Back to skill

Security audit

抖音竞品分析与品牌对比

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a disclosed Douyin public-data analysis tool that uses a third-party API token and saves fetched results locally for analysis.

Install only if you are comfortable sending Douyin search terms, profile/video links, limits, and your GUAIKEI_API_TOKEN to www.guaikei.com. Be aware that successful search, post, and comment calls save full JSON results locally in the skill’s logs directory, so avoid using it in shared or synced folders if the retrieved business or social-media data is sensitive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (37)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation performs local filesystem writes that are not disclosed in the skill description, that is a meaningful security concern because users and hosting agents may authorize a read-only analytics skill while it modifies local state. Undocumented write capability can enable data tampering, persistence, or accidental leakage through generated files, especially in automation environments that trust the declared behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation performs local filesystem writes that are not disclosed in the skill description, that is a meaningful security concern because users and hosting agents may authorize a read-only analytics skill while it modifies local state. Undocumented write capability can enable data tampering, persistence, or accidental leakage through generated files, especially in automation environments that trust the declared behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation performs local filesystem writes that are not disclosed in the skill description, that is a meaningful security concern because users and hosting agents may authorize a read-only analytics skill while it modifies local state. Undocumented write capability can enable data tampering, persistence, or accidental leakage through generated files, especially in automation environments that trust the declared behavior.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 76)May include surrounding context.

md
## 1.0.2 - 2026-03-24

- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON manifest-like schema applies natural-language metadata in a single fixed language, which can violate language/locale policy when no user opt-in or documented region-specific constraint is provided. The title and description indicate the skill is presented only in Chinese, but the file does not state that the skill is region-specific or that users can choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This manifest contains natural-language user-facing metadata in a single forced language, which can violate a language/locale policy when no opt-in or alternative is provided. The description does not indicate that the skill is intentionally limited to Chinese-speaking users or a China-specific compliance context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown skill description forces a specific language/locale for all users and does not indicate that Chinese is optional or limited to a China-specific audience. Under the stated policy, a skill should not impose a language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file title and all changelog content are written exclusively in Chinese, with no indication that the skill offers a language or locale choice. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code uses Chinese-only natural-language strings for the function description, error messages, and success output, such as on L027-L028, L038, L048, L060, L064, L086, and L097. That enforces a specific language/locale without any visible opt-in, fallback, or justification, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The calls to post.createPostTask and post.getPostTask send the normalized url and limit together with an API token, indicating network transmission of user-provided data. This CLI file does not clearly warn the user that invoking the command will send the supplied identifier or profile URL to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI writes the full fetched results to a local JSON file automatically, with no explicit notice, consent, or opt-in control at the point of execution. Because the output can contain scraped social-media data and potentially sensitive business intelligence or personal data, this creates a privacy and data-handling risk if the file is stored on shared systems, synced directories, or insecure locations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI writes the full search output, including query parameters and returned Douyin content data, to a local JSON file by default without obtaining user consent or clearly disclosing retention. In this skill context, saved result sets may contain sensitive business intelligence, research targets, or potentially personal data from public profiles/comments, creating unnecessary local data exposure if the host is shared, monitored, or later exfiltrated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code constructs outbound HTTPS API requests with a TOKEN header and sends request parameters and JSON payloads to a remote host. While the file has internal comments and retry logging, it does not provide any user-facing warning, confirmation, or disclosure that user/system data and credentials may be transmitted over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JavaScript file contains multiple user-facing validation/error strings only in Chinese, such as the messages printed on invalid keyword and option inputs. The policy allows locale constraints only when the skill offers user choice or clearly documents a justified region-specific limitation, which is not evident in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The schema title and property descriptions are entirely in Chinese, which imposes a specific language on users and integrators without any stated opt-in or justification. Under the policy, locale-specific language should either be optional or clearly documented as intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema title and description are written only in Chinese, which imposes a specific language on users or downstream tooling without any visible opt-in or alternative locale. This matches the policy concern for language or locale constraints expressed in natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON schema uses Chinese-only natural-language metadata in the title and description fields throughout the file. Under the stated policy, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The title and property descriptions are written entirely in Chinese, which indicates a language-specific constraint in the skill's natural-language interface. Because this JSON schema does not offer any language choice or document that the skill is intentionally region- or locale-specific, it may violate the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JSON schema is a manifest/config-style file, so SQP-3 applies. The title and description force a specific language context in natural-language metadata, and the file does not provide any user opt-in, alternative locale, or justification that the schema is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This manifest-like JSON schema uses Chinese titles and descriptions throughout, which imposes a specific language on users and integrators without any visible opt-in or documented locale limitation. Under the language/locale policy rule, that is a natural-language policy concern because the file provides no indication that the skill is intentionally China-specific or offers alternative language support.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file presents all usage instructions and parameter descriptions only in Chinese. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative language choice or justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code sends the user-provided video URL and a token to a remote API when creating a comment task, but the file contains no confirmation prompt, warning message, or user-facing disclosure about that transmission. Because this is a code file and the operation involves sending potentially sensitive user data to an external service, it meets the missing-warning criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The string literal used for the operation label is fixed in Chinese, which may impose a specific language on users without opt-in. The policy for natural-language violations calls for flagging locale or language constraints when the skill does not offer a choice or clearly justify the restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The task-query request transmits the supplied URL and token to an external endpoint, yet there is no visible warning, prompt, or user-facing logging explaining that data is being sent off-box. Under the code-file criteria, network operations that transmit user or system data should include some form of disclosure unless already clearly communicated elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16