Back to skill

Security audit

抖音数据分析 作品详情 作品评论

Security checks for vulnerabilities and agentic risk

Overview

The skill largely does what it claims, but it needs review because it sends the API token in request URLs and automatically saves collected Douyin data locally.

Install only if you are comfortable sending Douyin keywords, profile/video URLs, and your GUAIKEI_API_TOKEN to guaikei.com. Treat the token as sensitive, rotate it if exposed, avoid using this on shared machines for sensitive research, and review or delete the generated logs because they may contain public usernames, IDs, comments, URLs, and your research queries.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:94
Finding

API Token Exposed in URL Query Parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:25
Finding

Automatic Persistence of Collected Social-Media Data Without Restrictive Permissions or Retention Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (47)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音的数据采集与分析技能,但实际代码片段只是通用参数解析器(parseArgs、readValueAfterFlag、buildHelp)。它没有请求网络、没有处理抖音链接/aweme_id/sec_uid、没有搜索、抓取、评论分析、热榜查询或任何抖音专用逻辑。该代码更像底层辅助模块,而非所声明技能的核心或可见能力。因此描述与实际行为存在明显且实质性的不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向抖音的数据采集与分析技能,核心能力应涉及网络查询、内容抓取、热榜获取、评论分析等。而给出的代码片段只是在本地文件系统中写日志文件,属于通用辅助工具,没有任何抖音相关逻辑、API 调用、链接解析、搜索、抓取或分析处理。虽然日志功能可以作为支持性实现细节存在,但如果把这段代码单独拿来对照声明,其实际行为与声明用途明显不一致,且包含未声明的本地文件写入能力。因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

该代码片段的实际功能只是一个辅助工具函数:定位到 package.json,读取文件内容并返回其中的 name 字段。它访问的资源是本地文件系统,而不是抖音相关接口、网络数据源或分析逻辑。声明描述的是一个完整的抖音分析与抓取技能,但当前代码片段未体现任何相关实现,因此代码行为与声明用途存在明显且实质性的不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音的数据采集与分析技能,但当前代码片段只包含 token 管理模块。它验证 token 的长度与字符格式,并在无效时输出获取私有 TOKEN 的广告式提示信息,未执行任何与抖音相关的数据访问、解析、筛选、排序、评论分析、热榜查询或作品抓取操作。虽然 token 校验可视为某些技能的支持性实现,但就该代码片段本身而言,其实际行为与声明的核心能力明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 72)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares use of an environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool/permission scope such as allowed tools or environment access boundaries. This weakens least-privilege controls and makes it harder for a host runtime to constrain what the skill may access, even though the file itself only documents a single token requirement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes broad phrases such as content analysis, competitor analysis, marketing, trend tracking, and social listening, which may cause the skill to be invoked for loosely related requests beyond a narrow Douyin-only scope. Over-broad activation can route unrelated user queries into a third-party data skill, increasing unnecessary data exposure and the chance of unintended external API calls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README promotes fetching public comments, author data, and exporting JSON logs, but it does not clearly warn users that this content may include personal or sensitive public-platform data that will be stored locally. In a scraping/analytics skill, that omission increases the risk of unintended collection, retention, and mishandling of personal data, especially when logs are automatically written to disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file title is entirely in Chinese and the changelog provides no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown documentation forces a specific language/locale for all users by presenting all instructions and parameter explanations only in Chinese. The policy allows locale constraints only when the skill offers user choice or clearly documents a justified region-specific limitation, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code sends a token and user-provided Douyin video URL to external API endpoints via requestApi, which is a data-transmitting network operation. The file includes function docstrings, but they describe parameters and errors rather than warning users that their token and URL will be transmitted to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The GET request includes the token and video URL in request parameters, which sends potentially sensitive or user-associated data to an external service. There is no visible confirmation prompt, warning string, or explicit disclosure in this file that informs users of this transmission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file's natural-language content, including the module description and parameter documentation, is entirely in Chinese with no indication of language choice or opt-in. Under the stated policy, forcing a specific language without user choice is a locale/language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code sends a skill token and user-supplied Douyin profile URL to remote API endpoints via requestApi in both task creation and task lookup paths. While the functions are documented for developers, there is no visible confirmation prompt, user-facing notice, or disclosure in this file that user data will be transmitted over the network.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI persists fetched comment data to a local JSON file even though the skill is described as a query/analytics tool. Comment content and interaction data can contain sensitive or regulated information, and writing it to disk creates an undisclosed retention channel that increases exposure through local file leakage, reuse by other processes, or accidental inclusion in logs/artifacts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The CLI persists the full fetched results to a local JSON file after completing the query, even though the skill is presented primarily as a query/analysis tool. This creates an undisclosed data-at-rest copy of potentially sensitive research data, expanding exposure through local filesystem access, backups, or shared environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The program writes fetched results to disk automatically without explicit user confirmation or a clearly disclosed save option. In analyst or shared-host environments, silent persistence can surprise users and leave behind local artifacts containing scraped content or metadata that others may access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The code accesses process.env.GUAIKEI_API_TOKEN and uses it to create and fetch remote search tasks, which implies outbound network requests involving user-supplied keywords. Although the CLI prints status messages, it does not clearly disclose in help or comments that it uses an external API and transmits query data with credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI writes full search results and request metadata to a local file by default, which can persist potentially sensitive research terms, content analysis targets, and retrieved data without explicit user consent. In multi-user systems, CI runners, shared workstations, or environments with weak filesystem permissions, this creates avoidable data exposure and retention risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code performs outbound HTTPS requests and may transmit URL parameters and JSON payload data, but the file provides no user-facing disclosure such as a prompt, print statement, or warning comment describing that network transmission occurs. Under the code-file criteria, network calls that transmit user or system data should have some visible disclosure unless that warning is provided elsewhere in markdown documentation or is clearly implicit in the skill's stated purpose, which is not evident from this file alone.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains user-facing natural-language messages in Chinese, and similar hard-coded messages appear throughout the file, without offering the user a language or locale choice. That can violate language/locale policy when a skill forces a specific language without explicit opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing messages in this file are entirely in Chinese, including warnings and status output, with no indication that the skill supports other languages or that Chinese is a required locale. This can violate language/locale policy when users are not given an explicit opt-in or a documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function constructs all user-facing text in Chinese, including headings and labels, with no indication that the skill is region-specific or that users can opt into another language. This creates a natural-language policy concern because it forces a specific language on all users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file’s user-facing comments and error/output strings are entirely in Chinese, including validation errors and the formatted result message. This indicates a fixed language/locale behavior without any visible opt-in, fallback, or justification for being region-specific, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language usage instructions, trigger phrases, and operating guidance are predominantly fixed in Chinese, which can amount to forcing a specific language without user opt-in. The file does not state that the skill is intended only for Chinese-speaking users or offer an alternative language option.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:24