Back to skill

Security audit

guaikei-douyin-posts-for-content-research

Security checks across malware telemetry and agentic risk

Overview

The skill mostly matches its Douyin research purpose, but it combines bulk public-data collection, automatic local result retention, broad activation wording, and runtime promotional contact output that contradicts its own security notes.

Review this before installing if you handle sensitive research topics or regulated data. Use it only for lawful Douyin public-data research, keep the GUAIKEI_API_TOKEN private, avoid ambiguous non-Douyin prompts, and periodically delete the generated logs if you do not need retained search, post, or comment datasets. Be aware that auth failures may show vendor contact information even though the skill text says runtime auth errors should stay neutral.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
83% confidence
Finding
The changelog claims broader capabilities than the stated skill scope, including social data search and bulk scraping of a creator’s published works. This creates scope ambiguity and may enable data collection or automation beyond what users, reviewers, or platform policy expect, increasing the risk of privacy, compliance, and misuse issues.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The CLI writes full search output, including user-supplied keywords and returned results, to a local log file even though the stated skill purpose is just to query and return Douyin content. This creates unnecessary data retention and can expose sensitive research terms or collected content to other local users, backups, or later unintended processing.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill says it should also trigger when users discuss short-video research or competitor analysis even without explicitly mentioning Douyin, which broadens activation beyond the documented platform boundary. This can cause the agent to invoke Douyin data collection in unrelated or ambiguous contexts, leading to unintended data access, workflow hijacking, or user confusion about which platform is being queried.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description includes broad colloquial triggers like '网上火啥' and '评论区啥风向', which are common phrases not uniquely tied to Douyin. In a multi-skill environment, such vague triggers increase the chance of accidental activation and may route unrelated requests into a data-collection workflow the user did not intend.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This documentation provides concrete commands for collecting Douyin creator posts, comments, and trending data at scale, including limits up to 10,000 records, but gives no guidance on privacy, terms-of-service, rate limiting, or lawful use. In a content-research skill, that omission materially lowers the barrier to bulk surveillance or scraping of user-generated content and can enable misuse of personal data.

Missing User Warnings

Low
Confidence
89% confidence
Finding
The CLI persists the full fetched results to a local JSON file automatically, without an explicit opt-in or warning to the user. Because the data comes from Douyin content research and may include account/activity details, this can create unintended local data retention, exposure to other local users/processes, and privacy/compliance issues if the file is stored in a shared or insecure location.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.