Back to skill

Security audit

抖音达人发现与洞察

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently retrieves public Douyin data through a disclosed third-party API, with the main caution that results are saved locally by default for some commands.

Before installing, confirm you are comfortable sending Douyin keywords or links to www.guaikei.com with your GUAIKEI_API_TOKEN, and remember that search, creator-post, and comment results are saved under the skill's logs directory by default. Avoid using it for private, login-only, or redistributable data unless you have the right authorization.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (37)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

从提供的代码看,模块 src/api/search.js 的职责非常明确:调用 /api/douyin/general-search/keyword 与 /api/douyin/general-search/info 两个接口,围绕关键词搜索创建任务和获取结果,并对结果字段进行简单加工。这与声明中的第(1)项“关键词搜索视频/图文,可按点赞数、发布时间、视频时长、内容类型筛选排序”基本一致。但声明还强调四大能力,并包含热榜、作品抓取、评论分析,以及更高层的达人画像分析;这些能力在本代码片段中均没有任何对应实现。因此,若将“声明”理解为该技能由所给代码块支撑,则描述明显超出了实际行为范围,属于能力过度宣称。未发现代码存在额外未声明的敏感或不相关行为;问题在于声明比实际实现宽得多。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码片段仅包含 parseArgs、readValueAfterFlag 和 buildHelp 等通用命令行参数处理函数,功能范围是读取和校验命令行输入,并生成帮助信息。这属于底层工具代码,与声明中的抖音实时数据检索、达人分析、作品和评论抓取等核心业务能力不一致。根据评估标准,支持性实现细节本可不视为不匹配,但这里代码片段本身没有表现出任何已声明的核心能力,主要目的与声明明显不同,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 76)May include surrounding context.

md
## 1.0.2 - 2026-03-24

- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documentation is presented entirely in Chinese and does not indicate that other languages are supported or that the user can choose their preferred language. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code sends the user-supplied search keyword and authentication token through requestApi to a Douyin search endpoint. Although the function names and comments describe the API action, there is no confirmation prompt, warning, or explicit user-facing disclosure here that user query data will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The getSearchTask function performs a network request carrying the search keyword, filters, and token to a remote endpoint. The code lacks any print/log/confirmation or other visible disclosure to the user that their search inputs are being transmitted externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code writes retrieved comment data to a local JSON log file without explicit user warning or confirmation. Because this skill is specifically designed to collect and analyze public comments at scale, silent persistence materially increases privacy and data-handling risk beyond transient command output, especially on shared systems or environments with backup/sync agents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This CLI emits multiple user-facing strings only in Chinese, including errors and success messages, with no indication that users can opt into another language. That creates a locale/language policy issue because the skill effectively forces a specific language rather than offering a choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI persists the full fetched Douyin results to a local JSON file after completing the request, even though the stated purpose is to discover and analyze creators rather than archive retrieved data on disk. Because the results may contain profile details, post metadata, and potentially comment/interaction-derived data, this creates an undisclosed local data retention channel that can expose sensitive or regulated data to other local users, backups, or later compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code writes fetched results to a local JSON file without any explicit warning, consent, or indication in the normal execution path, so users may believe the tool only prints results and does not retain them. Silent persistence increases privacy and compliance risk because retrieved creator and engagement data may remain on disk beyond the session and be accessible through filesystem access, backup tooling, or shared environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The CLI persists request metadata and full search results to a local log file, which may include user-provided keywords and potentially sensitive business intelligence derived from Douyin/KOL searches. In shared environments, CI runners, or multi-user hosts, this creates an unnecessary data-retention and disclosure risk, especially because users are not clearly warned or given consent/control over persistence.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file contains multiple natural-language strings shown to users or operators in Chinese, such as error messages and retry logs. Under the language/locale policy, forcing a specific language without offering a choice or documenting a justified locale constraint is a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The title and field descriptions are entirely in Chinese, which can impose a fixed language/locale on users or downstream tooling without stating that the skill is intended only for Chinese-speaking contexts. The file does not offer a language choice or document a justified locale restriction.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This manifest-style JSON file describes the skill inputs and purpose, but the description is broad and does not state when the skill should or should not be invoked. Without explicit trigger constraints or exclusion conditions, an orchestrator could match it too broadly for general requests about comments or Douyin content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The title and description fields force a specific language/locale in natural-language metadata, but the file does not document that the skill is intended only for Chinese-speaking users or provide any language choice. Under the policy, locale-specific language should be justified or optional rather than implicitly enforced.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The schema's natural-language fields such as title and description are written exclusively in Chinese, which can impose a fixed language on downstream users or tools. Because the file does not indicate that this schema is intentionally region-specific or provide any language opt-in, it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The schema's human-readable title and description fields are written only in Chinese, which implies a fixed language choice for user-facing metadata. There is no indication that the skill offers language selection or that the Chinese-only locale is intentionally limited to a specific region or audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON schema contains user-facing natural-language metadata such as the title and description exclusively in Chinese. Because SQP-3 applies to all file types and flags locale/language constraints without opt-in or justification, this presents a language-policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions for the skill interface metadata, which can impose a specific language/locale on users without any opt-in or justification. Under the stated policy, language constraints should either offer a choice or clearly document that the skill is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions throughout, such as the title on L004 and descriptions across the property definitions. Because the file does not indicate that the skill is region-specific or that users can opt into this locale, it presents a language/locale policy concern under the natural-language policy rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file uses Chinese throughout, including headings and all release notes, but does not state that the skill is intended only for Chinese-speaking users or offer any language choice. That can create a natural-language locale policy issue if organizational guidance expects user-facing skill materials not to force a language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all usage instructions and examples exclusively in Chinese, and does not indicate that other languages are supported or that Chinese is an intentional, documented locale restriction. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This file uses natural-language strings in comments and JSDoc exclusively in Chinese, which can reflect a fixed language choice without any documented opt-in or stated region-specific justification. Under the language/locale policy rule, forcing a specific language in user- or maintainer-facing text can be a policy concern when no choice is offered.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This file’s natural-language content, including module and function documentation, is entirely in Chinese. Under the policy, forcing a specific language without opt-in or clear region-specific justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16