Back to skill

Security audit

抖音竞品研究

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its advertised Douyin public-data research purpose, but it handles an API token in a risky way and automatically saves retrieved datasets locally.

Install only if you are comfortable sending Douyin search terms, profile/video URLs, public comments, and your GUAIKEI_API_TOKEN to guaikei.com. Treat the token as sensitive, rotate it if exposed, and review or delete the generated logs directory after use, especially in shared, synced, or backed-up workspaces.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:86
Finding

API Credential Exposed in URL Query Strings

Content
View full analysis
{ const res = await getJson("/api/douyin/hot-search", { _: Date.now(), token: token, }); return res.data; }, ``` ### Technical Analysis `GUAIKEI_API_TOKEN` is an authentic ...[truncated 2108 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:25
Finding

Automatic Persistent Storage of Retrieved User Content Without Explicit Opt-In

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.slice(0, 200); } if (!safeFilename) { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ...[truncated 2901 chars]
Remediation
View remediation
` or `--save`. 2. Default to stdout-only operation, consistent with the documented CLI output contract. 3. Before saving comment or user datasets, clearly disclose what will be stored and obtain user confirmation where appropriate. 4. Create files with restrictive permissions: ```javascript await fs.promises.writeFile(outputFilename, content, { mode: 0o600 }); ``` 5. Add documented retention and deletion controls, including a command to remove generated files. 6. Add `logs/` to `.gitignore` to reduce accidental repository commits. 7. Minimize retained content by excluding unnecessary user identifiers and metadata. 8. Consider configurable redaction or pseudonymization for usernames and stable user identifiers. 9. Document the storage directory, retention behavior, file contents, and risks associated with shared workspaces and backups. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (37)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill that claims networked Douyin analysis but actually only reads local files such as package.json is materially misrepresented. Even if the local read is low-impact by itself, the deception erodes trust and can hide additional unexpected behaviors, which is a supply-chain and review risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill that claims networked Douyin analysis but actually only reads local files such as package.json is materially misrepresented. Even if the local read is low-impact by itself, the deception erodes trust and can hide additional unexpected behaviors, which is a supply-chain and review risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill that claims networked Douyin analysis but actually only reads local files such as package.json is materially misrepresented. Even if the local read is low-impact by itself, the deception erodes trust and can hide additional unexpected behaviors, which is a supply-chain and review risk.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 72)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill requires access to an environment variable (GUAIKEI_API_TOKEN) but does not declare an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege boundaries and makes it harder for a host system or reviewer to understand and constrain what sensitive resources the skill expects to access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The trigger list includes broad phrases such as analytics, search, trend tracking, and competitor analysis that can match many ordinary user requests. Overbroad activation increases the chance this skill is selected in inappropriate contexts, causing unnecessary data access, third-party API use, or routing away from a more suitable and safer tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file applies to SQP-2, and it advertises '自动生成JSON日志' as a feature without an explicit user-facing warning about local persistence of collected data. Because the skill handles potentially sensitive monitoring/comment data and stores it automatically, users should be clearly warned that outputs are saved on disk by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The setup instructions require users to place GUAIKEI_API_TOKEN in an environment variable, but the safety guidance is minimal and buried in the FAQ. In practice, users may expose the token through shell history, screenshots, shared terminals, CI logs, or committed .env files, enabling unauthorized API use or account abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The code sends the token parameter in API requests when creating a comment task, which is a transmission of credential-like data over the network. Although the function has developer-facing docstrings, there is no user-facing confirmation, warning, or disclosure in this file that the token will be sent to an external API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This function issues a GET request containing token, url, and limit, transmitting user-supplied and credential-like data to an API endpoint. The file contains only developer-oriented comments and no user-facing warning or disclosure that these values are sent over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code sends user-supplied content to external API functions via createCommentTask and getCommentTask. Although the script logs progress, it does not clearly disclose that the provided URL and request parameters will be transmitted to a remote service, which is a safety-relevant network operation for a code file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The CLI persists scraped Douyin results to a local JSON file automatically after successful execution, without any explicit user consent, warning, or opt-in control on this code path. Because the output may contain competitor research data, profile-derived content, or comment-analysis results, this creates unnecessary local data retention risk and can expose sensitive operational research to other local users, backup systems, or downstream tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes the full search output to a predictable local JSON file that includes the request keyword and returned results, but there is no explicit user-facing consent or warning before persistence. In this skill’s context, users may search competitor, brand, or monitoring terms that can be sensitive business intelligence; silent local retention increases the chance of unintended disclosure to other local users, processes, backups, or support tooling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits user-facing status and error messages only in Chinese, such as the validation errors on L07 and L11. The file provides no language selection, fallback, or documented locale constraint, which can violate a language/locale policy requiring user choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Several error messages presented through exceptions are hard-coded in Chinese, including authentication and network failures. This imposes a specific language on users without any visible locale choice or documented justification in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file emits all user-facing messages exclusively in Chinese, including warnings and status text. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the skill is clearly documented as region-specific, which is not shown here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JavaScript file contains comments and all user-visible validation/error/output strings exclusively in Chinese, including the formatted result message. Under the policy, forcing a specific language without user opt-in or a documented locale-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The manifest description and usage guidance are written entirely in Chinese and frame the skill around Chinese-language interaction, without offering any language choice or documenting that the locale restriction is intentional. Under the language/locale policy, forcing a specific language without user opt-in can be a policy concern unless clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON schema contains human-readable title and description fields entirely in Chinese, including parameter descriptions, with no indication that the skill is region-specific or that users may choose another language. That can violate language/locale policy when a skill implicitly forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The schema title and description are written only in Chinese, which imposes a specific language in natural-language metadata without offering an alternative or documenting a locale-specific scope. Under the policy, language constraints should be optional or clearly justified when they are region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON schema contains human-facing metadata entirely in Chinese, including the title and field descriptions. Because SQP-3 applies to all file types and flags language-policy issues when a skill forces a specific language without opt-in, this is a natural-language locale constraint with no visible alternative or justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON schema includes all human-facing title and description fields in Chinese only, such as the title and parameter descriptions. That creates a language/locale constraint in natural-language metadata without offering user opt-in or documenting that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON schema contains natural-language titles and descriptions entirely in Chinese, which imposes a specific language/locale on consumers of the skill metadata. The file does not indicate that the skill is intentionally region-specific or provide any user opt-in or alternative locale handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This manifest-type file contains user-facing title and description fields entirely in Chinese, including the parameter description text, but provides no indication that the skill is region-specific or that users may opt into another language. Under the policy, hard-coding a specific language without opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JSON schema uses Chinese-only natural-language metadata in the top-level title and description. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation, and this file does not document any optional language selection or region-specific justification.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:24