Back to skill

Security audit

guaikei-douyin-trending-videos-and-rankings

Security checks across malware telemetry and agentic risk

Overview

This is a real Douyin public-data research tool, but it needs Review because its activation scope, saved outputs, and download/contact disclosures do not fully match its stated limits.

Install only if you are comfortable sending Douyin keywords, URLs/IDs, and the GUAIKEI token to guaikei.com, and with result JSON files being saved locally by default. Confirm Douyin is intended before using it for broad short-video research, and do not use the returned media URLs as a video-download workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The schema explicitly documents `video_url` as both playback and download addresses, which conflicts with the skill’s stated restriction that it is not for downloading videos. This mismatch can enable downstream agents or users to discover and use download-capable URLs, expanding the skill’s effective behavior beyond its declared scope and potentially creating policy, compliance, or abuse risks.

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The schema explicitly documents `play_addr` as both a playback URL and a video download address, which conflicts with the skill’s stated scope that it is not for downloading videos. Even though this file is only a schema, exposing and normalizing a download-capable field can enable downstream agents or users to retrieve media in ways the skill claims to prohibit, increasing policy and misuse risk.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The CLI writes fetched comment results to a local JSON file by default, even though the skill is described as a read/query tool. Comments can contain personal data, usernames, opinions, or other sensitive content, and silently persisting them increases the data-retention and local exposure surface beyond what a user may expect from a lookup command.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The CLI persists retrieved Douyin post data to a local JSON file after completing a read/query operation. Even if intended for debugging or auditability, this creates an unnecessary data-at-rest copy of potentially sensitive research targets and user activity, increasing exposure if the host is shared, compromised, or logs are later reused unexpectedly.

Vague Triggers

High
Confidence
90% confidence
Finding
The description says the skill should be used even when the user did not mention Douyin, which broadens activation beyond the named platform and can cause unintended invocation in unrelated short-video research tasks. Overbroad routing increases the chance of sending user queries, URLs, or analysis requests to this external-data skill when the user did not intend Douyin-specific collection.

Vague Triggers

High
Confidence
92% confidence
Finding
The generalized activation guidance for multi-step workflows encourages automatic triggering when a task is loosely phrased, such as generic market or content research. In a tool-using agent, this can lead to inappropriate collection from Douyin, scope creep across platforms, and unintended external API use without clear user consent or platform specificity.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The tool sends the supplied Douyin URL/identifier to a remote API and later writes returned data to disk, but this file provides no explicit notice or consent mechanism for those side effects. In a skill presented as a querying/analysis utility, silently transmitting identifiers and persisting results can surprise users and expand privacy and data-handling risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.