Back to skill

Security audit

抖音热点总榜、抖音各垂类热搜榜

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform the Douyin data lookup it advertises, but it needs review because it sends user targets and an API token to a third-party service and automatically saves collected results locally.

Install only if you are comfortable sending Douyin keywords, creator URLs or sec_uid values, video URLs or aweme_id values, requested limits, and your GUAIKEI API token to guaikei.com. Treat the token as a secret, avoid using this in shared or synced workspaces unless you manage the logs directory, and delete or protect saved result files after use, especially for comment datasets or competitive research.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:94
Finding

API Token Exposed in URL Query Strings

Content
View full analysis

Vulnerability Details

File Location: src/utils/request.js:94-98, 119-123; token-bearing parameters originate in src/api/search.js:59-77, 104-118, src/api/comment.js:38-52, 67-78, src/api/post.js:23-35, 50-60, and src/api/hot.js:19-22
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: Medium

Vulnerable Code

Token-bearing request construction in src/api/search.js:

js
const params = {
  _: Date.now(),
  token: token,
};

const data = {
  keyword,
  sort_type: sort,
  publish_time: time,
  filter_duration: duration,
  content_type: content,
  limit: limit,
};

return await requestApi(
  "POST",
  "/api/douyin/general-search/keyword",
  params,
  data,
  constants.CREATE_MAX_ATTEMPTS,
  "创建任务",
);

Query-string construction in src/utils/request.js:

js
params.skill_name = skillName();

const fullPath = `${path}?${querystring.stringify(params)}`;
const jsonData = JSON.stringify(data);

const options = {
  host: constants.BASE_URL,
  path: fullPath,
  method: "POST",
  headers: {
    "Content-Type": "application/json",
    "Accept-Encoding": "identity",
    "Content-Length": Buffer.byteLength(jsonData),
  },
};

return await request(options, jsonData);

The GET helper uses the same pattern:

js
params._ = Date.now();

const fullPath = `${path}?${querystring.stringify(params)}`;
const options = {
  host: constants.BASE_URL,
  path: fullPath,
  method: "GET",
  headers: { "Accept-Encoding": "identity" },
};

return await request(options);

Technical Analysis

Every API operation adds GUAIKEI_API_TOKEN to the request parameter object. Both the POST and GET transport helpers serialize that object into the URL query string.

HTTPS protects the full request target while it is transmitted over the network, but it does not prevent the URL from being recorded after TLS t ...[truncated 1700 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove token from every query parameter object in the API modules.

  2. Pass the credential separately to the transport layer and place it in a dedicated header, preferably:

    js
    headers: {
      Authorization: `Bearer ${token}`,
      "Content-Type": "application/json",
      "Accept-Encoding": "identity",
    }
    
  3. If the server does not support bearer authentication, use a dedicated secret header such as X-API-Token and update the server accordingly.

  4. Ensure HTTP access logs, traces, exception reports, and proxy diagnostics redact authorization headers and any legacy token query parameter.

  5. Reject redirects to untrusted destinations if redirect support is added later, so authorization headers cannot be forwarded across origins.

  6. Rotate tokens that may already have been transmitted through query strings.

  7. Revise the documentation to distinguish local logging behavior from server-side or intermediary logging.

  8. Add automated tests asserting that generated request paths never contain token= or the configured credential.

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:25
Finding

Automatic Plaintext Retention of Collected Douyin Data

Content
View full analysis

Vulnerability Details

File Location: src/utils/log.js:25-35; invoked by src/douyin/comment-cli.js:151-162, src/douyin/post-cli.js:152-162, and src/douyin/search-cli.js:253-260
Vulnerability Type: Insecure plaintext storage and unnecessary retention of collected data
Risk Level: Low

Vulnerable Code

Automatic comment-result persistence in src/douyin/comment-cli.js:

js
console.log(JSON.stringify(finalOutput, null, 2));
utils.printSuccess(
  `获取评论任务完成, 共返回 ${finalOutput.results.length} 条结果`,
);

url = url.replace(/[^a-zA-Z0-9_-]/g, "");
url = url.replace("httpswwwdouyincomvideo", "");
url = url.replace("httpswwwdouyincomnote", "");
await log.taskWrite(
  `${startTime}_${url}_comment.json`,
  JSON.stringify(finalOutput, null, 2),
);

