Back to skill

Security audit

抖音KOL对标账号

Security checks for vulnerabilities and agentic risk

Overview

The skill broadly does what it claims, but it sends its API token in request URLs and automatically saves fetched Douyin data locally.

Review this before installing if the API token has paid quota or account value. Use a restricted, revocable GUAIKEI_API_TOKEN, rotate it if exposed, and avoid running searches/comments that would create local logs containing sensitive research targets or user-generated comment data on shared machines.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:89
Finding

API Credential Exposed in URL Query Parameters

Content
View full analysis

Vulnerability Details

File Location: src/api/search.js:59-62, src/utils/request.js:89-90, and src/utils/request.js:115-117
Vulnerability Type: Sensitive credential exposure through URL query strings
Risk Level: Medium

The same token-in-query pattern is also used by the comment, post, and hot API modules.

Vulnerable Code

In src/api/search.js, the API token is inserted into the request parameter object:

js
const params = {
  _: Date.now(),
  token: token,
};

In src/utils/request.js, these parameters are serialized directly into the URL for POST requests:

js
params.skill_name = skillName();

const fullPath = `${path}?${querystring.stringify(params)}`;
const jsonData = JSON.stringify(data);

GET requests use the same URL serialization mechanism:

js
params._ = Date.now();

const fullPath = `${path}?${querystring.stringify(params)}`;
const options = {
  host: constants.BASE_URL,
  path: fullPath,
  method: "GET",
  headers: { "Accept-Encoding": "identity" },
};

Technical Analysis

The GUAIKEI_API_TOKEN value is supplied as a URL query parameter rather than through an HTTP authorization header. Although the requests use HTTPS, TLS only protects the request while it is in transit. It does not prevent the complete URL from being recorded after TLS termination.

Query strings are commonly captured by:

  • Web server and reverse-proxy access logs
  • API gateways and load balancers
  • Application performance monitoring systems
  • Error-reporting and request-tracing platforms
  • Network diagnostic tools
  • Browser or intermediary history, where applicable

The risk is amplified by the polling design. Task creation and subsequent result queries repeatedly place the credential in request URLs. Search keywords, Douyin URLs, and other request parameters may also be recorded alongside the token.

This issue does not provide operating-system pri ...[truncated 1442 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove token from all query parameter objects in the search, comment, post, and hot API modules.
  2. Transmit the credential using a standard authorization header:
js
const options = {
  host: constants.BASE_URL,
  path: fullPath,
  method: "POST",
  headers: {
    Authorization: `Bearer ${token}`,
    "Content-Type": "application/json",
    "Accept-Encoding": "identity",
    "Content-Length": Buffer.byteLength(jsonData),
  },
};
  1. Refactor postJson, getJson, and requestApi so credentials are passed separately from ordinary request parameters and cannot accidentally be serialized into URLs.
  2. Ensure reverse proxies, API gateways, application logs, and monitoring platforms redact authorization headers and sensitive query fields.
  3. Avoid including complete request URLs in exceptions, retry logs, or telemetry.
  4. Rotate existing API tokens because previously issued tokens may already be present in server or infrastructure logs.
  5. Apply expiration, least-privilege scope, usage limits, and anomaly monitoring to API tokens.
  6. Add automated tests asserting that generated request paths never contain token, api_key, secret, or equivalent credential fields.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (45)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音内容与数据分析的业务型技能,但给出的代码片段只是通用参数解析模块(parseArgs、readValueAfterFlag、buildHelp)。这类代码可作为任意 CLI 工具的辅助基础设施,但本身不执行任何抖音平台访问、数据查询、解析、抓取或分析操作。根据评估标准,单纯的支持性实现细节通常不应单独判定为不匹配;但这里的问题在于:所提供代码片段完全没有体现声明中的核心能力,且其实际主用途与声明的业务目的明显不同。因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是抖音数据查询与分析能力,但给出的代码仅实现了本地日志文件写入功能,没有任何抖音搜索、热榜查询、博主作品抓取、评论分析、网络请求、API 调用或数据解析逻辑。虽然日志模块可能作为辅助实现细节存在,但单独看该代码块,其行为与声明的核心能力完全不一致,属于明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises multiple Douyin data retrieval and analysis capabilities. However, the supplied code chunk is only a simple utility that uses fs/path to read package.json and return its name. This behavior is unrelated to Douyin analytics and does not implement any of the described end-user features. While utility code can be a supporting detail, this chunk alone does not substantiate the declared purpose and instead reflects a materially different behavior: local package metadata access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音内容检索与分析的业务技能,但所给代码片段只是一个通用的 TOKEN 管理模块。它验证 GUAIKEI_API_TOKEN 的格式,并在无效时输出暂停使用、购买/获取私有 TOKEN 和客服联系方式等提示。该行为与描述中的四大抖音分析能力没有直接对应关系。虽然令牌校验可以算作支持性基础设施,但当前片段完全看不到任何与抖音搜索、热榜、博主作品或评论分析相关的实现,因此就该代码片段而言,描述与实际行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 72)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger list contains broad phrases such as analytics, competitor analysis, and short-video topic selection that can match underspecified user requests. In an agent setting, this can cause over-triggering and unintended invocation of a skill that sends user-supplied data and links to a third-party API, increasing the chance of unnecessary data disclosure or actions outside user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README states that logs are automatically saved as JSON and the skill explicitly supports collecting public author and comment data, but it does not prominently warn users that these exports may contain sensitive or regulated personal data. This can lead to unintentional local retention, redistribution, or misuse of identifiers, comments, and engagement data, especially in monitoring and analysis workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document title is entirely in Chinese, and the changelog content is predominantly written in Chinese without any indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. This can violate language/locale policy when a skill implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

