Back to skill

Security audit

guaikei快手数据抓取

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real cloud video-to-text skill, but it needs Review because it uploads user videos to cloud/presigned storage while its data-destination and retention disclosures are incomplete or contradictory.

Review this before installing if your videos may be sensitive. Use it only if you are comfortable sending the selected videos or video URLs, prompts, and token-authenticated requests to GuaiKei and its presigned storage destination; verify the provider's retention and privacy terms independently.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The mismatch between claimed transcription/analysis functionality and behavior that instead accesses local package metadata and lacks the described processing is a trust-boundary violation. While not inherently code-execution, deceptive or inaccurate capability claims can cause unsafe invocation decisions and mis-scoped permissions in an agent ecosystem.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The mismatch between claimed transcription/analysis functionality and behavior that instead accesses local package metadata and lacks the described processing is a trust-boundary violation. While not inherently code-execution, deceptive or inaccurate capability claims can cause unsafe invocation decisions and mis-scoped permissions in an agent ecosystem.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The mismatch between claimed transcription/analysis functionality and behavior that instead accesses local package metadata and lacks the described processing is a trust-boundary violation. While not inherently code-execution, deceptive or inaccurate capability claims can cause unsafe invocation decisions and mis-scoped permissions in an agent ecosystem.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The mismatch between claimed transcription/analysis functionality and behavior that instead accesses local package metadata and lacks the described processing is a trust-boundary violation. While not inherently code-execution, deceptive or inaccurate capability claims can cause unsafe invocation decisions and mis-scoped permissions in an agent ecosystem.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The mismatch between claimed transcription/analysis functionality and behavior that instead accesses local package metadata and lacks the described processing is a trust-boundary violation. While not inherently code-execution, deceptive or inaccurate capability claims can cause unsafe invocation decisions and mis-scoped permissions in an agent ecosystem.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README emphasizes convenience and cloud processing but does not clearly warn users that video links, uploaded local files, and custom prompts are sent to a third-party cloud service. This creates a meaningful privacy and consent risk, especially because the skill is designed to process potentially sensitive media and user-authored instructions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README encourages broad natural-language triggering such as '总结一下' or '改写成小红书文案' without clear activation boundaries or confirmation requirements. In an agent setting, this can cause unintended execution against local files, remote URLs, or prior task IDs, leading to accidental data submission to the cloud service and confused-deputy style misuse.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.md (reported line 99)May include surrounding context.

md
4. 同时传入文件路径与任务ID,优先执行 `--id`,忽略 `--file`
5. 无自定义 prompt 时,默认完整转录视频全部文字

| 用户自然语言指令                                         | 自动生成命令                                                                                                |
| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| 视频提取 https://example.com/video.mp4 中的文字          | `node scripts/video2text/index.js --file "https://example.com/video.mp4"`                                   |
| 把本地 /path/to/your/video.mp4 改成小红书风格的文案      | `node scripts/video2text/index.js --file "/path/to/your/video.mp4" --prompt "改写成小红书风格的文案"`       |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description frames use of the skill around Chinese requests and Chinese-specific output styles such as '改写成小红书文案', while also mentioning English translation only as a specific transformation target. This creates a default language/locale expectation rather than clearly offering language choice up front.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
## 7. 🗣️ 自然语言 → 命令(照这张表转)

| 用户说的话                                           | 就执行这条命令                                                                                              |
| ---------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| 提取 https://example.com/video.mp4 里的文字          | `node scripts/video2text/index.js --file "https://example.com/video.mp4"`                                   |
| 总结这个视频的核心观点 https://example.com/video.mp4 | `node scripts/video2text/index.js --file "https://example.com/video.mp4" --prompt "总结这个视频的核心观点"` |

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The conventions section says the skill's canonical name, directory, package name, and H1 should all be guaikei-video-to-doc, but the actual frontmatter name is guaikei-kuaishou-public-scraper and the visible title is different. This is an active contradiction in the file's own intent/documentation, which can mislead agents about what skill they are invoking.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JavaScript file contains multiple natural-language strings shown in thrown errors and request labels, all in Chinese (for example at L013, L016, L026, L031, L044, L047, L057, L062, L076, L079, L089, and L094). Because the file does not provide a user language option or document that the skill is intentionally Chinese-only, it appears to enforce a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This string forces a Chinese-language user-facing error message and remediation path, which is a natural-language locale policy concern when no user opt-in or language selection is provided. The same file contains several Chinese-only error messages, but this line is the clearest policy-relevant example because it is explicitly presented to the user.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code emits all user-facing status and warning messages in Chinese, including promotional text, with no indication that the skill is China-specific or that users can select another language. This creates a natural-language locale policy issue because the skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The comment makes a privacy and retention guarantee that is not enforced anywhere in this function or evidenced by code in this file. In a skill that uploads user videos for transcription and copy generation, this can mislead users into sharing sensitive media under false assumptions about deletion and limited use, creating privacy, compliance, and trust risk if backend storage retains or repurposes the data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code presents user-facing descriptions, examples, and runtime messages entirely in Chinese, which imposes a specific language on all users. The file does not offer any language selection or explain that the skill is intentionally limited to a Chinese-speaking context, so it violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The trust section states the tool should only talk to guaikei.com and that error messages should be neutral without marketing copy, contact details, or website links. Later sections include explicit business-contact and promotional guidance, which contradicts the document's own stated intent around neutral user-facing behavior and security/trust posture.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

This section provides canned outputs centered on Chinese locales and platforms such as 小红书、抖音、公众号, with bilingual translation framed only as Chinese↔English examples. While not always inappropriate, the templates nudge a specific locale/style unless the user overrides it.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

In this manifest file, the description says the skill handles local files or public links from multiple platforms and generates several kinds of outputs, but it does not define any explicit invocation phrases, scope boundaries, or negative examples. For manifest files, this can create an overly broad activation surface because the conditions for when the skill should be invoked versus not invoked are unclear.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The package description is written entirely in Chinese and does not state that the skill is intended only for Chinese-speaking users or offer a language choice. This may violate language/locale policy expectations when the skill is distributed in a broader context without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file contains user-facing error messages, comments, and help output entirely in Chinese, including thrown errors and generated usage text. That can violate a language/locale policy when users are not given any opt-in or alternative locale selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code contains natural-language comments and runtime messages entirely in Chinese, including the function doc comment and progress/error output shown to users. The file does not offer a language choice or document that the skill is intentionally limited to a Chinese-speaking context, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The user-facing banner is hard-coded in Chinese ('视频文案智能提取助手') with no indication of locale selection or opt-in. This can violate a language/locale policy when a skill imposes one language by default rather than offering a choice or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.