Back to skill

Security audit

抖音数据洞察

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Douyin public-data command tool that uses a third-party API and local JSON logs, with no hidden destructive or account-modifying behavior found.

Install only if you are comfortable sending Douyin keywords, links, IDs, request parameters, and your GUAIKEI_API_TOKEN to www.guaikei.com, and remember that search/post/comment results are saved locally under the skill's logs directory by default. Avoid passing untrusted strings containing terminal control characters until logging sanitization is improved.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/utils.js:23
Finding

Terminal Escape-Sequence Injection Through Unsanitized CLI Input

Content
View full analysis
"'&]/.test(keyword)) { utils.printError( `搜索关键词包含特殊字符 < > " ' &, 请输入普通关键词, 例如: 新媒体`, ); return false; } ``` ### Technical Analysis ANSI-compatible terminals interpret control sequences beginning with the ESC byte (`0x1B`) instead of displaying those bytes as ordinary text. The shared `printLog` function converts untrusted values to strings but does not remove, encode, or visibly escape control characters before writing them to stderr. The affected CLI commands log raw user input before URL or keyword validation can make it safe for terminal presentation. The keyword validator rejects selected characters s ...[truncated 2238 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (41)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is marketed as a read-only public-data tool, yet the finding says code performs local filesystem writes, path construction, and directory creation. This violates the stated trust model and can lead to unintended data retention, workspace tampering, or abuse of generated filenames/paths, especially if any of those paths derive from user-controlled input.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is marketed as a read-only public-data tool, yet the finding says code performs local filesystem writes, path construction, and directory creation. This violates the stated trust model and can lead to unintended data retention, workspace tampering, or abuse of generated filenames/paths, especially if any of those paths derive from user-controlled input.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 77)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger list contains broad terms such as 舆情监控, 热点追踪, 爆款挖掘, and generic analysis phrases that may match many unrelated user requests. Overbroad invocation conditions are risky because they can cause the agent to route conversations to a third-party API skill unexpectedly, increasing the chance of unintended data disclosure and misuse outside the user's actual Douyin intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README forces a specific language/locale experience for all users by presenting all instructions, warnings, and operational guidance only in Chinese. Under the policy, language constraints should either be optional for users or clearly justified as region-specific; neither appears here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file documents commands for fetching creator profiles, interaction metrics, posts, and comment data, but it does not include any user-facing warning about privacy, data handling, or the impact of collecting third-party content. Under the markdown-specific SQP-2 criteria, behaviours that could affect privacy should be disclosed in the skill description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The calls to comment.createCommentTask and comment.getCommentTask are network-oriented operations by purpose and use an API token, indicating transmission of user-supplied data to an external service. Although this is central to the skill's function, this file does not clearly disclose in help text or comments that the URL and related request data are sent to a remote service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The tool writes fetched comment data to a local JSON file even though it is presented as a read-only JSON toolbox. Persisting externally sourced comments and metadata to disk creates an undisclosed data-retention surface: sensitive or regulated content may remain on the host, be readable by other local users/processes, or be unintentionally collected into backups and logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Comment results are silently written to a local file without explicit warning in this CLI. Because comment payloads can include usernames, text, timestamps, and interaction data, undisclosed persistence increases privacy, compliance, and data-leakage risk, especially on shared systems or managed agent environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code presents user-facing strings such as errors, status messages, and success output only in Chinese. That forces a specific language/locale on users without any documented opt-in or selection mechanism, matching the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The code sends user-supplied Douyin identifiers/URLs together with a service API token to an external backend without any clear user-facing notice in this component. While this may be functionally necessary, the lack of explicit disclosure and consent can create privacy and data-handling risks, especially in a tool presented as a public-data read-only toolbox.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI writes the full fetched results to a local JSON file after already returning them to stdout, creating persistent storage of user-requested data beyond the tool's stated read-only/return-JSON behavior. This increases data retention and local disclosure risk, especially if results contain account metadata, comments, or links and the host environment is shared or logs/artifacts are collected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code presents user-facing descriptions, help text, status messages, and error messages entirely in Chinese. Because the file does not offer a language/locale option or indicate that the skill is intentionally limited to a Chinese-only region-specific use case, it creates a natural-language locale policy concern under the rule for forced language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI persists full search results to a local JSON file without explicit user consent or warning, which can unexpectedly store potentially sensitive research terms, retrieved content metadata, and URLs on disk. In shared environments, CI runners, or multi-user systems, these files may be accessible to others or retained longer than intended, creating an avoidable data exposure risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a read-only toolbox for querying public Douyin data and returning structured JSON, but this utility creates directories and writes arbitrary content to files under a local logs directory. Persisting data to disk is behavior beyond the stated read-only data retrieval/output scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Several natural-language strings shown to users, including failure and authentication guidance, are hard-coded in Chinese. This forces a specific language/locale without any indication of user opt-in or locale selection, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits all user-facing error messages in Chinese, which effectively forces a specific language on users. The file does not offer localization, user opt-in, or any indication that the skill is intentionally limited to a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON schema uses Chinese-only natural-language strings for the title and field descriptions, which can impose a specific language/locale on users without opt-in. The file does not indicate that the skill is intentionally region-specific or provide any multilingual alternative.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The schema title and description are written only in Chinese, which can impose a specific language/locale on users or downstream tooling without any opt-in or documented regional justification. Under the policy, locale-specific language is acceptable only when explicitly justified or optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This JSON schema is a manifest-type file, so natural-language policy checks apply. The title and description force a specific language/locale in user-visible metadata, and the file does not indicate that Chinese is optional or that the schema is intentionally limited to a Chinese-only regional context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This manifest-like JSON file contains user-facing title and description text entirely in Chinese, which may impose a specific language/locale without any documented opt-in or alternative. Under the stated policy, fixed language requirements can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON schema uses Chinese-only natural-language title and description text for the skill output schema. Under the policy, forcing a specific language without user opt-in or a documented justification can be a locale-policy violation, and no such opt-in or justification appears in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The schema's human-facing title and parameter descriptions are written only in Chinese, which imposes a specific language on users without any documented opt-in or locale-specific justification. Under the policy rule, this is a natural-language locale constraint because the file does not indicate that the skill is intentionally limited to Chinese-speaking or region-specific use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON schema contains natural-language titles and descriptions exclusively in Chinese, such as the title and every property description. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation unless the restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16