Back to skill

Security audit

抖音达人数据 达人作品 抖音KOL作品 抖音博主作品

Security checks for vulnerabilities and agentic risk

Overview

This Douyin data tool is coherent, but it automatically saves complete fetched social-media datasets to local plaintext files without an opt-out or retention controls.

Review before installing if you work in shared workspaces or handle sensitive research topics: this skill sends requests to guaikei.com and saves successful search, creator-post, and comment results locally as plaintext JSON. Treat those files as exported datasets, delete them when no longer needed, and avoid collecting or redistributing personal data without proper authorization.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/douyin/comment-cli.js:134
Finding

Automatic Plaintext Retention of User-Linked Douyin Data

Content
View full analysis
Remediation
View remediation
` or `--save`. - Do not write any result file unless the user requests it. 2. **Provide an explicit disable control** - If backward compatibility requires automatic export temporarily, support `--no-save` and document it prominently. - Prefer changing the next major version to disable retention by default. 3. **Apply data minimization** - Store only fields required for the requested analysis. - Omit or redact `user_uid`, `user_sec_uid`, `user_nickname`, `ip_label`, and complete request URLs unless the user explicitly requires them. - Consider pseudonymizing stable identifiers before export. 4. **Use restrictive filesystem permissions** - Create the log or export directory with mode `0700`. - Create result files with mode `0600`. - Avoid relying solely on the process umask. ```js await fs.promises.mkdir(outputDirectory, { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, flag: "wx", }); ``` 5. **Add retention controls** - Support automatic expiration or a configurable retention duration. - Provide a documented cleanup command. - Avoid accumulating historical results indefinitely. 6. **Separate diagnostics from data exports** - Keep diagnostic messages on stderr. - Treat complete API responses as data exports rather than logs. - Do not mix personal or user-linked records with operational logging. 7. **Improve disclosure and consent** - Clearly state in `SKILL.md` when data will be written, where it will be stored, which fields are included, and how users can prevent or delete it. - Obtain explicit confirmation before retaining comment datasets containing identifiers or regional labels. 8. **Add security tests** - Verify that no file is created during default command exec ...[truncated 235 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (44)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

从代码看,核心功能只有两项:createSearchTask 调用 /api/douyin/general-search/keyword 创建关键词搜索任务,getSearchTask 调用 /api/douyin/general-search/info 查询搜索结果;processSearchResults 仅对结果做字段补充与时间格式化。这与声明中的第(1)项“关键词搜索视频/图文,可按点赞数、发布时间、时长、内容类型筛选排序”是基本一致的。但声明同时声称支持第(2)热榜查询、第(3)博主作品抓取、第(4)视频评论分析,而这些能力在当前提供的代码块中完全没有体现,也没有对应接口或处理逻辑。因此,声明对该代码块的能力范围有明显夸大,描述与实际行为不完全匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音数据采集与分析的功能型技能,核心能力应涉及网络请求、抖音资源标识处理、内容列表获取、评论抓取或分析逻辑。但给出的代码片段仅包含通用参数解析函数(parseArgs、readValueAfterFlag、buildHelp),用于处理命令行选项、默认值、必填检查和帮助文本生成。这与声明的业务能力没有直接对应关系,且代码的主要目的明显不同。因此该描述与代码行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

这段代码是一个辅助性的本地日志写入模块,使用 fs 和 path 在本地目录中创建并写入日志文件,还对文件名进行了简单的安全处理。它没有出现任何与抖音相关的网络请求、数据抓取、搜索、热榜查询、作品列表获取或评论分析逻辑。因此,若将此代码块视为对技能行为的代表,其实际行为与声明的核心功能明显不符。虽然日志功能可能作为某些技能的内部支持实现存在,但当前提供的代码块本身只体现了本地文件写入能力,且访问了声明中未提及的文件系统资源,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises multiple Douyin-related data retrieval and analysis capabilities. However, the supplied code chunk does not interact with Douyin, external APIs, network resources, creator pages, videos, comments, or search/trending systems. It only accesses a local file (package.json) and returns the package name. This is a materially different behavior from the declared primary purpose, so the description does not accurately represent the actual code in the provided chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

