T09 · Insecure Skill Coding Practices
- Location
src/api/search.js:59- Finding
API Token Exposed in URL Query Parameters
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Douyin data tool largely does what it says, but it sends the API token in request URLs and automatically saves retrieved data locally, so it needs review before installation.
Install only if you are comfortable sending Douyin keywords, URLs, account/video identifiers, and your Guaikei API token to guaikei.com. Treat the token as sensitive, rotate it if exposed, and avoid using this in shared workspaces unless you manage or delete the generated logs under the skill's logs directory.
src/api/search.js:59API Token Exposed in URL Query Parameters
src/douyin/comment-cli.js:134Automatic Plaintext Retention of Retrieved Personal Data
声明描述的是一个面向抖音研究分析的业务技能,核心应涉及网络请求、抖音数据抓取/查询、内容分析等。实际提供的代码片段完全不涉及抖音、搜索、热榜、博主、评论或任何数据访问逻辑,只是一个与业务无关的通用参数解析器(parseArgs/buildHelp/readValueAfterFlag)。这不是单纯的底层辅助细节,因为当前代码片段本身未体现声明中的任何核心能力,主目的与描述严重不一致,因此应判定为明显不匹配。
该代码片段的唯一明确行为是接收文件名和内容,清洗文件名后使用 Node.js fs/path 将内容写入本地日志文件,并输出成功或失败信息。这与声明的核心能力——抖音搜索、热榜、作品抓取、评论分析——没有直接功能对应。虽然日志工具可能是某个更大技能的辅助模块,但就该代码片段本身而言,其行为属于未声明的本地文件写入支持功能,且完全不体现所述抖音数据获取/分析逻辑,因此应判定为描述与代码行为不匹配。
声明描述的是一个面向抖音数据采集与分析的技能,但提供的代码片段只是一个本地辅助函数:通过 fs 读取 package.json 并返回包名。这属于内部元数据读取,不是对声明功能的直接或明显支撑实现。就该代码片段本身看,其实际行为与声明的核心用途严重不一致,因此应判定为描述与行为不匹配。
声明描述的是一个面向抖音数据研究的技能,核心能力应围绕抖音内容检索、热榜获取、博主作品抓取和评论分析展开。但提供的代码片段只处理 TOKEN 的格式校验和提示信息输出,主要用途是检查环境变量中的 API token 是否可用,并在无效时暂停技能及提示购买/获取 token。该行为与声明的业务功能没有直接对应关系,属于 materially different primary purpose。虽然 token 校验可能是某些技能的辅助实现细节,但当前代码片段完全没有体现任何声明中的抖音数据能力,反而突出的是未声明的授权/营销提示功能,因此应判定为描述与行为不匹配。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。
Without declared permissions the skill's intent is opaque and cannot be validated.
The trigger list contains broad activators such as short-video research, competitor analysis, trend tracking, and analytics terms that may match user requests beyond Douyin-specific intent. Overbroad routing can cause the agent to invoke a third-party data skill unexpectedly, leading to unnecessary data disclosure to guaikei.com, user confusion, or inappropriate handling of non-Douyin requests.
The title and descriptions are entirely in Chinese, which imposes a specific language on users of this schema. The file does not indicate that the skill is region-specific or provide any user opt-in or language alternative, which can violate language/locale policy requirements.
The README explicitly promotes automatic JSON log export and local storage of scraped Douyin data, including videos, account data, and comments, but does not prominently warn that potentially sensitive collected content will be persisted to disk. In a research and monitoring skill, silent retention increases the risk of unintended data exposure, oversharing, or mishandling of public-but-sensitive personal data at rest.
The README tells users to obtain and configure GUAIKEI_API_TOKEN, but the warning about credential handling and authenticated outbound requests is not presented prominently before setup instructions. This can lead users to supply secrets without fully understanding that the tool will use them to call a third-party service, increasing the chance of credential leakage or misuse in shared environments.
The CLI reads an environment token and sends user-supplied identifiers/URLs to remote API functions without explicit disclosure in this file, creating a data-sharing risk. Even if expected for functionality, undisclosed transmission to a third-party backend can expose user research targets, queries, or operational metadata beyond the local environment.
Fetched post data is automatically written to a local file without user-facing notice or consent in this CLI flow. In a research skill, stored output can accumulate creator/content metadata and potentially sensitive analysis context on disk, increasing privacy and data-retention risk if the host system is shared or logs are later exfiltrated.
The tool persists search results to disk without any user-facing warning or confirmation, which can unexpectedly retain potentially sensitive keywords, competitive research, comment data, or trend-monitoring outputs. In the context of a Douyin research skill used for brand analysis and monitoring, this increases confidentiality risk because operator intent may be ephemeral querying, not local archival.
This code emits user-facing error messages in Chinese, and later also prints a success message in Chinese. The file provides no indication that the skill is region-specific or that users can choose their preferred language, which creates a natural-language policy concern under the language/locale rule.
The success and failure messages shown to users are also fixed to Chinese, reinforcing a forced locale choice across the function. Without explicit opt-in or documentation that this is a region-specific tool, this conflicts with the policy requirement to avoid forcing a specific language.
Multiple user-visible error strings in this file are hard-coded in Chinese, such as request failures and timeout/auth messages. This enforces a specific language choice without offering the user a locale option or documenting that the skill is intentionally Chinese-only.
The user-facing strings in this file are entirely in Chinese and there is no indication that the skill offers a language/locale choice or that the locale restriction is intentional and documented. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The user-facing natural-language strings and module description are entirely in Chinese, including the banner shown to users. This indicates a fixed language choice with no visible option for user language selection or justification that the skill is region-specific, which can violate language/locale policy requirements.
This JavaScript file contains natural-language comments and visible error/output strings in Chinese, indicating the skill forces a specific language experience. The policy requires flagging language or locale constraints when they are imposed without user opt-in or clear justification.
The natural-language strings in the schema are entirely in Chinese, including the title and field descriptions, which implies a fixed language/locale for users. The file does not indicate that Chinese is optional or that the skill is intentionally limited to a Chinese-speaking or region-specific context.
The title and description are presented entirely in Chinese, which can constitute a language/locale policy issue when no user opt-in or justification is provided. Because this is natural-language content in a JSON schema and there is no indication that the skill is intentionally region-specific, the file appears to force a specific language.
This JSON schema includes user-facing natural-language fields (title and description) exclusively in Chinese. Because the file provides no opt-in, alternative locale, or justification that it is intentionally region-specific, it can conflict with a policy requiring language or locale choice.
This JSON schema uses Chinese-only natural-language title and description fields, including property descriptions, with no indication that the skill is intentionally limited to Chinese-speaking users or a China-specific compliance context. Under the policy rule for language/locale constraints, this is a natural-language policy concern because it imposes a specific language without opt-in or justification.
The schema title and description are written only in Chinese, which can impose a language choice on downstream users or operators without any stated opt-in or locale justification. Under the policy, language-specific natural-language content should either offer choice or clearly document why the locale restriction is required.
This JSON schema uses Chinese-only natural-language metadata in the top-level title and description, and the rest of the field descriptions follow the same pattern. For an all-file-types language/locale policy check, this indicates a fixed locale with no visible opt-in or documented regional constraint in the file.
Detected: suspicious.exposed_secret_literal