T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:94- Finding
API Token Transmitted in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a real Douyin data tool, but it needs review because it sends its API token in URL parameters and automatically saves fetched user/comment data to plaintext local logs.
Install only if you are comfortable sending Douyin keywords, profile/video URLs, and your GUAIKEI_API_TOKEN to guaikei.com, and if you can manage the local logs safely. Treat saved logs as potentially sensitive, exclude the logs directory from sharing, backups, and commits, delete old logs when no longer needed, and rotate the API token if you suspect URL logs or terminal output were exposed.
src/utils/request.js:94API Token Transmitted in URL Query Strings
src/utils/log.js:5Automatic Plaintext Persistence of Query Results and Personal Data
The code chunk only implements the hot榜 retrieval path and does not show behavior for the other three prominently declared capabilities. Its primary behavior is narrower than the declared multi-capability tool description. While hot榜 querying is accurately represented, the supplied code does not match the broader declared description as a whole because it only supports the '实时热榜查询' portion. There is no evidence in this chunk of keyword search, blogger work listing, or comment analysis. No harmful undeclared capability is present; the mismatch is due to overstated scope relative to the provided code.
代码仅包含 args 解析与 help 文本生成功能:readValueAfterFlag、parseArgs、buildHelp。这些都是底层通用 CLI 支撑逻辑,不涉及网络请求、抖音接口访问、链接解析、评论抓取、热榜获取或任何数据分析处理。根据评估标准,支持性实现细节本身不应单独判定为问题;但这里提供的代码片段与声明的主要用途严重不符,因为片段的实际行为完全是一个通用参数解析器,而非抖音查询分析工具的可见业务实现。因此应判定为描述与行为不匹配。
声明描述的是一个面向抖音内容搜索、热榜查询、博主抓取和评论分析的数据技能,但提供的代码片段并未体现任何抖音平台访问、搜索、抓取、评论分析或网络请求能力。相反,它只是一个通用的本地日志写入辅助模块,负责将字符串内容保存到 logs 目录。虽然日志功能可能是某些技能的配套实现细节,但当前代码片段本身的实际行为与声明的核心用途完全不一致,因此应判定为描述与行为不匹配。
声明描述的是一个面向抖音平台的数据采集与分析技能,主功能应涉及网络请求、抖音资源解析、榜单/评论/作品数据处理等。但给出的代码片段只包含一个读取本地 package.json 文件并返回 name 字段的函数,属于元数据读取/辅助工具,与声明的核心用途明显不符。该代码既没有体现任何抖音相关处理逻辑,也没有实现所述四大能力,因此应判定为描述与实际行为存在明显不匹配。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。
The skill declares access to an environment variable (GUAIKEI_API_TOKEN) but does not define any explicit tool scope such as permissions or allowed-tools. In practice, this weakens least-privilege boundaries and makes it harder for a host agent to constrain what the skill may access, especially if additional code or future changes begin using broader process capabilities. The risk is amplified because the skill forwards user-provided data to a third-party API, so secret handling and execution scope should be tightly declared.
The trigger phrases are broad enough to match common requests like analytics, competitor analysis, public-opinion monitoring, or data analysis, which increases the chance of over-invocation. Over-broad routing can cause unnecessary collection and transfer of Douyin data to a third-party API when the user intent is ambiguous, creating privacy, compliance, and data-minimization risks even if only public data is targeted.
This JSON schema contains multiple user-facing natural-language strings only in Chinese, including the title and parameter descriptions. Because the file does not indicate that the skill is region-specific or provide any language/locale opt-in, it appears to enforce a specific language by default.
The README states that fetched results are automatically saved as JSON logs, including searches, creator post lists, and video comments, but it does not prominently warn that potentially sensitive public data will be persisted locally. In this skill’s context, the data may include large-scale collected account/content/comment datasets, so silent local retention increases privacy, compliance, and accidental disclosure risk on shared machines or synced folders.
The function sends the provided token and video URL to an external API endpoint via requestApi, which is a network operation involving potentially sensitive user or system data. While there are docstrings for parameters, there is no confirmation prompt, user-facing log/print, or explicit warning in this file that the data will be transmitted off-system.
This function performs a GET request to an external endpoint and includes the token and target video URL in the request parameters. The code lacks any confirmation, visible disclosure, or warning to the user that these values are being transmitted externally.
The tool writes fetched comment data to disk automatically without an explicit warning or consent at the point of write. In this skill context, the data is likely public, but local persistence can still create unintended data retention, leak analysis targets to other local users/processes, and expose stored outputs through backups or shared workspaces.
This JavaScript file contains multiple user-facing strings exclusively in Chinese, including status, error, and success messages. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.
The CLI writes the full fetched results payload to a local JSON file automatically, without an explicit opt-in, warning, or redaction step. In this skill's context, the data may include scraped creator content metadata or comment analysis results, so silent persistence can expose potentially sensitive or regulated data to other local users, backup systems, logs, or later unintended processing.
The code emits all user-facing validation and status messages in Chinese, such as the error text on L07 and L11. This imposes a specific language on users without any opt-in, fallback, or documented region-specific justification, which matches the locale policy violation criteria.
The success and failure messages on L36-L38 are also hard-coded in Chinese, so the skill consistently forces one language in operational output. Because the file provides no user language choice or explicit documented justification for a Chinese-only locale, this is a natural-language policy concern.
The 401/403 handler returns an error message that hard-codes a specific contact channel and phone/WeChat flow instead of a neutral authentication failure. This can socially steer users toward an off-platform contact path they did not request, which is risky in an agent ecosystem because error strings may be surfaced directly to end users and interpreted as trusted guidance.
The user-facing warning and status strings are entirely in Chinese, and the file provides no indication that language is configurable or that the skill is intentionally limited to a Chinese-speaking context. This creates a natural-language locale policy concern because the skill imposes a specific language on users without opt-in.
This JavaScript file contains user-facing error messages and formatted output entirely in Chinese, and the comments indicate the skill behavior is designed around that language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.
All invocation guidance, triggers, and usage descriptions are presented in Chinese, with only a few English keywords included as tags, and there is no statement that users may interact in another language. This can be a natural-language locale constraint without explicit opt-in or justification as a region-specific compliance requirement.
This manifest-style JSON file contains all user-facing title and description strings in Chinese, but provides no indication that the skill is region-specific or that users can opt into another language. Under the natural-language policy rule, forcing a specific language without opt-in or clear justification is a locale-policy concern.
This JSON schema contains natural-language title and description fields exclusively in Chinese. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy violation, and this file does not indicate that the schema is intentionally limited to a Chinese-speaking or region-specific context.
This JSON manifest/schema contains user-facing natural-language metadata entirely in Chinese, including the top-level title/description and property descriptions. Under the stated policy, forcing a specific language without opt-in or documented regional justification is a natural-language policy concern.
This JSON schema uses Chinese-only natural-language titles and descriptions throughout, such as the title and field descriptions, which can amount to a locale/language policy issue when no opt-in or justification is provided. The file does not indicate that the schema is intentionally region-specific or that consumers can select another language.
The title and descriptions are entirely in Chinese, with no indication that the skill is region-specific or that users can choose another language. Per the policy, a hardcoded locale in natural-language strings can be a language/locale policy violation when no opt-in or justification is provided.
Detected: suspicious.exposed_secret_literal