该代码片段的实际用途是管理和校验 GUAIKEI_API_TOKEN:检查 token 格式是否合法,合法则返回,非法则输出暂停使用提示和购买私有 TOKEN 的营销信息。与声明的抖音达人/作品/热榜/评论分析功能相比,这段代码没有体现任何相关业务实现,因此从描述与实际行为看存在明显不匹配。虽然令牌管理可算作支撑性实现细节,但这里提供的代码片段完全不涉及声明中的核心功能,且包含额外的营销推广输出,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 72)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description is entirely in Chinese and presents the skill behavior and intended use in a single language, with no indication that users may interact in other languages or choose a locale. Because the policy category covers language/locale constraints in natural language, this can be read as a language-specific requirement without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The invocation examples and user guidance are written solely in Chinese and do not provide an opt-in or alternative locale, which may imply a fixed language expectation for using the skill. Under the language/locale policy, this is a potential violation unless the Chinese-only scope is explicitly justified or users are given a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON schema uses Chinese-only titles and descriptions throughout, such as the title and field descriptions, which can impose a specific language on users or downstream tooling without opt-in. The policy specifically calls for flagging language or locale constraints when the skill does not offer a choice or justify the locale limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README’s instructional content, examples, warnings, and operational guidance are all presented in Chinese, which effectively forces a specific language for users. The policy allows locale constraints only when the skill offers language choice or clearly documents a justified regional constraint, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file presents the skill documentation heading entirely in Chinese, which indicates a language-specific presentation without any visible opt-in or alternative language path. The stated policy flags language or locale constraints when they are imposed without user choice or clear justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document explicitly describes collecting Douyin creator works and comment data, including by profile URL, sec_uid, video URL, and aweme_id, but provides no warning about privacy expectations, lawful basis, platform terms, or responsible handling of scraped public data. In a skill designed for content research and creator analysis, this omission increases the likelihood of misuse for surveillance, bulk profiling, or non-compliant data collection even if the underlying functionality targets public content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file contains natural-language content such as the module description and function docstrings entirely in Chinese, which imposes a specific language on maintainers or users of the skill without any opt-in. The policy allows locale constraints only when explicitly offered as a choice or clearly justified, neither of which is present in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI writes fetched comment data to a local JSON file automatically, without explicit user notice or opt-in. Comment content and interaction metadata may contain personal or sensitive data, and silently persisting it increases the risk of unintended retention, later disclosure, or access by other local users/processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The calls to post.createPostTask and post.getPostTask send user-provided input and authenticated requests to an external service. This file does not visibly disclose in help text, prompt, or comments that the provided Douyin URL and related request data will be transmitted off-system.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI persists fetched creator-post results to a local JSON file after completing what is presented as a query/fetch operation. These results may contain creator data, URLs, and other collected content, and the persistence is not clearly disclosed or made optional here, creating unnecessary data retention and local exposure risk on shared or monitored systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes the full fetched results to disk without explicit warning in this file that execution will create a local artifact. Users may reasonably expect a read-only lookup tool to print results only to stdout, so silent persistence can expose collected data to other local users, backups, endpoint monitoring, or later compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The program retrieves an API token from an environment variable and sends user search parameters to an external service. That is functionally necessary for this skill, but without an explicit warning or consent mechanism in this file, users may not realize their queries are being transmitted off-host, which can leak sensitive research terms or operational interests. The skill's purpose is remote Douyin data retrieval, so this is less suspicious than covert exfiltration, but it remains a genuine privacy and data-disclosure concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes the full search output to a local JSON file, and the filename includes user-supplied keyword data. Even if the data is not highly sensitive by default, search terms and returned content can reveal research interests or operational context, and silent persistence increases exposure on shared systems or in later backups. In this content-research skill, automatic logging is expected behavior, but the lack of clear notice, retention controls, and filename sanitization still creates a real privacy and local data-handling risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The AuthError message is hard-coded in Chinese and directs the user to a specific WeChat contact, which imposes a language/locale expectation without offering a choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code constructs outbound HTTPS requests that include a TOKEN header and JSON request body, which may transmit user or system data to a remote service. In this file, there is no confirmation prompt, user-facing disclosure, or inline warning comment/docstring explaining that data and credentials are sent over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing warning, error, info, and success messages are entirely in Chinese, and the file does not provide any indication that users can select another language or that the skill is intentionally limited to a Chinese-speaking context. This creates a natural-language policy concern because the skill imposes a specific language on users without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file constructs all user-facing output strings in Chinese, including headings and labels, with no indication that the skill is China-specific or that users can opt into another language. That creates a natural-language locale policy issue because the skill effectively forces a language choice on all users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JavaScript file contains user-facing error and output messages entirely in Chinese, and the comments describe behavior in Chinese as well. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly justified, which is not shown in this file.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16