Back to skill

Security audit

抖音账号拆解

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Douyin public-data lookup tool that sends user-provided keywords or links to guaikei.com and may save successful results locally, with no evidence of hidden execution or account-changing behavior.

Install only if you are comfortable sending Douyin keywords or links and your GUAIKEI_API_TOKEN to guaikei.com. Treat the returned creator, post, and comment data as retained locally in logs unless you delete it, and use the tool only for authorized public-data analysis consistent with Douyin terms and applicable privacy rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill performs local filesystem writes such as creating log directories and saving content while claiming it is read-only and 'does not upload any local files' with 'no write operations,' that is a meaningful trust-boundary violation. Users and orchestrators may grant the skill broader trust based on the documented read-only posture, while the implementation persists data locally, potentially including scraped content, links, or sensitive prompts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill performs local filesystem writes such as creating log directories and saving content while claiming it is read-only and 'does not upload any local files' with 'no write operations,' that is a meaningful trust-boundary violation. Users and orchestrators may grant the skill broader trust based on the documented read-only posture, while the implementation persists data locally, potentially including scraped content, links, or sensitive prompts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill performs local filesystem writes such as creating log directories and saving content while claiming it is read-only and 'does not upload any local files' with 'no write operations,' that is a meaningful trust-boundary violation. Users and orchestrators may grant the skill broader trust based on the documented read-only posture, while the implementation persists data locally, potentially including scraped content, links, or sensitive prompts.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 76)May include surrounding context.

md
## 1.0.2 - 2026-03-24

- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill declares use of an environment secret (GUAIKEI_API_TOKEN) and external API access, but does not define an explicit tool/permission scope such as allowed tools, network destinations, or secret usage boundaries. That makes the trust boundary implicit and increases the risk of over-broad execution or accidental secret exposure through future code changes or misconfigured runners.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is entirely in Chinese and defines invocation phrases only in Chinese, which effectively constrains use to a specific language. Under the policy, locale or language restrictions should either be optional or explicitly justified; no user opt-in or multilingual alternative is provided here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The operational instructions, prompts, and examples are all authored in Chinese, including the prescribed follow-up templates. This can amount to a language policy constraint because the skill does not offer the user a choice of language or explain why Chinese-only operation is necessary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description contains many broad natural-language trigger phrases such as account analysis, competitor analysis, data scraping, and diagnosis requests. In agent-routing systems, overly expansive trigger text can cause the skill to activate for loosely related user prompts, leading to unnecessary access to scraping/analysis capabilities and possible over-collection of third-party platform data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire README is written in Chinese and includes no indication that other languages are supported or that the user can choose their preferred language. Under the policy rule, a skill that effectively imposes a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file title and all release notes are written exclusively in Chinese, with no indication that the skill is region-specific or that users may choose another language. Under the language/locale policy, forcing a single language without opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation explicitly guides collection of Douyin account, post, and comment data at scale, including profile URLs, sec_uid values, interaction metrics, and comment retrieval, but provides no warning about privacy, consent, retention, or platform terms. In the context of an account-teardown skill built to reverse-engineer creators and competitors, this omission increases the likelihood of misuse for profiling, surveillance, or non-compliant data harvesting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The function sends the user-provided video URL and a token to an external API via requestApi, which is a data-transmitting network operation. While there are developer-facing comments, this file contains no confirmation prompt or user-facing disclosure that these values are being sent off-box.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This function performs a GET request to a remote API and includes the video URL, comment limit, and token in the request context. The operation is externally networked and data-bearing, but the file provides only developer documentation, not a user-facing notice or confirmation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language content in comments and JSDoc forces a specific language/locale for readers and maintainers. Under the policy, language-specific instructions are a violation unless the skill offers user opt-in or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code performs an outbound API call that transmits a skill token and a user-supplied Douyin profile URL, which can affect privacy and external data handling. While the function docstring describes parameters and API failure, it does not provide any user-facing warning, confirmation, or disclosure about transmitting this data to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This GET request sends potentially sensitive operational data, including the authentication token and target profile URL, to a remote endpoint. The code includes no visible confirmation prompt, print/log disclosure, or warning comment indicating to users that their input and credentials are being sent externally.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI persists fetched Douyin account/post data to a local JSON file after completing the request, even though this behavior is not surfaced in the user-facing flow. Persisting scraped profile and post data expands the data exposure window: sensitive or proprietary analysis outputs may remain on disk, be collected by other local processes, or be unintentionally committed/shared.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The tool writes fetched post results to a timestamped local JSON file without any explicit warning, consent step, or output-path control in this CLI flow. Undisclosed persistence can surprise operators and create privacy, compliance, or data handling issues, especially for a skill centered on collecting and analyzing third-party account data at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes full search results to a local JSON file using a filename derived from user input, without clearly informing the user that data will be persisted. In this skill's context, the results can contain scraped competitor/account analysis data and potentially sensitive operational intelligence, so silent retention increases the risk of unintended disclosure to other local users, backup systems, or downstream tooling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes Douyin data retrieval and analysis capabilities such as search, hot topics, account work scraping, and comment analysis. This helper creates directories and writes arbitrary content into a local logs folder, which is a persistence capability not mentioned or obviously required by the user-facing skill purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code returns multiple natural-language messages such as "请求失败" directly in Chinese, and similar fixed-language strings appear elsewhere in the file. Because the skill forces a specific language in user-visible errors without user opt-in or any documented locale justification, it violates the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The exceptions raised for parse, auth, and HTTP failures include Chinese-only messages such as "响应解析失败", "GUAIKEI_API_TOKEN 无效, 请检查环境变量", and "请求失败, 状态码". These are user-facing natural-language strings and impose a language choice without offering alternatives or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Several thrown errors and validation messages in this range are written only in Chinese, including timeout and input-validation text. This is a natural-language policy issue because the skill presents a fixed language to users without opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code emits user-visible status and error messages only in Chinese via string literals. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits all user-facing validation errors in Chinese string literals, which imposes a specific language on users without any opt-in or locale selection. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16