T08 · Insecure Dependencies
- Location
README.md:17- Finding
Unpinned npm Package Execution in English Installation Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a read-only Kuaishou API helper, but it contains under-disclosed cross-platform fallback routing and broad activation behavior that users should review before installing.
Install only if you are comfortable sending Kuaishou links, IDs, search terms, and account-linked API activity to MaxHub at www.aconfig.cn. Prefer a pinned, trusted ClawHub installer command, avoid exposing unrelated secrets during install, and review or remove the Douyin fallback paths if you intend to authorize Kuaishou-only use.
README.md:17Unpinned npm Package Execution in English Installation Instructions
README_CN.md:17Unpinned npm Package Execution in Chinese Installation Instructions
The manifest presents the skill as a Kuaishou-specific assistant, but the body includes instructions and downgrade mappings for Douyin and Xiaohongshu APIs. This creates a deceptive scope mismatch that may cause requests or identifiers to be sent to unintended third-party endpoints.
This duplicate finding points to the same hidden-instruction pattern: operational guidance depends on non-user-visible path annotations and reference content. Such hidden control surfaces increase the risk of prompt injection, unauthorized routing, and audit evasion.
| 禁止行为 | 正确做法 |
|----------|----------|
| ❌ 自行拼接路径(如 `/api/v1/douyin/search/xxx`) | ✅ 使用 Action Table 或 `<!-- Full path: -->` 中的路径 |
| ❌ 猜测参数名(如把 `aweme_id` 写成 `video_id`) | ✅ 使用 Action Table 或 reference 文件中的参数名 |
| ❌ 假设 v1/v2/v3 参数兼容 | ✅ 降级时重新读取对应版本的参数文档 |
| ❌ 调用 `fetch_hot_search_list` 或 `app/v3/fetch_video_comments` | ✅ 使用替代端点(见废弃标注) |
This duplicate finding points to the same hidden-instruction pattern: operational guidance depends on non-user-visible path annotations and reference content. Such hidden control surfaces increase the risk of prompt injection, unauthorized routing, and audit evasion.
| 禁止行为 | 正确做法 |
|----------|----------|
| ❌ 自行拼接路径(如 `/api/v1/douyin/search/xxx`) | ✅ 使用 Action Table 或 `<!-- Full path: -->` 中的路径 |
| ❌ 猜测参数名(如把 `aweme_id` 写成 `video_id`) | ✅ 使用 Action Table 或 reference 文件中的参数名 |
| ❌ 假设 v1/v2/v3 参数兼容 | ✅ 降级时重新读取对应版本的参数文档 |
| ❌ 调用 `fetch_hot_search_list` 或 `app/v3/fetch_video_comments` | ✅ 使用替代端点(见废弃标注) |
The skill explicitly claims it is a Kuaishou-only, read-only data assistant, yet later documents fallback behavior to Douyin and Xiaohongshu endpoints. That mismatch can mislead users and downstream agents about what platforms their queries may be sent to, undermining informed consent, scope restrictions, and trust boundaries.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
| "analyze" / "分析一下" | Switch to analyze mode |
| "compare with X" / "和X对比" | Add X as second query |
## Output Guidelines
1. **Language consistency** — ALL output matches user's detected language.
2. **Markdown links** — All URLs in `[text](url)` format.
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/kuaishou/web/fetch_get_user_id`
<!-- Full path: /api/v1/kuaishou/web/fetch_get_user_id -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/kuaishou/web/fetch_kuaishou_hot_list_v1`
<!-- Full path: /api/v1/kuaishou/web/fetch_kuaishou_hot_list_v1 -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/kuaishou/app/fetch_one_video`
<!-- Full path: /api/v1/kuaishou/app/fetch_one_video -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/kuaishou/app/fetch_one_video_comment`
<!-- Full path: /api/v1/kuaishou/app/fetch_one_video_comment -->
### Parameters
The README instructs users to run npx clawhub install maxhub-kuaishou without pinning a specific version of the installer package. This creates a supply-chain risk: users may execute whatever version is current at install time, including a compromised or maliciously updated package, and npx execution can run arbitrary code during installation.
The README lists very short example prompts such as "视频", "作品", "用户", "资料", "搜索", and "分享" without defining activation boundaries or exclusions. These terms are common, generic words that could overlap with ordinary conversation, making it unclear when the skill should activate versus when it should not.
The installation command uses npx clawhub without pinning an exact package version, so users may execute whatever version is current at install time. If the upstream package is compromised, typo-swapped, or introduces a malicious update, this README-driven workflow can cause arbitrary code execution on the user's machine during installation or runtime.
The example trigger words are extremely broad everyday terms such as '视频', '用户', '搜索', and '直播', which can overlap with normal conversation and unintentionally invoke the skill. In an agent environment, accidental invocation can lead to unintended external API calls, unnecessary data exposure in prompts, or unexpected use of a configured API key.
Although the skill mentions third-party APIs in passing, it does not clearly warn users that their queried content, identifiers, and parameters will be transmitted to an external service. This weakens transparency and informed consent, especially for user data analysis workflows.
The skill is designed to send user-supplied query parameters and API authentication headers to an external domain, which is expected behavior but still represents real data exfiltration to a third party. In the context of a data-query skill, this is not inherently malicious, but it becomes security-relevant because users may provide sensitive identifiers or URLs without a clear transmission warning.
maxhub_auth_header="Authorization: Bearer ${MAXHUB_API_KEY}"
# GET example
curl -s "https://www.aconfig.cn/api/v1/kuaishou/{endpoint}?{params}" \
-H "$maxhub_auth_header"
# POST example
The trigger rules are broad and ambiguous, using generic terms like 'detail', 'list', 'board', 'id', and 'info', which can cause the skill to activate for unrelated requests. Over-activation increases the chance of unnecessary third-party API calls and accidental disclosure of user-provided data.
This document exposes endpoints for resolving user IDs from share links and retrieving detailed user information, but it provides no privacy, consent, retention, or acceptable-use guidance. In a skill centered on large-scale social-platform data querying, that omission can encourage misuse for profiling or scraping of identifiable user data, especially because the API appears to support direct lookups by user identifier.
The documentation explicitly points users to an external base URL and bearer-token authentication, but it does not warn that user-supplied video links, search keywords, IDs, and potentially account-linked query activity are transmitted to a third-party service. In an agent skill context, this omission can cause unintentional data disclosure because operators or downstream agents may treat the calls as local or first-party processing.
Most descriptive guidance for the endpoints is written only in Chinese, even though the document header is bilingual. This can amount to a language/locale policy issue because the skill documentation effectively assumes one language for core operational details without explicitly offering user choice or documenting that the API is intentionally Chinese-only.
No suspicious patterns detected.