Back to skill

Security audit

抖音七日点赞视频榜 抖音自定义垂类视频点赞榜 抖音自定义关键词点赞榜 抖音一日点赞视频榜

Security checks for vulnerabilities and agentic risk

Overview

This Douyin data skill is mostly a disclosed API wrapper, but it needs Review because it automatically stores scraped results locally and overstates its specialized ranking capability.

Install only if you are comfortable sending Douyin queries, URLs/IDs, and a GUAIKEI_API_TOKEN to guaikei.com and with fetched public content being saved locally in plaintext logs. Avoid use on shared or synced workspaces unless logs are protected and cleaned up, and do not rely on the claimed seven-day like-surge TOP1000 feature unless the publisher clarifies how it is actually calculated.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/douyin/comment-cli.js:159
Finding

Automatic Plaintext Retention of Collected Douyin Data

Content
View full analysis
Remediation
View remediation
`. - Continue using stdout as the default output channel. 2. **Apply restrictive file permissions** - Create the log directory with mode `0700`. - Create result files with mode `0600`. - Where supported, use exclusive creation to avoid overwriting existing files. Example: ```js await fs.promises.mkdir(logDirectory, { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, flag: "wx", }); ``` 3. **Minimize stored data** - Store only fields explicitly requested by the user. - Avoid retaining complete API responses when a summary is sufficient. - Provide an option to redact usernames, stable user identifiers, profile URLs, and comment-author metadata. 4. **Avoid identifiers in filenames** - Replace keywords, account identifiers, and video identifiers with random identifiers or non-reversible hashes. - Keep sensitive request details inside the protected file only when necessary. 5. **Implement retention controls** - Support a configurable expiration period. - Delete expired records automatically. - Provide a documented command for removing all retained results. 6. **Document retention clearly at execution time** - If saving is requested, report the destination, retained fields, permissions, and retention period before or immediately after writing. - Explain that collected public data may still constitute personal data under applicable policies or regulations. 7. **Protect existing installations** - Recommend deleting unnecessary files already present under `logs/`. - Ensure `logs/` is excluded from source control, package publication, and build artifacts. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (46)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

该代码片段的实际功能局限于通用关键词搜索:向 /api/douyin/general-search/keyword 创建搜索任务,并从 /api/douyin/general-search/info 拉取结果,参数包含关键词、排序、发布时间、时长、内容类型、数量等,这与声明中的第(1)项“关键词搜索视频/图文”基本一致。但声明把工具核心定位为“抖音七日点赞飙升榜查询工具”“输出七日新增点赞TOP1000榜单”,而代码中没有任何专门的榜单接口、七日新增点赞计算逻辑、TOP1000排行汇总逻辑或行业榜单封装。与此同时,声明还列出实时热榜、博主作品抓取、评论分析三项能力,而当前代码完全没有涉及相应接口或处理流程。因此描述显著超出代码实际行为,属于能力与主要用途不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

代码的主命令和输出均明确围绕“hot/热榜”展开:调用 getHotTask,request.command 为 hot,成功消息为“获取抖音热榜任务完成”。这与声明中的核心定位“抖音七日点赞飙升榜查询工具”存在明显偏差。虽然声明里包含“实时热榜查询”这一能力,与代码部分一致,但该代码块只覆盖了其中一个子能力,且没有实现声明中强调的主要功能与其余三项能力。因此,描述未准确代表该代码块的实际行为,属于实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

