Back to skill

Security audit

抖音评论分析与用户洞察

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Douyin public-data CLI that sends user-provided queries or links to a third-party API and saves some results locally for analysis.

Install only if you are comfortable sending Douyin keywords, links or IDs to www.guaikei.com with your GUAIKEI_API_TOKEN. Be aware that search, creator-post, and comment results are saved locally under the skill's logs directory by default.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (42)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向抖音内容与评论分析的业务型技能,涉及外部数据查询、抓取和分析。给出的代码片段却仅是底层通用工具函数:解析 CLI 参数、校验 flag 值、处理默认值/必填项、生成帮助文案。这类代码可作为其他功能的配套组件,但就该片段本身而言,并未展示任何与抖音平台、评论内容、热榜、作品列表或分析逻辑相关的实现。因此该代码片段的实际行为与声明用途存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向抖音内容检索与评论分析的技能,核心能力应涉及网络请求、数据获取、筛选排序和分析处理。而提供的代码片段只是在本地文件系统中安全地写日志,属于通用辅助功能,且使用了文件系统资源(fs、path、本地 logs 目录)而非抖音相关数据源。虽然日志模块可能是整个技能的配套实现细节,但就该代码片段本身而言,其实际行为与声明的业务功能没有直接对应,且包含未声明的本地写文件能力,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音数据检索与评论分析的技能,涉及外部内容查询、抓取、分析和洞察输出。而提供的代码片段只是一个本地工具函数:读取 package.json 获取技能名并做缓存。这属于内部辅助实现,但就该代码片段本身而言,与声明的核心功能没有直接对应关系,也没有体现任何已声明的四项能力。由于实际行为与声明目的在本片段中明显不一致,应判定为存在描述与行为不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 76)May include surrounding context.

md
## 1.0.2 - 2026-03-24

- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON schema contains user-facing title and description text only in Chinese, which imposes a specific language/locale without any opt-in or documented justification. The policy explicitly flags language or locale constraints when the skill does not offer user choice or explain a region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This manifest-style JSON schema uses Chinese-only title and description fields for the skill and its required argument, with no indication that the skill is region-specific or that another language is supported. Under the policy, forcing a specific language without user opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON schema includes human-readable title and description fields exclusively in Chinese, which imposes a specific language on users and integrators. The file does not indicate that the skill is intentionally region-specific or provide any opt-in or alternative locale, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documentation is presented entirely in Chinese and does not indicate that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The title and all changelog entries are written in Chinese, and the file does not mention any option for users to choose a different language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Manifest 将技能范围限定为四项能力:关键词搜索、热榜查询、博主作品抓取、视频评论分析。但更新日志在此处声明“增加获取抖音博主互动数据的功能”,这是一项不同于“公开作品列表抓取”的额外数据能力,表明文档宣称的实际功能边界可能已超出 manifest 描述。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI persists fetched comment data to a local JSON file by default after printing the results, but there is no explicit warning or opt-in before storing potentially sensitive user-generated content. In this skill's context, comment text and interaction data may contain personal information or business-sensitive research inputs, so silent local persistence increases privacy, compliance, and data-retention risk if the workstation is shared or logs are later exfiltrated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code presents user-facing strings such as errors, status messages, and comments only in Chinese, which effectively forces a specific language on users. The file does not indicate that the skill is region-specific or provide any opt-in or alternative locale handling.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI persists the full fetched results to a local JSON file without any user opt-in or documented need in the stated skill behavior. Because the results may contain scraped public profile/post data and potentially derived metadata, this creates unintended local data retention and possible privacy or data-governance issues if the host environment is shared or logs are later exfiltrated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code presents user-facing help and status text in Chinese, and the pattern continues throughout the file. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the tool is clearly documented as region- or locale-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Multiple user-visible string literals in this file are fixed in Chinese, including request failures, timeout/network errors, parameter validation, and retry logs. There is no indication of locale selection, fallback, or user opt-in, so the skill appears to enforce a specific language policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains multiple user-facing error strings in Chinese, which effectively forces a specific language for the skill's interaction. Under the policy, hard-coding a locale without user choice or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The title and description fields force a specific language in natural-language metadata, which can violate a language/locale policy when no user opt-in or documented regional scope is provided. Because this is a general JSON schema rather than a clearly region-scoped compliance artifact, the single-language constraint should be called out.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The schema's human-readable title and description fields, as well as all property descriptions, are written only in Chinese. For a general-purpose skill asset, this imposes a specific language/locale in natural-language metadata without any opt-in or documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON schema contains human-facing natural-language fields entirely in Chinese, including the title and description, with no indication that the skill is region-specific or that other languages are supported. Under the policy rule for language or locale constraints, this can be a natural-language policy issue because it imposes a specific language without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON schema contains user-facing title and description strings exclusively in Chinese, including the field descriptions. Because the file does not indicate that the skill is region-specific or provide any user opt-in for language selection, it may violate the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The package description is written only in Chinese, which may imply the skill is intended to operate in a specific language without any documented user opt-in or explicit locale scoping. Under the policy, forced language behavior should be documented as a justified locale constraint or presented as a user choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Manifest 重点描述的是从抖音评论和相关内容中归纳消费者问题、购买顾虑、反馈和情绪证据,并列出的第三项能力仅为按主页链接或 sec_uid 获取公开作品列表。这里的“竞品账号内容批量抓取”“竞品监控”表述将技能用途扩展到竞争情报/批量抓取场景,和当前 manifest 的用户洞察导向存在语义偏移。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

此处更新日志写明技能提供“视频、图文、用户及社交数据搜索”,而当前 manifest 只声明关键词搜索、热榜、博主作品抓取和视频评论分析。尤其“用户及社交数据搜索”并非 manifest 明示能力,说明技能文档历史上对能力边界的表述比当前声明更宽。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

标题及整份说明文档均以中文呈现,未见任何语言选择、双语支持或对中文限定范围的说明。根据规则,强制特定语言且未提供用户选择,属于自然语言层面的语言/区域政策风险。

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16