Plaintext file creation in src/utils/log.js:

js
const outputFilename = path.join(
  path.dirname(__filename),
  "..",
  "..",
  "logs",
  safeFilename,
);

try {
  await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true });
  await fs.promises.writeFile(outputFilename, content);
  utils.printSuccess(`  → 已保存到 ${outputFilename}`);
} catch (error) {
  utils.printError(`日志写入失败: ${error.message}`);
}

Equivalent persistence calls write complete search and creator-post results:

js
await log.taskWrite(
  `${startTime}_${url}_post.json`,
  JSON.stringify(finalOutput, null, 2),
);
js
await log.taskWrite(
  filename,
  JSON.stringify(finalOutput, null, 2),
);

Technical Analysis

Successful search, creator-post, and comment operations automatically serialize their complete result objects to JSON files under the project-level logs/ directory. These results may include public nicknames, comments, creator identifiers, content details, links, and the operator's queried targets.

Persistence is not opt-in, no retention period or deletion mechanism is implemented, an ...[truncated 1704 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make file persistence opt-in through an explicit option such as --output path or --save.

  2. Do not create a result archive when the user only requests standard output.

  3. Create files with owner-only permissions where supported:

    js
    await fs.promises.writeFile(outputFilename, content, {
      encoding: "utf8",
      mode: 0o600,
      flag: "wx",
    });
    
  4. Create the logs/ directory with restrictive permissions such as 0700.

  5. Add logs/ to .gitignore to reduce accidental publication.

  6. Provide configurable retention and a documented cleanup command.

  7. Offer field-level redaction for nicknames, user identifiers, profile links, and comment text when full data is unnecessary.

