Back to skill

Security audit

抖音评论分析

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform the advertised Douyin public-data lookups, but it automatically saves full result datasets to local log files without opt-in or retention controls.

Install only if you are comfortable sending Douyin queries and links to guaikei.com and having successful search, post, and comment results saved locally in the skill's logs directory. Treat saved logs as sensitive business and social-data artifacts, clean them up when no longer needed, and avoid using the skill in shared or synced workspaces unless retention is acceptable.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/log.js:25
Finding

Automatic Persistent Storage of Personal and Behavioral Data

Content
View full analysis
Remediation
View remediation
` or `--save-results`, and clearly disclose what fields will be retained. 3. Minimize stored content by excluding user identifiers, SEC_UID values, nicknames, IP-region labels, and comment text unless they are required for the stated purpose. 4. Create files with restrictive permissions, for example: ```js await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, flag: "wx", }); ``` 5. Implement a documented retention period and automatic deletion mechanism. 6. Provide a command for securely deleting previously retained result files. 7. Add `logs/` to `.gitignore` and packaging exclusions to reduce accidental publication. 8. Document the local persistence behavior, data categories, retention period, and access controls in `SKILL.md` and the README. 9. Consider pseudonymizing stable user identifiers and removing IP-region data before any optional persistence. 10. Add tests confirming that default executions do not create files and that opt-in output files use restrictive permissions. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音运营分析的业务技能,核心应涉及抖音内容检索、热榜数据获取、作品/评论抓取及分析输出。而提供的代码片段仅是底层通用命令行参数解析器(parseArgs/readValueAfterFlag/buildHelp),属于基础工具函数。它不访问抖音资源、不处理链接或 aweme_id/sec_uid、不做任何抓取、分析、情绪判断或建议生成。虽然这类工具代码可能作为整个项目的配套组件存在,但就该代码片段本身而言,其实际行为与声明用途存在明显且实质性的不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码片段的功能非常有限:它只使用 fs 和 path 定位到上级目录中的 package.json,读取并解析该文件,然后返回其中的 name 字段。该行为与声明中描述的抖音运营分析、数据抓取、热榜查询、评论分析等核心用途完全不一致。虽然这可能是某个辅助工具文件,但就所提供代码片段本身而言,其实际行为与声明用途存在明显的实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

该代码片段的实际职责是辅助性的 TOKEN 管理,而声明描述的是完整的抖音运营分析与数据获取技能。两者在当前片段层面存在明显功能不一致:代码没有访问抖音资源、没有执行搜索/抓取/分析,也没有输出任何用户画像、情绪舆情或运营建议。虽然 token 管理可视为支撑性实现细节,但此片段还包含面向用户的商业推广/联系方式输出,这并未在技能描述中声明。因此,就“描述是否准确代表该代码片段实际行为”而言,应判定为不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 72)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions throughout, including the top-level title/description and field descriptions. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documentation and all user-facing instructions are written entirely in Chinese, including the natural-language command mapping and operational guidance, with no indication that other languages are supported or that the user may choose their preferred language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The CLI silently persists fetched comment data to a local file without an obvious user-facing warning or opt-in. In shared workstations, CI runners, or multi-tenant agent environments, this can leave behind scraped comment content and metadata that later users or processes may access, creating an unintended data exposure risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language strings throughout the file, including comments and runtime messages such as error and success outputs, are exclusively in Chinese. There is no opt-in, locale selection mechanism, or documented justification that this skill is intentionally limited to a Chinese-language audience.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI persists fetched Douyin post results to a local JSON file after completing the request, but the skill description focuses on retrieval and analysis rather than local data retention. This creates an unnecessary data-at-rest exposure: scraped content, metadata, and potentially sensitive operational inputs can remain on disk and be accessed by other local users, backup systems, or later processes without the user's awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code writes fetched results to a local JSON file without any explicit warning, confirmation, or user-controlled output option in this file. Silent persistence is risky because users may assume the tool only prints results, while in reality it creates an additional copy on disk that can outlive the session and broaden exposure of collected content and analysis artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The tool sends user-provided search parameters to a remote API as part of its normal function, but does not clearly warn users that their inputs leave the local environment. In this skill context, search terms may reveal campaign plans, brand monitoring targets, or other sensitive operational interests, so undisclosed transmission can create confidentiality and compliance concerns.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI persists full search output to a local file, including user-supplied keywords and returned results, but does not clearly disclose that data will be stored on disk. This creates a privacy risk because sensitive business queries, account research targets, or analysis outputs may remain accessible to other local users, backups, or later processes longer than the operator expects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The string literals shown to users at L07, L11, and elsewhere in the file force Chinese-language interaction. Under the policy, a fixed language without user opt-in or a documented locale-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code constructs and sends outbound HTTPS requests containing a TOKEN header and JSON body data, which may transmit user or system data to a remote service. The file includes validation and retry logging, but no user-facing notice, confirmation, or comment/docstring warning that network transmission and token use occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The GET helper appends params to the URL and sends them, along with a TOKEN header, to an external host. Although this is expected utility behavior, this file does not provide any warning or explanatory comment disclosing that request parameters and credentials are transmitted over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JavaScript file uses Chinese for module documentation and all user-visible status/warning messages, with no indication that the user can select another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The keyword cleaning logic permits Chinese characters, ASCII letters/numbers, and a small punctuation set, while all user-facing validation/error messages are hard-coded in Chinese elsewhere in the file. This creates a locale-specific behavior and user experience without any visible opt-in, alternative locale handling, or justification that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The markdown includes free-form trigger examples such as "帮我做抖音竞品分析" and similar conversational phrases, which are broad enough to match common analytical requests without tightly specifying when this skill should be chosen over adjacent content/marketing skills. Although the document has routing guidance elsewhere, the trigger examples themselves do not include explicit negative examples or narrow constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and descriptions in this schema use Chinese exclusively, including user-facing field documentation. Because the file does not provide an alternative language option or explain that the skill is intentionally region/language-specific, it may violate a language/locale policy requiring user choice or explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The title and description fields force a specific language/locale in natural-language metadata. Under the policy, locale-specific language is only acceptable when the skill offers user choice or clearly documents a justified regional constraint, which is not present in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The schema title and description are written only in Chinese, which imposes a specific language in natural-language metadata without any indication of user opt-in or a documented locale-specific constraint. Under the policy, language restrictions should either offer choice or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The schema's natural-language fields are entirely in Chinese, including the title and property descriptions, with no indication that the skill is region-specific or that users can choose another language. Under the policy for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The schema title and description are written only in Chinese, which imposes a specific language in user-facing metadata without any indication of optional language selection or a documented region-specific constraint. Under the policy, language-only presentation can be a natural-language locale violation when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The title and descriptions are written entirely in Chinese, which imposes a specific language in the schema's user-facing metadata. The file does not indicate that the skill is intentionally China-specific or that users can opt into another language, so this appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16