Back to skill

Security audit

抖音市场趋势洞察

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Douyin public-data lookup tool, with the main caveats that it uses a third-party API token and saves some results locally.

Install this only if you are comfortable sending Douyin keywords or links and your GUAIKEI_API_TOKEN to www.guaikei.com. Treat saved logs as retained analytics data, especially for comments or competitor research, and delete or protect the logs folder if the machine is shared.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (37)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill writes locally generated log files or arbitrary string content to the filesystem while presenting itself as a read-only external data lookup tool, that is a meaningful behavior mismatch. Undisclosed local writes can expose sensitive queried data, create persistence on the host, or be abused for unintended file creation if path handling is unsafe, especially because users are told the tool performs no local file upload or write-like side effects relevant to their workflow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill writes locally generated log files or arbitrary string content to the filesystem while presenting itself as a read-only external data lookup tool, that is a meaningful behavior mismatch. Undisclosed local writes can expose sensitive queried data, create persistence on the host, or be abused for unintended file creation if path handling is unsafe, especially because users are told the tool performs no local file upload or write-like side effects relevant to their workflow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill writes locally generated log files or arbitrary string content to the filesystem while presenting itself as a read-only external data lookup tool, that is a meaningful behavior mismatch. Undisclosed local writes can expose sensitive queried data, create persistence on the host, or be abused for unintended file creation if path handling is unsafe, especially because users are told the tool performs no local file upload or write-like side effects relevant to their workflow.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 77)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JSON schema is a manifest-type file, so natural-language policy checks apply. The title and descriptions consistently force a Chinese-language interface/description context, but the file does not document that the skill is China/Chinese-specific or offer any language/locale choice, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire skill description and operating instructions are presented only in Chinese, with no indication that users may choose another language or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all usage instructions, parameter descriptions, and examples exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code sends the provided token and user-supplied Douyin profile URL to an external API via requestApi when creating a task. While the function is documented for developers, there is no user-facing warning, confirmation, or disclosure in this file that data will be transmitted off-process.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The query path also transmits the token plus the Douyin profile URL to a remote endpoint. This is a safety-relevant network operation involving potentially sensitive account and usage data, but the file contains no user-oriented disclosure beyond developer comments.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI persists fetched comment results to a local JSON file automatically after successful execution. Comment datasets can contain sensitive or regulated content, and silent disk persistence expands the skill from transient analytics into local data retention, creating privacy, leakage, and endpoint exposure risks if the host is shared or logs are collected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code includes user-facing natural-language strings such as error and success messages exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present in this file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI persists fetched creator-post results to a local JSON file after completing the request, but this storage behavior is not surfaced to the user in this file and goes beyond a simple query/display flow. Persisting third-party content and metadata locally can create unintended data retention, privacy exposure, and forensic residue on shared or multi-user systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code silently writes fetched results to a local file without an explicit warning, consent mechanism, or user-controlled destination in this file. Because the results may include creator metadata and post information, undisclosed persistence can surprise users, leak data to other local users/processes, and conflict with expectations for a read-only analytics tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The program writes search results to a local log file after successful execution, but users are not given a prominent warning or choice about persistent file output. This can leave behind sensitive research history, result data, or metadata on shared systems, increasing the risk of unintended disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code returns multiple natural-language messages such as "请求失败", "响应解析失败", and "GUAIKEI_API_TOKEN 无效, 请检查环境变量" directly to users/operators. Because the file hard-codes a specific language with no opt-in, fallback, or documented regional limitation, it violates the language/locale policy for all file types.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code constructs all user-facing messages in Chinese, including headings and labels, with no indication that the skill is China-specific or that users can opt into the locale. That creates a natural-language policy concern because it forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema uses Chinese-only natural-language strings for the title and field descriptions, which can impose a specific language on users or downstream tooling. The file does not indicate that the skill is region-specific or provide any opt-in or alternative locale, matching the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The schema title and field descriptions are written entirely in Chinese, which constitutes a language-specific constraint in natural-language content. Because the file does not indicate that the skill is China-specific or offer any language/locale choice, this may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions throughout, such as the title and field descriptions. Because the file provides no indication that the schema is intentionally region-specific or that users can choose a locale, it may violate a language/locale policy that requires opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This JSON schema contains user-facing natural-language fields entirely in Chinese, including the title and parameter descriptions. Because the file does not indicate that the skill is region-specific or provide any language/locale opt-in, it may violate a policy requiring language choice rather than a forced locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions for the command-line input definition. For a general-purpose skill artifact, that imposes a specific language/locale without any opt-in or documented justification, which matches the language-policy concern in SQP-3.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON schema is a manifest-type file, so natural-language policy checks apply. The title and description are entirely in Chinese, which imposes a fixed language/locale in the user-facing schema metadata without any opt-in, alternative locale, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file presents all user-facing documentation in a single forced language, and there is no visible note that the skill is China-specific or that users can choose another language. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The top-level natural-language description and function docstrings are presented in Chinese only, with no indication that users can choose another language or that the locale is intentionally constrained. Under the policy rule, forcing a specific language without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16