Back to skill

Security audit

快手短视频采集

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a read-only Kuaishou API helper, but it contains under-disclosed cross-platform fallback routing and broad activation behavior that users should review before installing.

Install only if you are comfortable sending Kuaishou links, IDs, search terms, and account-linked API activity to MaxHub at www.aconfig.cn. Prefer a pinned, trusted ClawHub installer command, avoid exposing unrelated secrets during install, and review or remove the Douyin fallback paths if you intend to authorize Kuaishou-only use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:17
Finding

Unpinned npm Package Execution in English Installation Instructions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README_CN.md:17
Finding

Unpinned npm Package Execution in Chinese Installation Instructions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest presents the skill as a Kuaishou-specific assistant, but the body includes instructions and downgrade mappings for Douyin and Xiaohongshu APIs. This creates a deceptive scope mismatch that may cause requests or identifiers to be sent to unintended third-party endpoints.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
84% confidence
Finding

This duplicate finding points to the same hidden-instruction pattern: operational guidance depends on non-user-visible path annotations and reference content. Such hidden control surfaces increase the risk of prompt injection, unauthorized routing, and audit evasion.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
| 禁止行为 | 正确做法 |
|----------|----------|
| ❌ 自行拼接路径(如 `/api/v1/douyin/search/xxx`) | ✅ 使用 Action Table 或 `<!-- Full path: -->` 中的路径 |
| ❌ 猜测参数名(如把 `aweme_id` 写成 `video_id`) | ✅ 使用 Action Table 或 reference 文件中的参数名 |
| ❌ 假设 v1/v2/v3 参数兼容 | ✅ 降级时重新读取对应版本的参数文档 |
| ❌ 调用 `fetch_hot_search_list` 或 `app/v3/fetch_video_comments` | ✅ 使用替代端点(见废弃标注) |

Hidden Instructions

High
Category
Prompt Injection
Confidence
84% confidence
Finding

This duplicate finding points to the same hidden-instruction pattern: operational guidance depends on non-user-visible path annotations and reference content. Such hidden control surfaces increase the risk of prompt injection, unauthorized routing, and audit evasion.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
| 禁止行为 | 正确做法 |
|----------|----------|
| ❌ 自行拼接路径(如 `/api/v1/douyin/search/xxx`) | ✅ 使用 Action Table 或 `<!-- Full path: -->` 中的路径 |
| ❌ 猜测参数名(如把 `aweme_id` 写成 `video_id`) | ✅ 使用 Action Table 或 reference 文件中的参数名 |
| ❌ 假设 v1/v2/v3 参数兼容 | ✅ 降级时重新读取对应版本的参数文档 |
| ❌ 调用 `fetch_hot_search_list` 或 `app/v3/fetch_video_comments` | ✅ 使用替代端点(见废弃标注) |

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly claims it is a Kuaishou-only, read-only data assistant, yet later documents fallback behavior to Douyin and Xiaohongshu endpoints. That mismatch can mislead users and downstream agents about what platforms their queries may be sent to, undermining informed consent, scope restrictions, and trust boundaries.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 183)May include surrounding context.

md
| "analyze" / "分析一下" | Switch to analyze mode |
| "compare with X" / "和X对比" | Add X as second query |

## Output Guidelines

1. **Language consistency** — ALL output matches user's detected language.
2. **Markdown links** — All URLs in `[text](url)` format.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-user.md (reported line 11)May include surrounding context.

md
`GET /api/v1/kuaishou/web/fetch_get_user_id`

<!-- Full path: /api/v1/kuaishou/web/fetch_get_user_id -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-user.md (reported line 36)May include surrounding context.

md
`GET /api/v1/kuaishou/web/fetch_kuaishou_hot_list_v1`

<!-- Full path: /api/v1/kuaishou/web/fetch_kuaishou_hot_list_v1 -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-video.md (reported line 11)May include surrounding context.

md
`GET /api/v1/kuaishou/app/fetch_one_video`

<!-- Full path: /api/v1/kuaishou/app/fetch_one_video -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-video.md (reported line 61)May include surrounding context.

md
`GET /api/v1/kuaishou/app/fetch_one_video_comment`

<!-- Full path: /api/v1/kuaishou/app/fetch_one_video_comment -->

### Parameters

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx clawhub install maxhub-kuaishou without pinning a specific version of the installer package. This creates a supply-chain risk: users may execute whatever version is current at install time, including a compromised or maliciously updated package, and npx execution can run arbitrary code during installation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README lists very short example prompts such as "视频", "作品", "用户", "资料", "搜索", and "分享" without defining activation boundaries or exclusions. These terms are common, generic words that could overlap with ordinary conversation, making it unclear when the skill should activate versus when it should not.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The installation command uses npx clawhub without pinning an exact package version, so users may execute whatever version is current at install time. If the upstream package is compromised, typo-swapped, or introduces a malicious update, this README-driven workflow can cause arbitrary code execution on the user's machine during installation or runtime.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example trigger words are extremely broad everyday terms such as '视频', '用户', '搜索', and '直播', which can overlap with normal conversation and unintentionally invoke the skill. In an agent environment, accidental invocation can lead to unintended external API calls, unnecessary data exposure in prompts, or unexpected use of a configured API key.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Although the skill mentions third-party APIs in passing, it does not clearly warn users that their queried content, identifiers, and parameters will be transmitted to an external service. This weakens transparency and informed consent, especially for user data analysis workflows.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill is designed to send user-supplied query parameters and API authentication headers to an external domain, which is expected behavior but still represents real data exfiltration to a third party. In the context of a data-query skill, this is not inherently malicious, but it becomes security-relevant because users may provide sensitive identifiers or URLs without a clear transmission warning.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
maxhub_auth_header="Authorization: Bearer ${MAXHUB_API_KEY}"

# GET example
curl -s "https://www.aconfig.cn/api/v1/kuaishou/{endpoint}?{params}" \
  -H "$maxhub_auth_header"

# POST example

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger rules are broad and ambiguous, using generic terms like 'detail', 'list', 'board', 'id', and 'info', which can cause the skill to activate for unrelated requests. Over-activation increases the chance of unnecessary third-party API calls and accidental disclosure of user-provided data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This document exposes endpoints for resolving user IDs from share links and retrieving detailed user information, but it provides no privacy, consent, retention, or acceptable-use guidance. In a skill centered on large-scale social-platform data querying, that omission can encourage misuse for profiling or scraping of identifiable user data, especially because the API appears to support direct lookups by user identifier.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly points users to an external base URL and bearer-token authentication, but it does not warn that user-supplied video links, search keywords, IDs, and potentially account-linked query activity are transmitted to a third-party service. In an agent skill context, this omission can cause unintentional data disclosure because operators or downstream agents may treat the calls as local or first-party processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

Most descriptive guidance for the endpoints is written only in Chinese, even though the document header is bilingual. This can amount to a language/locale policy issue because the skill documentation effectively assumes one language for core operational details without explicitly offering user choice or documenting that the API is intentionally Chinese-only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.