Back to skill

Security audit

抖音爆款选题

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it automatically saves user queries and collected Douyin data to local plaintext log files without strong controls or consistent disclosure.

Review this before installing if your searches, monitored accounts, or comment datasets are sensitive. The skill sends inputs and its API token to www.guaikei.com and automatically keeps search/post/comment results in local JSON log files; use it only where that storage is acceptable, and delete or protect the logs after use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/log.js:29
Finding

Automatic Plaintext Persistence of User Queries and Collected Douyin Data

Content
View full analysis

Vulnerability Details

File Location: src/utils/log.js:29-35, invoked from src/douyin/search-cli.js:280-283, src/douyin/post-cli.js:209-212, and src/douyin/comment-cli.js:198-201
Vulnerability Type: Automatic plaintext storage of potentially sensitive data
Risk Level: Medium

Complete Code Snippets

The shared logging utility creates a project-local directory and writes supplied content with default filesystem permissions:

js
const outputFilename = path.join(
  path.dirname(__filename),
  "..",
  "..",
  "logs",
  safeFilename,
);

try {
  await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true });
  await fs.promises.writeFile(outputFilename, content);
  utils.printSuccess(`  → 已保存到 ${outputFilename}`);
} catch (error) {
  utils.printError(`日志写入失败: ${error.message}`);
}

Successful searches unconditionally persist the complete request and response. The keyword is also included in the filename:

js
await log.taskWrite(
  `${startTime}_${keyword}_${sort}_${time}_${duration}_${content}_search.json`,
  JSON.stringify(finalOutput, null, 2),
);

Successful post retrievals unconditionally persist the complete result:

js
await log.taskWrite(
  `${startTime}_${url}_post.json`,
  JSON.stringify(finalOutput, null, 2),
);

Successful comment retrievals unconditionally persist the complete result:

js
await log.taskWrite(
  `${startTime}_${url}_comment.json`,
  JSON.stringify(finalOutput, null, 2),
);

Technical Analysis

Every successful search, post, or comment operation serializes its complete output envelope and writes it in plaintext beneath the project’s logs/ directory. Persistence is automatic: users are not required to provide an output option or explicitly consent to local retention.

The saved content contains the request parameters and complete API results. Depending on the operation, this can include:

  • Search keywords and research interests
  • Monitored account, video, or post ident ...[truncated 2936 chars]
Remediation
View remediation

Remediation Suggestions

  1. Disable persistence by default

    • Do not call taskWrite() unless the user explicitly requests saved output.
    • Add an option such as --output <path> or --save.
    • Keep stdout as the default and only output channel.
  2. Obtain informed consent

    • Clearly disclose which request and result fields will be retained.
    • Require explicit confirmation before storing comments, identifiers, or location-related metadata.
    • Correct SKILL.md so it accurately states that local writes occur when persistence is enabled.
  3. Use restrictive file permissions

    • Create the directory with a restrictive mode where supported.
    • Write files with mode 0o600.
    • Verify that existing files are not overwritten with broader inherited permissions.
  4. Minimize retained data

    • Do not include raw keywords or user identifiers in filenames.
    • Use a random identifier or timestamp-only filename.
    • Exclude fields not required for the user’s stated purpose.
    • Consider redacting commenter identifiers and IP-region information.
  5. Implement lifecycle controls

    • Add configurable retention periods and secure deletion.
    • Provide a command to enumerate and delete saved results.
    • Document backup and source-control risks.
    • Add logs/ to .gitignore if local persistence remains supported.
  6. Prevent uncontrolled storage growth

    • Enforce a maximum output-file size.
    • Add rotation or quotas.
    • Warn before persisting unusually large result sets.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (40)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码片段仅包含 parseArgs、readValueAfterFlag 和 buildHelp,功能是解析命令行参数和生成帮助信息。这属于底层通用支持模块,而不是声明中的核心业务能力。根据给定代码,既没有网络请求、也没有访问抖音资源、也没有返回作者/互动数据/标签/链接等结构化结果。因此该代码片段的实际行为与声明的技能用途存在显著不一致,属于材料性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

