Back to skill

Security audit

抖音作品洞察

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Douyin data-collection purpose, but it automatically saves full query results to local log files even though the main skill instructions say it has no write operations.

Install only if you are comfortable sending Douyin keywords, links, and your Guaikei API token to the Guaikei service, and with successful search/post/comment results being saved locally under the skill's logs directory. Review or clear those logs after use, especially on shared machines or workspaces.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/log.js:5
Finding

Automatic Persistence of User Queries and Complete API Results

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.slice(0, 200); } if (!safeFilename) { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outputFilename, content); utils.printSuccess(` → 已保存到 ${outputFilename}`); } catch (error) { utils.printError(`日志写入失败: ${error.message}`); } } ``` Successful search operations persist the complete request and response. The raw search keyword is included in the JSON content, while the normalized keyword is also included in the filename: ```js const finalOutput = { status: "success", error_code: "OK", message: "搜索任务完成", timestamp: new Date().toLocaleString(), request: { command: "search", keyword_raw: keywordRaw, keyword: keyword, sort: sort, time: time, duration: duration, content: content, limit: limit, }, ...[truncated 4744 chars]
Remediation
View remediation
`, or `--retention-enabled`. 2. **Correct the Agent-facing documentation** - Update `SKILL.md` to state clearly that successful requests may be retained locally. - Describe the storage directory, retained fields, access implications, and cleanup procedure. - Remove the inaccurate statement that the Skill performs no write operations. 3. **Remove sensitive values from filenames** - Do not include raw or normalized search keywords, account identifiers, or video identifiers in filenames. - Use a random identifier or one-way hash, for example: ```js const filename = `${Date.now()}_${crypto.randomUUID()}.json`; ``` 4. **Apply restrictive permissions** - Create the log directory with mode `0o700`. - Create output files with mode `0o600`, subject to platform support: ```js await fs.promises.mkdir(logDirectory, { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, flag: "wx", }); ``` 5. **Minimize retained data** - Store only fields required for the user's stated purpose. - Exclude raw input, unnecessary metadata, and complete API responses unless explicitly requested. - Provide configurable redaction for account identifiers, URLs, and comment author information. 6. **Implement retention and cleanup controls** - Add a documented expiration period. - Automatically remove expired records. - Provide a command to list and securely delete retained output. - Ensure cleanup also covers failed or interrupted operations if temporary files are introduced. 7. **Provide explicit consent and destination reporting** - Before writing, communicate what will be stored and ...[truncated 113 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (46)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code chunk is narrowly focused on one capability: fetching a creator's published posts via Douyin homepage URL using two API endpoints (/api/douyin/post/url and /api/douyin/post/info). It does not implement keyword search, comment retrieval, hot rankings, or the various filtering/sorting features described. The declared description presents the skill as a multi-capability Douyin intelligence tool, but this code only supports the '博主主页作品抓取' portion. That is a material scope mismatch between declared functionality and actual implemented behavior in this chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个覆盖多种抖音采集场景的综合工具,且重点提到“输入抖音ID,通过API实时获取账号基础信息和作品内容列表”,并列出4项能力。但给出的代码片段只对应其中的“关键词搜索”子能力:创建搜索任务、查询搜索结果,并对结果进行简单字段处理。代码中没有任何根据抖音ID抓取账号信息或主页作品的逻辑,也没有评论接口、热榜接口或相关资源访问。因此,代码实际行为仅覆盖声明中的一小部分,且与声明的主叙述(KOL作品获取/账号信息抓取)存在明显偏差,应判定为描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

代码行为非常明确:这是 comment-cli.js,参数为作品 URL/aweme_id 和评论数上限,核心调用是 createCommentTask 与 getCommentTask,输出的是评论结果。它并不执行关键词搜索、博主作品列表抓取、账号基础信息获取、作品内容列表获取或热榜查询。虽然声明中包含“评论抓取”这一能力,代码与其中一部分相符,但整体声明把技能描述为包含4种能力的综合抖音采集工具,且特别强调“输入抖音ID获取账号基础信息和作品内容列表”,这与当前代码块的实际职责明显不符。因此应判定为描述与代码存在实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

该代码块的主功能非常明确:获取指定抖音博主主页的作品列表。参数只有 url/sec_uid 和 limit,没有任何搜索关键词、排序、时间窗、时长、图文类型、评论对象或热榜相关参数;调用的 API 也是 post.createPostTask / post.getPostTask,语义上对应作品抓取而非搜索、评论或热榜。因而,声明描述把该技能说成具备4项能力的综合抖音采集工具,但此代码仅覆盖其中“博主主页作品抓取”这一项。虽然描述中包含了该能力,整体声明仍对当前代码块的实际能力有明显夸大,属于描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音内容采集/搜索/评论/热榜分析的业务技能,核心应包含对抖音相关接口或第三方API的调用、数据抓取与结构化输出。而提供的代码片段仅为通用参数解析模块(parseArgs/readValueAfterFlag/buildHelp),负责处理命令行输入和帮助信息生成。这类代码最多算辅助基础设施,不构成声明中的主要能力实现。由于当前代码的实际用途与声明的核心目的明显不同,应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音数据采集与分析的技能,核心行为应涉及网络请求、抖音内容获取、评论/热榜查询及结构化数据输出。但提供的代码片段只处理本地日志文件写入,与抖音平台、怪奇API、内容抓取或JSON结果生成均无直接关系。虽然日志功能可能是辅助模块,但就该代码片段本身而言,其实际行为与声明目的明显不一致,而且包含了未声明的文件系统写入能力。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a Douyin KOL/content retrieval tool with multiple data-collection capabilities. However, this code chunk is only a utility that reads package.json from the local filesystem and returns the package name with caching. That behavior is unrelated to the declared end-user functionality. While this could be a supporting helper within a larger project, based on the supplied code chunk alone, the actual behavior does not match the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a feature-rich Douyin collection/search/comment/hot-list tool. The supplied code chunk does not implement any of those user-facing capabilities or interact with Douyin, a third-party API, account IDs, comments, rankings, or structured content output. It is only a supporting utility for retrying asynchronous operations with exponential backoff. Because the actual code’s purpose is materially different from the declared primary purpose, this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

