Back to skill

Security audit

抖音每日热门作品榜 GuaiKei 抖音关键词每日最多点赞视频

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real Douyin data tool, but it needs review because it sends its API token in URL parameters and automatically saves fetched user/comment data to plaintext local logs.

Install only if you are comfortable sending Douyin keywords, profile/video URLs, and your GUAIKEI_API_TOKEN to guaikei.com, and if you can manage the local logs safely. Treat saved logs as potentially sensitive, exclude the logs directory from sharing, backups, and commits, delete old logs when no longer needed, and rotate the API token if you suspect URL logs or terminal output were exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:94
Finding

API Token Transmitted in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/log.js:5
Finding

Automatic Plaintext Persistence of Query Results and Personal Data

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.slice(0, 200); } if (!safeFilename) { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outputFilename, content); utils.printSuccess(` → Saved to ${outputFilename}`); } catch (error) { utils.printError(`Log write failed: ${error.message}`); } } ``` `src/douyin/comment-cli.js:153-162`: ```js utils.printSuccess( `Comment retrieval completed; ${finalOutput.results.length} results returned`, ); url = url.replace(/[^a-zA-Z0-9_-]/g, ""); url = url.replace("httpswwwdouyincomvideo", ""); url = url.replace("httpswwwdouyincomnote", ""); await log.taskWrite( `${startTime}_${url}_comment.json`, JSON.stringify(finalOutput, null, 2), ); ``` The same unconditional persistence pattern is used for successful search and profile-post results. The ...[truncated 2986 chars]
Remediation
View remediation
` or `--save`. 2. Preserve stdout-only behavior by default. 3. When persistence is requested, create directories and files with restrictive permissions: ```js await fs.promises.mkdir(directory, { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, content, { mode: 0o600, flag: "wx", }); ``` 4. Avoid putting keywords, profile identifiers, or video identifiers in filenames. Use random identifiers or neutral timestamps. 5. Minimize stored data by default. Redact or omit stable user identifiers, profile URLs, nicknames, and IP-region labels unless explicitly required. 6. Add configurable retention controls and a cleanup command. Document how users can securely delete stored results. 7. Add `logs/` to `.gitignore` and exclude it from release archives, CI artifacts, cloud synchronization, and routine backups unless explicitly approved. 8. Warn users before saving datasets that may contain personal data. 9. For use cases requiring long-term retention, support encryption at rest and document key-management expectations. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code chunk only implements the hot榜 retrieval path and does not show behavior for the other three prominently declared capabilities. Its primary behavior is narrower than the declared multi-capability tool description. While hot榜 querying is accurately represented, the supplied code does not match the broader declared description as a whole because it only supports the '实时热榜查询' portion. There is no evidence in this chunk of keyword search, blogger work listing, or comment analysis. No harmful undeclared capability is present; the mismatch is due to overstated scope relative to the provided code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码仅包含 args 解析与 help 文本生成功能:readValueAfterFlag、parseArgs、buildHelp。这些都是底层通用 CLI 支撑逻辑,不涉及网络请求、抖音接口访问、链接解析、评论抓取、热榜获取或任何数据分析处理。根据评估标准,支持性实现细节本身不应单独判定为问题;但这里提供的代码片段与声明的主要用途严重不符,因为片段的实际行为完全是一个通用参数解析器,而非抖音查询分析工具的可见业务实现。因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向抖音内容搜索、热榜查询、博主抓取和评论分析的数据技能,但提供的代码片段并未体现任何抖音平台访问、搜索、抓取、评论分析或网络请求能力。相反,它只是一个通用的本地日志写入辅助模块,负责将字符串内容保存到 logs 目录。虽然日志功能可能是某些技能的配套实现细节,但当前代码片段本身的实际行为与声明的核心用途完全不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音平台的数据采集与分析技能,主功能应涉及网络请求、抖音资源解析、榜单/评论/作品数据处理等。但给出的代码片段只包含一个读取本地 package.json 文件并返回 name 字段的函数,属于元数据读取/辅助工具,与声明的核心用途明显不符。该代码既没有体现任何抖音相关处理逻辑,也没有实现所述四大能力,因此应判定为描述与实际行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 72)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill declares access to an environment variable (GUAIKEI_API_TOKEN) but does not define any explicit tool scope such as permissions or allowed-tools. In practice, this weakens least-privilege boundaries and makes it harder for a host agent to constrain what the skill may access, especially if additional code or future changes begin using broader process capabilities. The risk is amplified because the skill forwards user-provided data to a third-party API, so secret handling and execution scope should be tightly declared.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The trigger phrases are broad enough to match common requests like analytics, competitor analysis, public-opinion monitoring, or data analysis, which increases the chance of over-invocation. Over-broad routing can cause unnecessary collection and transfer of Douyin data to a third-party API when the user intent is ambiguous, creating privacy, compliance, and data-minimization risks even if only public data is targeted.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON schema contains multiple user-facing natural-language strings only in Chinese, including the title and parameter descriptions. Because the file does not indicate that the skill is region-specific or provide any language/locale opt-in, it appears to enforce a specific language by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states that fetched results are automatically saved as JSON logs, including searches, creator post lists, and video comments, but it does not prominently warn that potentially sensitive public data will be persisted locally. In this skill’s context, the data may include large-scale collected account/content/comment datasets, so silent local retention increases privacy, compliance, and accidental disclosure risk on shared machines or synced folders.