentic risk

Overview

This is a read-only Douyin public-data tool that uses a third-party API and saves query results locally, with no evidence of deception or harmful actions.

Install only if you are comfortable sending Douyin keywords, video or author URLs, and the GUAIKEI_API_TOKEN to guaikei.com, and with returned public data being saved under the skill's local logs directory. Avoid using confidential monitoring terms or proprietary targets unless that data flow is acceptable, and delete logs when they are no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

High
Confidence
96% confidence
Finding
The description says the skill should be used '即使用户没提"抖音"或"数据"', which authorizes invocation beyond clear user intent. That can cause unnecessary collection and transmission of user prompts or derived search targets to a third-party API, increasing privacy risk and enabling overreach by the agent.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill notes third-party API dependence and data externalization only later in the document, not prominently in the main overview or invocation guidance. Users may therefore trigger the skill without realizing their keywords, links, or analysis targets will be sent to `guaikei.com`, undermining informed consent and potentially exposing sensitive business research intent.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README states that results are automatically exported as JSON logs, but it does not clearly warn that scraped public data and comment content will be persisted to local files. This can lead operators to unknowingly retain potentially sensitive or regulated data on disk, increasing exposure through local compromise, backups, log sharing, or accidental redistribution.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The README instructs users to set GUAIKEI_API_TOKEN but does not prominently disclose that this credential will be sent to an external third-party service to perform the data retrieval. Users may expose a paid or privileged token without understanding the trust boundary, which raises the risk of credential misuse, leakage through environment inspection, or unintended transmission to an external vendor.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The CLI writes the full comment retrieval output to a local JSON file automatically after successful execution, with no explicit opt-in, warning, or control over persistence. In this skill’s context, scraped public-comment datasets can still contain personal data, usernames, IDs, or sensitive analysis targets, so silently persisting them increases privacy, data-handling, and accidental exposure risk on shared systems or agent environments.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The CLI writes the full fetched results to a local JSON file derived from the queried author URL without any explicit user warning or opt-in. In this skill's context, the output may contain scraped public-profile data that can accumulate locally, creating privacy, retention, and unintended disclosure risk if the workstation, logs directory, or shared environment is accessed by others.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The CLI persists full search output to a local JSON file, including the user’s keyword and returned results, without explicit notice, consent, or an option to disable logging. In this skill’s context, the data is public Douyin data, but it may still contain sensitive research targets, monitoring topics, or operational intelligence that can be exposed to other local users, backups, or downstream tooling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.