根据所给代码片段,实际行为只是辅助性的终端输出工具,包括打印“抖音数据智能分析助手”横幅和INFO/SUCCESS/WARN/ERROR日志。这类日志/界面输出属于支持性实现细节,但当前片段中完全看不到声明核心能力所需的任何网络请求、API集成、抖音ID处理、搜索参数过滤、评论或作品列表抓取、热榜获取、结构化JSON生成等逻辑。因此,这段代码的实际功能与声明的主要用途存在显著不一致,应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个多功能抖音采集/分析工具,但给出的代码片段只是一个输入验证模块,主要用于校验抖音作品URL/ID和评论数量上限。它既没有访问怪奇API,也没有实现作品列表抓取、评论抓取、搜索、热榜等核心功能。因此,从“描述的主要能力”与“代码实际行为”来看存在明显不匹配。尽管该代码可能是整个技能中的辅助文件,但就当前提供的代码块本身而言,功能范围远小于声明内容。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 77)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger list includes broad phrases such as '舆情监控', '热点追踪', '爆款挖掘', and generic English terms that could cause the skill to activate for loosely related requests outside a strict Douyin context. Over-broad routing can send user prompts, keywords, or links to a third-party API unintentionally, increasing the risk of unnecessary data exposure and misuse of an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema uses Chinese-only natural-language title and description strings for the skill output schema, which imposes a specific language/locale without indicating user opt-in or any justified region-specific limitation. Under the policy, locale-specific language is only acceptable when the skill offers a choice or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The package description embeds many broad natural-language trigger phrases such as '查看抖音视频', '抖音内容采集', and related marketing/analysis terms that can match ordinary user requests. In an agentic environment, this can cause overbroad skill invocation, routing benign viewing/research requests into a high-volume scraping tool, increasing the chance of unnecessary data collection, privacy issues, and misuse of third-party content at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code performs a network request that sends the supplied url and token to /api/douyin/comment/url, which is a safety-relevant data transmission. In this file there is no confirmation prompt, user-facing log, or warning comment/docstring disclosing that user input and credentials will be sent to an external API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The getCommentTask function makes a GET request to /api/douyin/comment/info including the url, limit, and token, which constitutes network transmission of user/system data. No confirmation prompt, user-visible log, or explicit warning is present here to inform the user about that transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends a skill token and a user-supplied Douyin profile URL to remote API endpoints via requestApi, which is a data-transmission operation covered by the warning requirement for code files. Although the functions have developer-facing docstrings, there is no visible confirmation prompt, user-facing log/print, or other disclosure in this file that the data will be sent over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The getPostTask function performs a GET request that includes the token and Douyin profile URL as request inputs to a remote service. This is a network/data-sharing action, and the file contains no confirmation, print/log disclosure, or user-oriented warning about that transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool silently writes full comment results to disk after completing the request, with no user-facing confirmation or consent. In this skill context, the data being collected is third-party platform content at scale, so hidden persistence materially increases privacy, compliance, and unintended data exposure risk beyond the expected structured stdout response.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code reads GUAIKEI_API_TOKEN from the environment and then calls hot.getHotTask(tokenValue), which strongly indicates an authenticated remote API request. The file has error handling and status output, but it does not include a confirmation prompt, comment/docstring warning, or other user-facing disclosure that credentials will be used to contact an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The CLI sends the normalized Douyin URL/sec_uid and token to remote API functions via createPostTask and getPostTask. Although the skill's purpose implies remote fetching, this file does not provide a clear user-facing disclosure that user input and authentication data will be sent to an external service before those requests occur.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI writes the full fetched Douyin results to a local JSON file after printing them, but this persistence is not clearly disclosed by the described behavior of the skill. Silent local retention increases the risk of unintended storage of scraped profile/content data on shared systems, developer workstations, or agent hosts where other users or processes may later access it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The CLI writes the full structured output, including the searched keyword and returned content data, to a local file automatically. In a data-collection skill that may retrieve large volumes of third-party content and comments, this creates an unannounced persistence channel that can expose sensitive research targets, collected personal data, or regulated content to other local users, backups, or log collectors.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JavaScript file contains multiple user-facing error strings in Chinese, such as the messages printed during keyword validation and option validation. Because the skill forces a specific language in its natural-language output without any evident user opt-in or documented locale justification in this file, it matches the language/locale policy-violation category.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16