Back to skill

Security audit

GUAIKEI抖音达人筛选与KOL推荐

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Douyin public-data CLI skill that uses a documented API token and saves local result logs, with no evidence of hidden execution or destructive behavior.

Install only if you are comfortable sending Douyin keywords or links, plus the GUAIKEI API token, to www.guaikei.com. Results may include public creator/comment data and are saved locally for search/post/comment runs, so manage log retention and use the data only in compliant, authorized contexts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (36)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音达人发现、筛选、分析的业务技能,核心应涉及抖音内容检索、热度数据查询、账号作品抓取和评论分析。而提供的代码仅是 src/utils/args.js,一个与业务无关的基础工具模块:读取 flag 值、解析 CLI 参数、校验必填项、处理布尔参数、生成帮助文本。它不包含任何网络请求、抖音接口调用、数据抓取、内容分析、达人评估或候选名单输出逻辑。虽然这类参数解析器可以作为完整工具的配套实现细节,但单就该代码块本身,其实际行为与声明目的明显不一致,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个面向抖音达人发现与评估的业务技能,核心能力应涉及平台数据检索、抓取、分析与筛选。但提供的代码片段只是一个本地日志工具,使用 Node.js 的 fs/path 模块将内容写入 logs 目录中的文件。虽然日志记录可能是辅助实现细节,但当前片段没有展示任何与抖音数据获取或分析相关的行为,且包含了未声明的本地文件写入能力。因此,就该代码片段本身而言,实际行为与声明用途明显不一致。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 76)May include surrounding context.

md
## 1.0.2 - 2026-03-24

- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language description is entirely in Chinese and provides no indication that other languages are supported or that the Chinese-only scope is an intentional, justified regional restriction. Under the language/locale policy, forcing a specific language without user opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents features that retrieve Douyin creator interaction data, which can affect user privacy expectations, but it does not include any warning or disclosure about handling public social data. Under the markdown-specific SQP-2 criteria, descriptions of data-affecting behavior should warn users when privacy-relevant collection is involved.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entry explicitly states that the skill can fetch and analyze comment content from specified Douyin works. Because this is a markdown file describing behavior that may affect privacy and user data, the absence of any warning or disclosure about responsible use, consent, or platform-policy considerations is a missing user warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This entry describes one-click bulk fetching of all public works from a creator account for competitor monitoring and account analysis. In markdown, such potentially privacy- or compliance-impacting behavior should be accompanied by a warning, but this changelog entry contains only capability descriptions and no user-facing caution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly enables collection of Douyin comment content and interaction data at scale, but provides no privacy, lawful-basis, retention, or platform-terms guidance. In a creator-screening skill, this increases the risk of indiscriminate scraping, profiling, and downstream misuse of personal data because operators are encouraged to gather user-generated content without safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code writes retrieved comment data to a local JSON file without a user-facing warning or consent flow in the command implementation. Because the skill processes public social-media comments at scale, undisclosed persistence can create compliance, privacy, and operational risks if the host environment retains sensitive or regulated data longer than expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI persists the full fetched results to a local JSON file automatically after execution, without opt-in, redaction, or a user warning. In this skill's context, the output may include creator profile data, content metadata, and engagement data that can be sensitive in commercial screening workflows; silently writing it to disk increases the risk of unintended retention, local disclosure, or later exfiltration from shared machines or CI runners.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Multiple natural-language strings in this file, including error messages and retry logs, are fixed in Chinese, which imposes a specific language on users. The file does not provide localization, opt-in language selection, or documentation justifying a Chinese-only locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON schema contains human-facing title and description text exclusively in Chinese, which can impose a language requirement on users without any opt-in or explanation. The stated policy requires flagging language or locale constraints unless the skill offers a choice or clearly justifies the locale specificity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON schema contains user-facing natural-language title and description fields exclusively in Chinese, including field descriptions. Under the language/locale policy rule, forcing a specific language without user opt-in can be a policy violation when no alternative or explicit locale scope is documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON schema contains user-facing natural-language strings entirely in Chinese, including the title and field descriptions. For a general-purpose skill asset, this can violate language/locale policy when no opt-in, alternative locale, or explicit region-specific justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The title and field descriptions are entirely in Chinese, which constitutes a language-specific natural-language constraint in the skill-facing metadata. There is no indication that this schema is intentionally region-specific or that users can opt into another language, so it may conflict with organizational language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON schema uses Chinese-only natural-language metadata in the title and description fields, which can impose a specific language on downstream users or tooling without indicating that the locale is optional. The policy calls for flagging language or locale constraints when they are forced without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This manifest-style JSON file contains user-facing title and description text entirely in Chinese, and the schema does not indicate that the skill is region-specific or that users can choose another language. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON schema uses Chinese-only natural-language metadata for the title and description, and the field descriptions throughout the file follow the same pattern. Under the policy rule, forcing a specific language without user opt-in can be a locale-policy issue when no alternative or opt-in is documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
65% confidence
Finding

The file presents all user-facing instructions in Chinese and does not mention any language selection or that the skill is intended only for Chinese-speaking users. If organizational policy requires not forcing a language without opt-in, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This file includes natural-language comments and task labels such as "创建任务" and "查询任务" exclusively in Chinese, with no indication that the skill supports other languages or that Chinese-only operation is a justified locale constraint. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The natural-language content in the file is entirely Chinese, including the module description, parameter documentation, and error/log messaging. Under the policy rule, forcing a specific language without offering a user choice or documenting a justified locale constraint can constitute a language/locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This file’s natural-language content is entirely Chinese, including the module description and user-facing operation labels such as '创建任务' and '查询任务'. Under the stated policy, forcing a specific language without offering a language choice or documenting a justified locale constraint is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This file’s natural-language content, including the module description and function documentation, is entirely in Chinese. Under the policy, forcing a specific language without offering user choice or documenting a justified locale constraint can be a language/locale policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest focuses on creator discovery, content retrieval, and comment analysis, but does not mention handling credentials or reading secrets from the environment. Accessing process.env.GUAIKEI_API_TOKEN is a capability beyond the user-facing purpose, even though it may support backend API access.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16