T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:94- Finding
API Token Transmitted in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill largely does what it claims, but it sends an API token to a third-party service in URL query strings and automatically saves collected Douyin data locally.
Install only if you are comfortable sending Douyin search terms, creator or video URLs, and your Guaikei API token to guaikei.com. Treat the token as sensitive, rotate it if exposed, and clean or protect the generated logs directory because it can contain public user identifiers, comments, IP-region labels, and your analysis targets.
src/utils/request.js:94API Token Transmitted in URL Query Strings
src/utils/log.js:5Automatic Plaintext Retention of Complete Query and Comment Datasets
该代码片段完全是一个与业务无关的通用参数解析模块:readValueAfterFlag 读取 flag 值,parseArgs 解析 CLI 参数并做重复/缺失校验,buildHelp 生成帮助文案。它不包含任何抖音相关的数据源访问、API 调用、页面抓取、链接解析、热榜查询、作品抓取或评论分析逻辑。根据评估标准,这不是可忽略的支持细节与主功能一致的问题,而是代码片段的实际行为与声明的核心用途明显不符,因此应判定为 mismatch。
声明描述的是面向抖音平台的数据抓取、搜索、热榜、作品列表和评论分析能力;但代码片段实际只是一个通用日志写入模块,并未体现任何抖音相关接口调用、数据查询、爬取、搜索、热榜获取、评论分析或账号资料查询逻辑。虽然日志功能可作为辅助实现细节存在,但当前提供的代码片段本身的行为与声明的核心能力完全不一致,且涉及未声明的本地文件系统写入能力。因此应判定为描述与行为不匹配。
代码仅使用 fs 和 path 读取本地 package.json,并导出 skillName() 函数返回包名。这与声明的抖音数据采集和分析用途明显不符。该代码既没有网络请求,也没有处理抖音链接、关键词、aweme_id、sec_uid、评论或热榜数据的逻辑。虽然这可能只是一个辅助文件,但就所提供代码片段本身而言,其实际行为与声明能力无关,属于明显不匹配。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。
Without declared permissions the skill's intent is opaque and cannot be validated.
The trigger list includes broad phrases such as short-video topic selection, competitor analysis, public-opinion monitoring, and generic analytics terms, which can cause the skill to activate on ambiguous requests that are not clearly limited to Douyin public-data retrieval. Over-broad routing increases the chance of unintended tool use, unnecessary third-party data disclosure, or the agent selecting this skill when a safer or more appropriate skill should have been used.
This manifest file describes the skill with broad terms like '抖音', '抖音达人', '抖音博主', and '竞品分析' and lists generic keywords such as 'search', 'hot', and 'keyword' without clarifying when the skill should or should not be invoked. In a manifest, such broad trigger language can overlap with common user requests and increases the risk of unintended activation.
The skill promotes comment scraping and analysis but does not clearly warn users that exporting comment content and interaction data may involve personal data, sensitive opinions, or other regulated information. Even when data is publicly accessible, bulk collection and local export materially change the privacy risk profile and can enable misuse, unauthorized sharing, or noncompliant processing.
The README explicitly states that search, post, and comment results are automatically exported as JSON logs in the local logs directory, but it does not prominently warn that these files may contain scraped public profile, content, and comment data that can accumulate and persist on disk. Persistent storage of collected social-media data increases privacy, retention, and accidental disclosure risk, especially on shared machines or when logs are later redistributed.
The function sends the provided token and video URL to an external API via requestApi, which is a safety-relevant data transmission operation for a code file. While comments describe parameters, there is no confirmation prompt, user-facing log, or explicit disclosure warning in the file about sending this data over the network.
This function performs a GET request that includes the token, URL, and limit in request parameters, which transmits potentially sensitive access data and user-supplied content. The file does not show any confirmation prompt, print/log disclosure, or warning text informing users that these values are sent externally.
This JavaScript file contains user-facing strings such as status messages and errors entirely in Chinese, and there is no indication that the skill is limited to a Chinese-speaking audience or that users can opt into another language. That can violate language/locale policy because it forces a specific language experience without user choice.
The script reads GUAIKEI_API_TOKEN from the environment and sends it, along with the normalized Douyin URL and limit, to post.createPostTask and post.getPostTask. There is no explicit notice in this file that user input and authentication material will be sent over the network, which may be important for privacy and operational transparency.
The CLI persists fetched Douyin post results to a local JSON file by default, even though the command’s primary purpose is to query and display public data. Silent local retention expands the data exposure surface: results may contain profile/work metadata and can later be accessed by other local users, backup agents, or unrelated tooling without the operator realizing the data was stored.
Retrieved post data is written to a local JSON file without user confirmation or a prominent warning, creating an unexpected side effect for a read-oriented CLI. Even if the source data is public, undisclosed persistence can violate operator expectations, leak analysis targets, and leave artifacts on shared systems or in automated job environments.
The CLI persists full search output to a local JSON file named with user-supplied query data, but the script does not clearly warn users that results will be stored on disk. In this skill’s context, searches may contain sensitive competitive-intelligence, monitoring, or investigation terms, so silent local retention can expose data to other local users, backups, or log collection systems.
Several user-visible strings in this file are written only in Chinese, such as error messages and retry notices, with no option for users to choose another language or indication that the skill is region-specific. This can violate language/locale policy when the skill forces a specific language without opt-in.
The authentication and network error paths return messages only in Chinese, including token guidance and timeout/network errors, without any localization mechanism or user opt-in. Because these strings are directly surfaced to users, they constitute a forced language choice.
This code performs outbound network requests via HTTPS and sends both URL parameters and JSON body data to a remote host, but there is no confirmation prompt, user-facing notice, or comment/docstring disclosing that user or system data may be transmitted. The retry logging only reports failures and does not warn about the data transmission itself.
All user-facing status and warning strings in this module are hard-coded in Chinese, including warnings and operational messages. This can violate language/locale policy when the skill is used in broader contexts because users are not given an opt-in or alternative language option, and no region-specific justification is documented in the file.
This file contains natural-language comments and runtime error/output strings exclusively in Chinese, including validation errors and formatted result messages. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.
This JSON schema contains user-facing natural-language fields such as title and description entirely in Chinese, but does not offer any language/locale choice or explain that the skill is intentionally region-specific. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy concern.
This JSON schema uses Chinese-only natural-language metadata in the title and field descriptions, which imposes a specific language/locale across the skill artifact. Under the policy, language constraints should either offer user choice or be clearly documented as a justified region-specific requirement, which is not evident here.
This JSON schema contains user-facing natural-language fields such as title and description exclusively in Chinese. Per the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy issue.
The natural-language fields in this schema are entirely in Chinese, including the title and property descriptions. Because the file does not indicate that the skill is region-specific or provide an opt-in or alternative locale, it presents a language/locale policy concern under the natural-language policy rule.
Detected: suspicious.exposed_secret_literal