Back to skill

Security audit

抖音数据实时采集获取

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to do the Douyin data collection it advertises, but it handles an API token and saved result files in ways users should review before installing.

Install only if you are comfortable sending Douyin queries, links, and your Guaikei API token to the third-party Guaikei service. Treat generated logs as sensitive research records, keep the skill directory private, delete logs when no longer needed, and consider rotating the token if you suspect request URLs may be logged by infrastructure you do not control.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:94
Finding

API Token Transmitted in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:5
Finding

Automatic Plaintext Persistence of Search, Post, and Comment Results

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.slice(0, 200); } if (!safeFilename) { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outputFilename, content); utils.printSuccess(` → 已保存到 ${outputFilename}`); } catch (error) { utils.printError(`日志写入失败: ${error.message}`); } } ``` Successful comment queries persist the complete request metadata and returned comments: ```js const finalOutput = { status: "success", error_code: "OK", message: "获取评论任务完成", timestamp: new Date().toLocaleString(), request: { command: "comment", url: url, limit: limit, }, metadata: { skill_version: constants.VERSION, runtime_version: process.versions.node, execution_time: Date.now() - startTime, }, results: commentTask, }; console.log(JSON.stringify(finalOutput, null, 2)); url = url.replace(/[^a-zA-Z0-9_ ...[truncated 2725 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (49)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest advertises Douyin search, hot-list, creator-post, and comment-analysis features, but the static findings say the code only performs local filesystem reads. This discrepancy is security-relevant because it indicates deceptive packaging or severely inadequate review, making it impossible for a user to rely on the manifest to understand data access and behavior; such mismatch can mask unauthorized collection of local data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest advertises Douyin search, hot-list, creator-post, and comment-analysis features, but the static findings say the code only performs local filesystem reads. This discrepancy is security-relevant because it indicates deceptive packaging or severely inadequate review, making it impossible for a user to rely on the manifest to understand data access and behavior; such mismatch can mask unauthorized collection of local data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest advertises Douyin search, hot-list, creator-post, and comment-analysis features, but the static findings say the code only performs local filesystem reads. This discrepancy is security-relevant because it indicates deceptive packaging or severely inadequate review, making it impossible for a user to rely on the manifest to understand data access and behavior; such mismatch can mask unauthorized collection of local data.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 72)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The trigger phrases include broad terms such as marketing analysis, trend tracking, and competitive analysis that can match many unrelated user requests. Overbroad activation is dangerous in an agent ecosystem because it increases accidental invocation of a skill that handles external data and secrets, especially when the same skill also has purpose/behavior mismatches noted elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly says scraped Douyin data is automatically exported to JSON logs, including comments and author-related data, but it does not warn that this creates persistent local copies of potentially sensitive or regulated data. In shared workstations, CI runners, or synced folders, these files could be unintentionally exposed, retained longer than expected, or redistributed beyond the stated internal-use boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document provides detailed instructions for collecting Douyin content, creator posts, hot-search data, and especially scraping comment data at scale, but it does not include any warning about privacy, consent, data-handling obligations, or platform terms/rate-limit considerations. In a data-collection skill, that omission can normalize misuse and increase the chance that users collect personal or behavioral data in ways that violate policy, expectations, or platform restrictions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The code creates a remote API request that transmits a skill token and a user-provided Douyin video URL to an external endpoint. Although the operation is documented in developer-facing comments, there is no confirmation prompt, user-facing disclosure, or warning text in this file about transmitting potentially sensitive identifiers off-box.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

This function performs a GET request to an external API and includes the token and video URL in request parameters. The file contains no user-facing notice that these values are sent to a third-party service, which can affect privacy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JavaScript file contains natural-language documentation in Chinese, such as the module description and parameter docs, but does not indicate that the skill is intentionally limited to Chinese-speaking users or provide any opt-in for language preference. Under the policy, forcing a specific language without user choice is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest presents the skill as a Douyin data query/analysis assistant for searching videos, hot topics, creator works, and comments, but it does not disclose any credential handling capability. This CLI reads GUAIKEI_API_TOKEN from the environment to operate, which is a privileged capability beyond the manifest’s stated purpose and use guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The CLI sends the normalized URL, limit, and token-backed request to external API functions to create and retrieve a comment task. There is no explicit warning in this file that the provided Douyin URL and associated request data will be sent over the network, which is a relevant disclosure for privacy and safety-sensitive operations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes the full fetched comment results to a predictable local JSON file without any visible user consent, retention limit, or redaction. Comment data can contain personal data, handles, content, or behavioral metadata, so silent persistence increases privacy and data-handling risk, especially on shared systems or automated runners.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code stores fetched comment data locally without warning the user in this file, creating a transparency and privacy issue. Even if the data is publicly sourced, unexpected retention can expose collected datasets to other local users, backups, or downstream tools without the operator realizing it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script reads GUAIKEI_API_TOKEN from the environment and then invokes remote task-creation and task-fetch operations with the normalized URL and limit. There is no visible disclosure in this file that the provided Douyin URL/sec_uid and token-backed request will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI writes the full fetched results to a local JSON file automatically after a successful run, without any opt-in, warning, or control in this file. Because the tool collects third-party platform data and may be used in shared workstations, CI runners, or multi-user environments, this can create unintended local persistence of scraped content and metadata, increasing the risk of disclosure or retention beyond the user's expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The command descriptions, help text, errors, and status messages are written in Chinese throughout the file, forcing a specific language for all users. This is a natural-language policy issue unless the skill explicitly offers language selection or documents a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Multiple user-visible error strings are hard-coded in Chinese, including API failure, parsing, timeout, and authentication messages. Because the file does not offer any language selection or explain that the skill is intentionally region- or locale-specific, this creates a natural-language policy issue for forced language behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The user-facing strings in this file are entirely in Chinese, including warnings and status messages, with no indication that the skill offers a language choice or that it is intentionally limited to a Chinese-speaking region. This creates a natural-language locale policy concern because the skill imposes a specific language on users by default.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This JSON manifest/schema uses broad natural-language descriptions of the skill inputs but provides no explicit activation constraints, negative examples, or narrow invocation context. For manifest-type files, the absence of specific trigger scope can make it unclear when this skill should activate versus when similar user requests should not invoke it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

All user-facing schema title and description fields are written in Chinese, and there is no indication that the skill offers a language choice or that the locale restriction is intentional and documented. This can violate language/locale policy when a skill implicitly assumes a single language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON schema contains user-facing title and description fields exclusively in Chinese, including field descriptions. Because the file does not indicate that the skill is region-specific or provide any language opt-in, it appears to enforce a specific language/locale in natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON schema contains user-facing natural-language metadata entirely in Chinese, including the title and field descriptions, but does not state that the schema is intended only for a Chinese-language or region-specific context. Under the policy rule, forcing a specific language without opt-in or documented justification can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest-style JSON file contains all user-facing title and description text in Chinese only, with no indication that the skill is region-specific or that another language is available. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:24