  8. Warn users before saving large datasets and clearly identify the destination path.

  9. Review backup, synchronization, and CI artifact policies to exclude locally retained results by default.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是面向抖音平台的数据抓取与分析技能,核心能力应涉及网络请求、抖音资源标识处理、内容列表/评论/热榜数据获取等。但提供的代码片段仅实现了通用参数解析和帮助文案生成,不包含任何抖音相关逻辑、数据访问、接口调用、爬取、分析或平台特定处理。虽然这类代码可能是更大项目中的辅助模块,但就该代码片段本身而言,其行为与声明的主要用途明显不一致,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音内容搜索、热榜查询、博主作品抓取和评论分析的数据技能;但提供的代码片段只是一个通用日志模块。它使用 fs 和 path 在本地 logs 目录下创建文件并写入内容,还进行了文件名清洗与错误输出。这属于辅助型日志实现,而当前片段中完全看不到任何抖音相关接口调用、网络请求、解析、搜索、评论抓取或热榜处理逻辑。由于评估对象是该代码片段本身,其实际行为与声明的核心能力明显不一致,应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音内容检索与分析的技能,核心应涉及网络请求、抖音数据处理或相关查询逻辑。但提供的代码片段只是在本地通过 fs 读取 package.json,并导出一个返回包名的函数。这与声明的主要用途明显不一致,且没有体现任何抖音相关功能。虽然这可能是辅助工具文件而非完整技能实现,但基于所给代码片段本身,其行为与声明能力严重不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向抖音的数据检索与分析技能,但给定代码片段的实际功能只是 TOKEN 管理辅助模块,不涉及抖音、网络请求、搜索、榜单、作品列表或评论数据处理。虽然 token 校验可能是整项技能的支持性实现细节,但就该代码片段本身而言,其行为与声明的核心能力完全不对应;此外还包含明显的私有 TOKEN 获取/营销提示,这也未在描述中说明。因此该描述不能准确代表此代码片段的实际行为,属于明显不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 72)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language trigger examples include phrases like "帮我做抖音竞品分析" and the manifest also lists broad trigger concepts such as "短视频选题" and "抖音数据分析". These are high-level intents rather than narrowly scoped invocation phrases, which can cause the skill to match everyday analytical requests without enough specificity about required Douyin context or inputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON schema contains user-facing natural-language titles and descriptions entirely in Chinese, such as the title and field descriptions. Because the file does not provide an alternate locale, opt-in mechanism, or documented region-specific justification, it may violate a language/locale policy requiring user choice or explicit locale scoping.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README states that task results are automatically saved under a local logs directory, but it does not clearly warn users that scraped public content, URLs, comments, and derived analysis may persist on disk after execution. This creates a privacy and data-retention risk, especially on shared machines or in team environments where those files may be copied, indexed, or exposed unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README instructs users to obtain and configure a token for a third-party service, but it does not clearly disclose that user queries, target Douyin URLs, sec_uid values, and related metadata are sent to an external token-gated backend. That omission can mislead users about where potentially sensitive research targets or monitoring subjects are being transmitted, creating privacy, compliance, and trust risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all natural-language content in Chinese, including the title, changelog entries, and usage-related notes, with no indication that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This file contains natural-language comments and interface documentation exclusively in Chinese, including the module description and function parameter docs. Under the policy rule, forcing a specific language without offering a language or locale choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI persists full comment query results to a local JSON file automatically after successful execution, but there is no explicit user warning, consent flow, or opt-in for disk persistence at the write site. Because this skill is specifically designed to collect Douyin comment content and interaction data, the saved file can contain large amounts of user-generated content and metadata that may be sensitive in operational, compliance, or privacy contexts, and can remain on disk longer than the user expects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file's comments and user-visible status/error strings are written exclusively in Chinese, including operational output like failure and success messages. There is no indication that the skill is region-specific or that users can opt into this locale, which may violate language or locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI writes the full fetched Douyin results to a local JSON file automatically, using data derived from a user-supplied target URL, without any explicit consent, opt-in flag, or warning. In this skill's context, the results can include scraped public profile/work data that may still be sensitive from a privacy, compliance, or shared-environment standpoint, and automatic persistence increases the risk of unintended retention, disclosure, or later misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code emits user-facing status and error messages exclusively in Chinese, such as the validation errors on these lines. This imposes a specific language on users without any opt-in or indication that the skill is intentionally limited to a Chinese-speaking context, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Multiple error messages in this file are hard-coded in Chinese, which can impose a specific language on users without opt-in or documented regional scope. The policy requires either offering language choice or clearly justifying a locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file emits all user-facing warnings and status messages exclusively in Chinese, including operational guidance and error text. This imposes a specific language on users without offering a language choice or documenting a justified locale restriction, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This JSON manifest-like schema describes the skill as '抖音评论获取' and its CLI parameters, but it does not provide any explicit trigger phrases, invocation constraints, or exclusion conditions. For manifest/config-style files, missing specificity around when the skill should activate can contribute to ambiguous invocation behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The title and descriptions are entirely in Chinese, which may impose a language expectation without documenting a user opt-in or a region-specific justification. Under language/locale policy checks, forcing a specific language can be a policy concern when no choice or rationale is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema contains natural-language title and description fields exclusively in Chinese. Because SQP-3 applies to all file types and flags forced language/locale choices without opt-in or justification, this appears to impose a specific language on users or downstream tooling with no documented alternative or region-specific rationale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This JSON schema uses Chinese-only natural-language title and description strings, which can impose a specific language/locale on downstream users or tools without any opt-in or stated regional justification. Under the policy, locale-specific language is acceptable when clearly documented and justified, but that context is not present in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest-format file contains user-facing title and description text entirely in Chinese, including parameter descriptions, with no indication that the skill is region-specific or that another language is supported. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The schema title and description are entirely in Chinese, which imposes a specific language/locale in user-facing natural-language metadata. The file does not indicate that this is a region-specific schema or offer any language choice, so it may violate the language/locale policy for broadly reusable skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema is a manifest/config-style file, so natural-language policy review applies. The title and descriptions are entirely in Chinese, and the file does not indicate that the skill is region-specific or that users can opt into this locale, which can violate a language/locale policy requiring choice or justification.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:24