该 markdown 文档从标题到参数说明、示例注释均仅使用中文,没有提供多语言选项、用户语言偏好说明或适用区域限定。按规则,未经用户选择而强制单一语言/locale 属于自然语言政策问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This file contains natural-language content that forces a specific language/locale in comments and operation labels, such as the module description at L002 and task labels like "创建任务" and "查询任务". Under the policy, a skill should not impose a language choice without user opt-in or a documented, justified locale constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The CLI submits the target URL and parameters to external API methods to create and retrieve a comment task. While network access is part of the tool's function, this file does not clearly warn the user that supplied URLs and related request data will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The CLI writes fetched comment data to a local JSON file automatically, and comment content can contain personal data, sensitive opinions, or other regulated user-generated content. Persisting that data without explicit opt-in, path control, or retention guidance increases privacy and data-handling risk, especially on shared machines or in automated pipelines.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JavaScript file contains multiple natural-language strings in Chinese for errors, status messages, and task descriptions, but there is no indication that the skill is intentionally limited to Chinese-speaking users or that users can opt into another language. That can violate language/locale policy when a skill forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI persists full fetched Douyin post results to a local JSON file after completing the request, which creates a secondary data store beyond the user-visible query operation. Even if the data is publicly sourced, silent retention can expose collected content, metadata, and usage history to other local users, backup systems, or later compromise, especially because the skill description does not disclose this persistence behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The CLI writes full search results to a local file named with the user keyword, without an explicit user-facing warning or opt-in. In this skill context, search terms and returned Douyin content may reveal research interests, monitoring targets, or potentially sensitive business intelligence, so silent persistence increases exposure to local disclosure and forensic recovery.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Several thrown error messages are hard-coded in Chinese, including authentication and network failures, and there is no indication that the skill offers localization or requires Chinese as a documented regional constraint. This can violate language/locale policy when users have not opted into that language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code performs outbound HTTPS GET and POST requests and sends caller-supplied parameters and JSON data to a remote host via request, postJson, and getJson. Although the file has an internal API docstring and retry logging, it does not provide any user-facing warning, confirmation, or comment disclosing that user or system data may be transmitted off-box.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill emits all user-facing warnings and status messages in Chinese only, including operational guidance and promotional text. This can violate language/locale policy when no user opt-in, fallback, or documented region-specific justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file contains natural-language strings and comments entirely in Chinese, including the banner text and log descriptions. Because the skill does not offer a language choice or document that it is intentionally limited to a Chinese-speaking context, it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language comments, error messages, and formatted output entirely in Chinese, which effectively forces a specific language for user-facing interactions. Under the policy, locale-specific behavior should either offer user opt-in/choice or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This manifest-style JSON file contains user-facing title and description strings entirely in Chinese, but it does not state that the skill is limited to Chinese-speaking users or offer any language choice. That can conflict with language/locale policy expectations when a skill is used in broader multilingual environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions throughout, such as the title and field descriptions. Under the policy rule for language/locale, this can be a violation when a specific language is imposed without user opt-in or a clearly documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON schema contains human-readable title and description fields entirely in Chinese, including the top-level title/description and property descriptions. For a generally reusable skill asset, this imposes a specific language without any visible opt-in or justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The schema title and description are written entirely in Chinese, which imposes a specific language on users of this skill. The file does not indicate that the skill is China-specific or that users can choose another language, so this appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:24