Back to skill

Security audit

抖音作品批量下载

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Douyin public-data collection CLI that sends requested keywords or links to a third-party API and saves returned JSON results locally.

Install only if you are comfortable sending Douyin keywords or links, plus your GUAIKEI_API_TOKEN, to www.guaikei.com. Treat saved logs as retained copies of public search, creator, and comment data; delete them when no longer needed and follow Douyin terms, privacy law, and content redistribution rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (43)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code is narrowly focused on keyword search functionality, which does align with one part of the description: filtered/sorted Douyin search. However, the declared description presents a broader multi-capability skill whose advertised abilities include hot-search retrieval, creator works extraction, comment analysis, watermark-free link parsing, and local batch downloading. None of those behaviors appear in this code chunk. There is no evidence of file I/O, downloader logic, comment endpoints, hotlist endpoints, or creator-feed fetching. Therefore, the description overstates what this supplied code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a feature-rich Douyin scraping/search/download/analysis skill. However, the supplied code chunk does not implement any Douyin-specific behavior, network access, scraping, downloading, parsing of media links, or comment analysis. It is a reusable command-line argument parser and help-text generator. While such a utility could support a larger Douyin tool, this code chunk by itself materially differs from the declared purpose and lacks the advertised capabilities. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises substantial Douyin data collection, parsing, and download features. The supplied code chunk does not perform any network access, Douyin API interaction, scraping, searching, downloading, or comment analysis. It only reads package.json from the local filesystem to obtain the package name and caches the result. This is materially different from the declared primary purpose, so the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 76)May include surrounding context.

md
## 1.0.2 - 2026-03-24

- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The package description on L04 says the skill accepts keywords and Douyin profile links to fetch account works and parse watermark-free download links for batch local download. However, the exposed CLI entrypoints on L20-L23 include dedicated 'comment' and 'hot' operations, which align with broader analytics features not mentioned in the manifest description shown in this file. This is a semantic mismatch between the claimed purpose and the actually exposed functionality.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

This manifest description broadly states that the skill accepts keywords and Douyin profile links to automatically fetch and batch-download content, but it does not define specific trigger phrases, scope boundaries, or exclusion conditions. In a manifest file, such broad natural-language activation wording can cause unintended invocation because it lacks explicit constraints on when the skill should or should not run.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description advertises automatic retrieval of account works and one-click batch download to the local machine, which can affect user storage, local files, and potentially privacy-sensitive content handling. The markdown/manifest-facing description provides no warning or disclosure about these impactful behaviors.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation is entirely in Chinese and repeatedly addresses users and AI operators in Chinese only, with no indication that another language is supported or that Chinese is an explicit opt-in requirement. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation explicitly enables bulk downloading, creator work scraping, hot-search collection, and comment harvesting, but provides no warning about privacy expectations, platform terms, consent, retention, or lawful use. In this skill context, the omission matters because the tool is purpose-built for scaled collection of public content and interaction data, which increases the risk of misuse, non-compliant surveillance, or unauthorized redistribution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI silently persists fetched comment data to a local JSON file after printing results, which creates an additional undisclosed data sink beyond the stated behavior of comment retrieval/analysis. Comment content and interaction metadata can contain personal or sensitive information, and writing them to disk increases exposure through leftover files, backup systems, multi-user hosts, or later unintended reuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The program writes full comment results to a local file without user warning, consent, or confirmation, so users may believe data is only displayed transiently while it is actually retained on disk. This can expose scraped comments and metadata to other local users, endpoint monitoring tools, or future accidental disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code emits multiple user-visible messages exclusively in Chinese, including errors and success responses. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command description, examples, and subsequent user-facing messages in this file are written in Chinese only, which forces a specific language experience. The file does not offer language selection or explain that the skill is intentionally limited to a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI writes full search results and request metadata to a local JSON file, including user-supplied keywords that may reveal interests, research topics, or other sensitive activity. In a downloader/search skill, persistent local logging increases privacy and data exposure risk, especially on shared systems or when logs are stored without access controls or user consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Multiple error strings and doc comments are written only in Chinese, such as request failure and timeout messages. This imposes a specific language on users without any visible opt-in, language selection, or documented region-specific justification in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JavaScript file contains multiple natural-language error strings in Chinese, such as the messages printed at L06, L10, L14, L19, and later similar lines. Because the skill forces a specific language in user-facing output without any visible opt-in or documented regional justification in this file, it matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This is a manifest-like JSON schema file, so vague-trigger review applies. The title and description describe the skill's purpose in broad terms but do not define when it should or should not be invoked, nor provide narrow trigger phrases or exclusion conditions, which could allow overly broad activation in orchestration systems that rely on these descriptions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

Natural-language policy review applies to all file types. The title and descriptions force a single language/locale in user-facing metadata, and the file does not indicate that Chinese is optional, user-selected, or required for a documented region-specific reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema includes human-readable title and description fields entirely in Chinese, which can impose a fixed language on users or downstream tooling without any opt-in or justification. The policy specifically calls for flagging language or locale constraints when no user choice or documented regional scope is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This JSON schema contains user-facing natural-language strings entirely in Chinese, including the title and field descriptions. For a general-purpose skill asset, that can constitute a locale/language policy issue when no opt-in, alternative locale, or documented region-specific scope is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema's title and descriptions are entirely in Chinese, which imposes a specific language in user-facing metadata. There is no indication that the skill is region-specific or that users can opt into another language, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON schema uses Chinese-only title and description strings, which can impose a specific language on users or downstream tooling without any opt-in or documented locale restriction. The policy requires flagging language or locale constraints when they are forced and not justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema uses only Chinese natural-language titles and descriptions for the skill interface, which can impose a language/locale constraint on users without any opt-in or documented regional justification. The policy for this audit flags language-forcing behavior when no user choice or clear region-specific rationale is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON schema uses Chinese for the title, top-level description, and nearly all property descriptions, which imposes a specific language on users or downstream tooling. The file does not indicate that the skill is region-specific or provide any opt-in or alternative locale, matching the language-policy concern described by SQP-3.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16