该代码片段并未实现任何声明中的核心能力,如抖音关键词搜索、作品抓取、评论抓取或热榜查询。相反,它的实际作用是将给定内容写入本地 logs 目录中的文件,并包含文件名净化、目录创建和错误处理逻辑。虽然日志模块可能作为辅助基础设施存在,但就单独提供的代码片段而言,其行为与声明的对外技能描述明显不一致,且包含未声明的本地文件写入能力与文件系统访问。因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises substantial Douyin data collection and analysis capabilities, but the supplied code chunk does not implement any network access, scraping, search, ranking retrieval, comment handling, or JSON data assembly for Douyin content. Instead, it is a simple utility that reads a local package.json and returns its name field. This is not merely a supporting detail for the declared functionality in any meaningful way based on the supplied chunk; the observed behavior is unrelated to the declared primary purpose.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 77)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README presents all user-facing instructions, warnings, and usage guidance only in Chinese. Under the policy rule, forcing a specific language without offering the user a language or locale choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is entirely written in Chinese, including the primary heading and all release notes, with no indication that the skill is region-specific or that users may choose another language. Under the policy rule for natural-language violations, forcing a specific language without opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code performs a network request that transmits user data (url) and a credential-like value (token) through requestApi, but the file contains no confirmation prompt, user-facing log, or explicit warning about that transmission. Because comment retrieval involves sending potentially sensitive request data to a remote service, some disclosure would be expected unless documented elsewhere in markdown.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The getCommentTask function issues a GET request with the supplied url, limit, and token, which constitutes network transmission of user-provided data and access credentials. There is no visible prompt, warning, or user-oriented disclosure in this file explaining that external API access occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code sends a token plus a user-provided profile URL to remote API endpoints via requestApi, which is a network/data-transmission operation covered by the warning requirement for code files. Although the function has developer-facing docstrings, there is no visible confirmation prompt, user-facing log/print, or explicit disclosure in this file that these values will be transmitted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The getPostTask function performs a GET request that includes the token and user-derived parameters, which may expose user/system data to a remote service. The file contains no user-facing warning, confirmation, or print/log statement disclosing that this network request occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The script sends the user-provided Douyin URL and uses an API token to create and fetch a remote comment task. Although network access is central to the tool's purpose, this file does not clearly disclose in its help or comments that input data is sent to an external service, which is relevant for privacy and transparency.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI writes fetched Douyin comment data to a local JSON file as a side effect after printing results, but this storage behavior is not disclosed in the skill description or obvious from the command interface. Comments and associated metadata may contain personal or sensitive information, so undisclosed persistence increases privacy, compliance, and data-retention risk on the host system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool stores comment results to disk without warning the user in this CLI flow, creating a silent data persistence channel. Because comment data can include user-generated content and identifiers, unexpected local storage can expose data to other local users, backups, or later compromise of the machine.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing strings in comments, errors, and success output are consistently in Chinese, and the file provides no option to select another language or locale. This can violate language/locale policy when skills are expected to avoid forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI silently persists fetched Douyin results to a local JSON file after printing them, which can leave scraped content, account data, and potentially sensitive analysis artifacts on disk without the user's awareness. In shared environments, automation runners, or multi-tenant hosts, these files may be accessible to other users or retained longer than intended, increasing privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The calls to search.createSearchTask and search.getSearchTask necessarily transmit the keyword and related parameters over the network. While network access is central to a search skill, the current CLI output and help text do not clearly disclose that user-entered queries are sent to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI persists the full request and returned search results to a local JSON file, including user-supplied keywords and potentially sensitive collected content, without any visible consent, retention control, or redaction. In a data-collection skill focused on competitor monitoring, comments, and search analytics, this creates a real privacy and data-handling risk because users may not expect durable local storage of queried topics and scraped results.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code emits user-facing error messages in Chinese only, and later success/error messages are also Chinese-only. This imposes a specific language on users without opt-in or any documented region-specific justification, which matches the locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code returns multiple hard-coded Chinese messages such as "请求失败" and the authentication guidance string, which creates a fixed-language user experience. Under the policy, forcing a specific language without user opt-in or clear justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This manifest-style JSON schema uses only Chinese natural-language labels and descriptions for the skill inputs, which can impose a language-specific interaction pattern on users without opt-in. The file does not indicate that the skill is intentionally region-specific or provide any alternative locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The schema title and description are written only in Chinese, which imposes a specific language in natural-language metadata without any opt-in or explanation of a region-specific constraint. Under the policy rule, locale or language restrictions should either offer user choice or be clearly documented as intentionally limited to a specific audience or compliance context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The schema's natural-language metadata fields such as title and description are written entirely in Chinese, which can impose a language constraint on downstream users or tools consuming this skill asset. The file does not indicate that Chinese is optional, user-selected, or required for a documented region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON schema includes user-facing title and description fields entirely in Chinese, but provides no indication that the skill is region-specific or that users may opt into another language. Under the policy rule for natural-language violations, hard-coding a single language without documented justification or choice is a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON schema contains user-facing natural-language metadata entirely in Chinese, including the schema title and field descriptions. Because the file does not document that the skill is region-specific or provide any language/locale opt-in, it appears to impose a specific language by default, which matches the stated language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16