描述把该技能的主用途定义为“抖音七日点赞飙升榜查询工具”,强调七日/周度飙升榜、实时作品榜单、关键词垂类榜单等榜单能力;而这段代码只处理 --url/sec_uid 和 --limit 参数,校验博主主页 URL,调用 createPostTask / getPostTask 获取公开作品列表,输出结果。其注释“获取抖音博主作品列表”也与实际行为一致。代码中没有任何与七日点赞飙升榜、关键词榜单、热搜热榜、评论抓取相关的参数、调用或处理逻辑。因此,声明与实际行为存在明显的功能性不一致:声明的主要用途与代码真实用途 materially different,且多数宣称能力未体现在该代码中。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明将技能定位为抖音七日点赞飙升榜/周榜飙升榜工具,但该代码块的核心行为是通用搜索 CLI:输入关键词后按排序、发布时间、时长、内容类型和数量筛选搜索内容。虽然这与声明中的第(1)项“关键词搜索视频/图文”一致,但与整体主描述中的“七日点赞飙升榜查询工具”“七日新增点赞TOP1000榜单”明显不符,代码里没有任何榜单、点赞增量排行、TOP1000聚合或实时榜单专属逻辑。并且声明的另外三项能力在该代码块中也没有体现。因此描述相对该代码块存在实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码片段仅实现了通用参数解析与帮助文本生成(parseArgs、readValueAfterFlag、buildHelp),属于底层 CLI 辅助模块。它不包含任何与抖音平台交互、网络请求、榜单计算、关键词检索、作品抓取或评论分析相关的行为。虽然这类工具函数可能作为更大项目的支持模块存在,但就所给代码片段本身而言,其实际行为与声明的技能核心功能明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音数据抓取与榜单分析的工具,核心应涉及网络请求、抖音内容检索、榜单计算或评论/作品数据获取。而提供的代码片段只是在本地文件系统中保存日志内容,属于通用辅助模块,与所宣称的业务功能没有直接对应关系。虽然日志记录可作为配套实现细节存在,但该代码片段本身并未体现任何声明中的主要能力,且实际访问了本地文件系统这一与描述不相符的资源。因此该描述与代码行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个功能完整的抖音数据分析/榜单查询工具,但提供的代码片段只是一个本地工具函数:读取 package.json 并返回 name 字段。其实际行为与所宣称的核心用途完全不一致。虽然该代码访问本地文件系统属于实现细节,但它没有体现任何与抖音榜单、搜索、抓取或评论分析相关的逻辑,因此应判定为明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音内容分析的功能型工具,而给定代码片段只处理访问令牌的格式验证与错误提示,且包含引导购买私有 TOKEN 的输出。该代码既不访问抖音数据,也不执行任何榜单、搜索、作品抓取或评论分析相关操作。因此就当前代码片段而言,其实际行为与声明用途存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明中的核心用途是“抖音七日点赞飙升榜/周榜飙升”查询,并扩展到作品搜索、博主抓取、评论分析等多项能力。但提供的代码只包含 formatMessage(result) 一个纯格式化函数,输入似乎是热榜条目数组,输出标题明确为“抖音最新热榜”,字段也对应热搜词条的热度、搜索量和上榜时间。这与“七日新增点赞榜单作品”这一主要目标明显不一致。虽然声明里提到支持“实时热榜查询”,代码与这一子能力相符,但就当前代码块而言,它没有体现声明的核心榜单逻辑,也没有体现其余三大能力,因此描述与实际行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 72)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description is entirely in Chinese and presents the skill's activation/use conditions only in that language. There is no indication that users may choose another language or locale, which can be a natural-language policy concern when the skill is not explicitly documented as Chinese-only or region-restricted.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest markets the package as a narrowly scoped seven-day Douyin like-surge ranking tool, but the exposed scripts and description indicate broader capabilities including search, post scraping, comment analysis, and hot-trend querying. This scope mismatch is dangerous because it can mislead reviewers, users, or policy gates into granting trust or permissions to a package that performs more extensive collection and analysis of platform data than advertised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README explicitly promotes automatic JSON logging of retrieved Douyin data, including comment content, but does not prominently warn that these files may contain personal data, user-generated content, or other sensitive business intelligence stored persistently on disk. In the context of a scraping/analytics skill, silent local retention increases the chance of unintended disclosure through shared workstations, backups, source-control commits, or log collection systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file documents commands to fetch a creator's published works and up to 10,000 comments from Douyin URLs or identifiers, which affects third-party data privacy and may have platform-policy implications. The descriptions are purely operational and do not include any warning or disclosure about handling public user data, consent, or responsible use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script sends the supplied URL and limit to remote APIs to create and retrieve a comment task, but it does not clearly disclose this network transmission to the user before doing so. In a scraping/analytics context, the provided URL may reveal what content the user is investigating, and silent transmission to a third-party backend can create privacy, compliance, or operational risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The CLI writes fetched comment results to a local JSON file automatically, and those results may contain user-generated content or other potentially sensitive data. Because the write happens by default and there is no explicit opt-in or prominent disclosure at the write site, users may unintentionally persist scraped data to disk, increasing privacy and data-handling risk on shared or monitored systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code uses Chinese-only natural-language strings in comments, errors, status messages, and success output, but provides no user opt-in or indication that the skill is intentionally limited to a Chinese-speaking audience. That can violate language/locale policy when a skill forces a specific language by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code persists the full command output, including the requested URL and retrieved results, to a local file via log.taskWrite(...). Although the operation is implemented directly in the CLI, there is no visible warning, confirmation prompt, or disclosure in this file that running the command will create a local artifact containing scraped data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The code reads process.env.GUAIKEI_API_TOKEN and then uses the token and user-provided keyword in API operations through createSearchTask and getSearchTask. Although the skill's purpose is search and some network use is implicit, this file does not visibly disclose credential use or that user input is transmitted to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI writes the full search output to a local JSON file using a filename derived from the keyword and parameters, but this file persistence is not clearly disclosed in the code path shown. Search queries and returned content may contain sensitive business interests, research topics, or other user data, and leaving them on disk can create unintended exposure to other local users, backup systems, or later compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Multiple user-visible error messages are hard-coded in Chinese, including authentication and network failure text. The file does not offer language selection or indicate that the skill is intentionally limited to a Chinese-speaking or region-specific context, which conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file emits all user-facing warning and status messages exclusively in Chinese, including operational warnings and promotional text. That creates a language/locale policy issue because the skill does not offer a user opt-in or alternative language path, and no region-specific justification is documented in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains natural-language comments and user-visible validation errors exclusively in Chinese, such as the messages emitted at L011, L015, L019, and L024. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON schema contains user-facing title and description strings exclusively in Chinese, which can impose a specific language on users without offering any locale choice or opt-in. The policy explicitly flags language or locale constraints when they are forced rather than documented as optional or region-specific.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16