Back to skill

Security audit

抖音竞品洞察分析

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Douyin public-data command skill; the main user considerations are third-party API use, token handling, and local result logs.

Install only if you are comfortable sending Douyin keywords, links, and the GUAIKEI service token to www.guaikei.com. Keep the token private, avoid using the skill for private or logged-in data, and be aware that search/post/comment outputs are saved locally under the skill's logs directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a Douyin data-analysis tool, but the analyzed implementation reportedly accesses local filesystem/package metadata instead of Douyin-related data sources and lacks the advertised search, hot-list, post, and comment features. This mismatch increases supply-chain and trust risk because a user may run code under false assumptions about what data it touches and why.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a Douyin data-analysis tool, but the analyzed implementation reportedly accesses local filesystem/package metadata instead of Douyin-related data sources and lacks the advertised search, hot-list, post, and comment features. This mismatch increases supply-chain and trust risk because a user may run code under false assumptions about what data it touches and why.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a Douyin data-analysis tool, but the analyzed implementation reportedly accesses local filesystem/package metadata instead of Douyin-related data sources and lacks the advertised search, hot-list, post, and comment features. This mismatch increases supply-chain and trust risk because a user may run code under false assumptions about what data it touches and why.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 76)May include surrounding context.

md
## 1.0.2 - 2026-03-24

- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README presents all user-facing instructions, warnings, and operational guidance only in Chinese. Per the policy, forcing a specific language without offering user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains user-facing natural-language content exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. Under the language/locale policy, forcing a specific language without opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes the full JSON result payload to a local file via log.taskWrite without any consent prompt, masking, or retention control. In this skill's context, the output can contain competitor data, account identifiers, URLs, and comment/interaction data, so silently persisting it increases the risk of local data exposure through shared machines, backups, or other local users/processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI persistently writes the full search output to a local JSON file using a filename derived from user-supplied keyword content, but the user is not clearly warned that result data will be stored on disk. In this skill’s context, search terms, returned content metadata, and competitive-analysis activity may be sensitive business intelligence; silent persistence increases the risk of unintended disclosure to other local users, backups, or log collectors.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits multiple user-visible error messages only in Chinese, such as at L037, L042, L049, L052, and L059. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not shown here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file-level description is written solely in Chinese ('通用工具函数模块'), and the exported banner/log strings also present the skill identity in Chinese without any indication of language choice. Under the policy, forcing a specific language is a natural-language locale issue unless the constraint is documented and justified or the user is offered an opt-in choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The banner string '🎬 抖音数据智能分析助手' is emitted directly to stderr as user-facing output and provides no mechanism for users to choose another language or locale. This matches the language/locale policy concern because the skill forces a specific language in its visible interface without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema contains all human-readable title and description fields in Chinese, which can constitute a language/locale policy violation when no alternative language option or opt-in is provided. Because the file is a manifest/config-style artifact consumed by users or tooling, the embedded natural-language text effectively fixes the skill's interface language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The schema's title and all field descriptions are written only in Chinese, which imposes a specific language on users and integrators. There is no natural-language indication that this schema is intentionally limited to a Chinese-speaking or region-specific audience, nor any opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The schema title and description are written only in Chinese, which imposes a specific language in the skill's natural-language metadata. There is no indication that the skill is China-specific or that users can opt into this locale, so this may violate language/locale policy guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions such as the title and field descriptions, but does not state that the skill is intended only for Chinese-speaking users or a China-specific workflow. Under the stated policy, forcing a specific language without opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema contains natural-language titles and descriptions entirely in Chinese, such as the title on L04 and multiple property descriptions throughout the file. For an all-file-types language policy check, this can be a locale/language constraint because the file does not offer an alternative language or document that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This manifest-style JSON schema contains user-facing title and description fields only in Chinese, which can impose a specific language on users without opt-in. The file does not indicate that the skill is intentionally region-specific or provide an alternative language/locale option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON schema contains user-facing natural-language strings such as the title and descriptions entirely in Chinese. Because the file does not indicate that the skill is region-specific or offer any language/locale opt-in, it may violate a language/locale policy requiring user choice or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language description at L04 forces a specific language for users reading the skill metadata. Under the policy, language constraints should either be optional for users or clearly justified as region-specific; this file does not state such a justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file presents all usage instructions, parameter descriptions, and examples only in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This file’s natural-language strings and comments are entirely in Chinese, including the module description and parameter/return documentation. Under the stated policy, forcing a specific language without user opt-in can be a locale/language policy violation when no justification or alternative is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file’s natural-language comments and parameter descriptions are entirely in Chinese, which can amount to a language/locale constraint without any indication that users may choose another language or that the skill is intentionally region-specific. Under the stated policy, forced language usage without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JavaScript file contains natural-language documentation entirely in Chinese, including descriptions of the module, parameters, and operation labels. Under the policy, a skill should not force a specific language or locale unless it offers user opt-in or clearly documents a justified region-specific constraint, which is not present here.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest focuses on Douyin competitor insight features such as comment retrieval and analysis, but does not mention credential handling or dependency on an external service token. Reading process.env.GUAIKEI_API_TOKEN introduces secret access that is not user-visible from the stated purpose, even if it may be implementation-driven.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16