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The function sends the provided token and video URL to an external API endpoint via requestApi, which is a network operation involving potentially sensitive user or system data. While there are docstrings for parameters, there is no confirmation prompt, user-facing log/print, or explicit warning in this file that the data will be transmitted off-system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This function performs a GET request to an external endpoint and includes the token and target video URL in the request parameters. The code lacks any confirmation, visible disclosure, or warning to the user that these values are being transmitted externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The tool writes fetched comment data to disk automatically without an explicit warning or consent at the point of write. In this skill context, the data is likely public, but local persistence can still create unintended data retention, leak analysis targets to other local users/processes, and expose stored outputs through backups or shared workspaces.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This JavaScript file contains multiple user-facing strings exclusively in Chinese, including status, error, and success messages. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI writes the full fetched results payload to a local JSON file automatically, without an explicit opt-in, warning, or redaction step. In this skill's context, the data may include scraped creator content metadata or comment analysis results, so silent persistence can expose potentially sensitive or regulated data to other local users, backup systems, logs, or later unintended processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code emits all user-facing validation and status messages in Chinese, such as the error text on L07 and L11. This imposes a specific language on users without any opt-in, fallback, or documented region-specific justification, which matches the locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The success and failure messages on L36-L38 are also hard-coded in Chinese, so the skill consistently forces one language in operational output. Because the file provides no user language choice or explicit documented justification for a Chinese-only locale, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The 401/403 handler returns an error message that hard-codes a specific contact channel and phone/WeChat flow instead of a neutral authentication failure. This can socially steer users toward an off-platform contact path they did not request, which is risky in an agent ecosystem because error strings may be surfaced directly to end users and interpreted as trusted guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The user-facing warning and status strings are entirely in Chinese, and the file provides no indication that language is configurable or that the skill is intentionally limited to a Chinese-speaking context. This creates a natural-language locale policy concern because the skill imposes a specific language on users without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This JavaScript file contains user-facing error messages and formatted output entirely in Chinese, and the comments indicate the skill behavior is designed around that language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

All invocation guidance, triggers, and usage descriptions are presented in Chinese, with only a few English keywords included as tags, and there is no statement that users may interact in another language. This can be a natural-language locale constraint without explicit opt-in or justification as a region-specific compliance requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This manifest-style JSON file contains all user-facing title and description strings in Chinese, but provides no indication that the skill is region-specific or that users can opt into another language. Under the natural-language policy rule, forcing a specific language without opt-in or clear justification is a locale-policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON schema contains natural-language title and description fields exclusively in Chinese. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy violation, and this file does not indicate that the schema is intentionally limited to a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON manifest/schema contains user-facing natural-language metadata entirely in Chinese, including the top-level title/description and property descriptions. Under the stated policy, forcing a specific language without opt-in or documented regional justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions throughout, such as the title and field descriptions, which can amount to a locale/language policy issue when no opt-in or justification is provided. The file does not indicate that the schema is intentionally region-specific or that consumers can select another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The title and descriptions are entirely in Chinese, with no indication that the skill is region-specific or that users can choose another language. Per the policy, a hardcoded locale in natural-language strings can be a language/locale policy violation when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:24