Back to skill

Security audit

guaikei-douyin-comments-to-insight-data

Security checks across malware telemetry and agentic risk

Overview

This Douyin research skill does what it says, but it can automatically route broad requests into external social-data collection and save large result sets locally without a clear opt-out.

Review this before installing if you work with confidential research topics or regulated data. Use it only when you explicitly want Douyin data sent to guaikei.com, assume outputs may be saved under logs, and delete or protect those files when they contain comments, user identifiers, account URLs, or sensitive business research terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The CLI persists fetched comment results to a local JSON file after printing them, which creates an additional data-retention channel not apparent from the user-facing behavior in this file. Because comments may contain personal data or sensitive business research inputs, silent local storage increases privacy and data-handling risk if the host is shared, monitored, or later compromised.

Vague Triggers

High
Confidence
92% confidence
Finding
The skill instructs broad activation even when the user did not mention Douyin, causing the agent to route generic research requests into a social-media data collection workflow without clear user consent. This can lead to over-collection, unexpected third-party API use, and disclosure of user research intent or search terms to an external service.

Vague Triggers

High
Confidence
94% confidence
Finding
The generalized trigger rule for vague multi-step requests like '帮我调研一下这个赛道' encourages automatic execution in contexts where the user has not chosen the platform or consented to external collection. In skill-routing systems, this kind of overbroad invocation increases the chance of unintended data transfer, unnecessary API calls, and scope creep beyond user intent.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
Automatically saving outputs to `logs/` with timestamps and query parameters can persist sensitive search terms, target account URLs, or investigative topics to disk without prominent user warning. This creates local data-retention risk and may expose confidential research intent or regulated data to other users, backups, or later compromise of the host.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The hot-list trigger mapping uses broad phrases such as asking what is hot today, which can cause the agent to invoke this scraping skill when the user did not clearly request Douyin-specific data collection. In this skill’s context, that means unintended collection and processing of third-party platform data, increasing privacy, compliance, and least-surprise risks.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The search trigger definitions include generic verbs like 'search', 'search for', and 'find' with no strong scope boundary, making accidental invocation likely in unrelated conversations. Because this skill performs external data retrieval and local logging, overbroad routing can lead to unexpected scraping, token use, and storage of collected data without sufficiently specific user intent.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The README advertises automatic JSON export and log saving but does not prominently warn that scraped public data, including comments and account-related data, will persist locally. In this context, silent persistence increases privacy and data handling risk because users may not realize third-party content is being retained on disk for later access, sharing, or misuse.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This documentation explicitly enables bulk collection of Douyin creator posts and comments, including up to 10,000 records, but provides no guidance on privacy, consent, platform terms, retention, or handling of potentially personal data in comments. In the context of a skill whose purpose is to analyze what is trending and how audiences react, the omission increases the likelihood of misuse for profiling, surveillance, or non-compliant data harvesting.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The script writes comment data to disk without a clear user-facing warning or consent mechanism in this file, so users may reasonably expect ephemeral processing while the tool actually creates a local artifact. This transparency gap can lead to accidental retention of potentially sensitive scraped content and surprise exposure through backups, shared machines, or later inspection.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The CLI persists the full fetched result set to a local JSON file automatically after successful execution, without any explicit consent prompt or clear warning in this file. Because the tool is designed to collect Douyin profile and comment-related intelligence, the saved output may contain sensitive research data or user-generated content that remains on disk longer than intended and could be accessed by other local users, backup systems, or later processes.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.