Back to skill

Security audit

抖音机会研究

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Douyin public-data research skill with expected third-party API use and local result logs, and I found no hidden, destructive, or deceptive behavior.

Install only if you are comfortable sending Douyin keywords or links to www.guaikei.com with a GUAIKEI_API_TOKEN and keeping returned public-data results in local log files. Review those logs if comments, user identifiers, or research outputs should not persist on disk.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (40)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code matches one declared capability well: keyword search over Douyin content with filtering and sorting options. It creates and queries search tasks through general-search endpoints and enriches results with author URLs and formatted timestamps. However, nothing in this chunk implements the other three prominently declared capabilities: no hot search/hot榜 endpoints, no creator works listing by homepage/sec_uid, and no comment retrieval/analysis by video link or aweme_id. Therefore the supplied code chunk does not accurately represent the full declared description and is a mismatch for this chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音数据研究的功能性技能,核心应包括访问/查询抖音搜索、热榜、作品和评论数据。给出的代码片段仅实现了通用参数解析与帮助文本生成,没有任何网络请求、抖音接口调用、数据抓取、搜索、评论分析或达人作品处理逻辑。虽然 CLI 参数解析可以作为此类工具的辅助基础设施,但当前代码片段本身与声明的主要用途存在明显不一致,因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是抖音相关的数据检索与分析能力(搜索、热榜、作品抓取、评论分析),而代码片段实际只实现了一个本地日志写入辅助函数,没有体现任何抖音数据访问、抓取、搜索、分析或相关触发逻辑。虽然日志工具可能作为内部支持实现存在,但就该代码片段本身来看,其行为与声明的核心能力无直接对应,且包含未在描述中提及的本地文件写入能力。因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a Douyin research and analytics skill with multiple data-fetching and analysis capabilities. However, the supplied code chunk does not interact with Douyin, perform network requests, analyze content, retrieve creator data, or process comments. It simply reads a local package.json file to obtain the skill/package name. This is a materially different purpose from the declared functionality, so the description does not accurately represent the behavior shown in the code.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 76)May include surrounding context.

md
## 1.0.2 - 2026-03-24

- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON schema contains user-facing natural-language title and description fields entirely in Chinese, including field descriptions. Per the policy, forcing a specific language without user opt-in or justification is a natural-language policy violation, and no locale choice or region-specific justification is present in the file.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description is broad enough to activate on generic Douyin-related requests such as topic selection, growth, or user pain-point analysis, which can cause the skill to run outside a narrowly intended research workflow. Over-broad activation increases the chance of unnecessary external data access and use of scraping/search capabilities in contexts the user did not explicitly request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file title and all user-facing changelog content are written in Chinese, with no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking audience. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents commands that retrieve creator works, interaction metrics, and comment data, which can affect privacy expectations and involve bulk collection of third-party content. The description provides usage syntax and examples but does not include any warning or disclosure about handling scraped public data responsibly, respecting platform terms, or potential privacy impact.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI persists fetched comment data to a local JSON file after printing it, which creates an additional at-rest copy of potentially sensitive user-generated content without any explicit consent or retention control. In the context of a research tool that analyzes public Douyin comments, silent local persistence increases privacy and data-handling risk because comments may contain personal data, and the file may be accessible to other local users, backups, or downstream tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool writes full comment results to a local JSON file with no explicit user confirmation, which can surprise users who expect a read-only analysis workflow. Because comment datasets can contain usernames, text, timestamps, and interaction metadata, this undisclosed persistence increases privacy exposure and may violate least-surprise and data-minimization expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code presents multiple user-facing strings entirely in Chinese, including error and success messages. The file provides no mechanism for selecting language or documenting that the skill is intentionally limited to a Chinese-speaking audience, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a Douyin research skill focused on searching, ranking, fetching public works, and analyzing comments. In this file, the code accesses process.env.GUAIKEI_API_TOKEN to obtain credentials, which introduces secret-reading capability not stated in the manifest and not obviously required by the user-facing purpose as described.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI silently persists fetched Douyin results to a local JSON file after successful execution. Because the data may include profile, post, or engagement information, this creates an undisclosed local data-retention channel that can leak sensitive research outputs to other local users, backups, or log collectors.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command writes fetched results to a local file without an explicit user warning, even though the primary observable behavior appears to be stdout JSON output. This can surprise operators and cause unintended disclosure of collected data through residual files, especially in shared environments or automated pipelines.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest frames the skill as a read-oriented research tool for searching Douyin content, hot topics, creator posts, and comments. This helper performs persistent local file writes under a logs directory, which is an additional operational behavior not reflected in the described capabilities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file contains multiple natural-language strings shown to users or operators in Chinese, such as error messages and retry logs. Because the skill does not provide a language/locale opt-in or indicate that it is intentionally limited to a Chinese-speaking context, it violates the language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains multiple user-facing validation error strings in Chinese, such as the messages printed at L06, L10, L14, L19, L57, L61, L66, L71, and L75. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not evident in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The schema title and description are written only in Chinese, which can constitute a language/locale policy issue when no user opt-in or region-specific justification is provided. Because this is natural-language metadata in a JSON file, it falls under the all-file-types policy check.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON schema includes human-readable title and description fields entirely in Chinese, which can constitute a language/locale policy issue if the skill is expected to be locale-neutral or user-selectable. There is no accompanying indication that the schema is China-specific or that users can opt into this locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON schema uses Chinese-only natural-language strings in the title and property descriptions, which can impose a specific language on users or integrators. The file does not indicate that the skill is region-specific or provide any opt-in or alternative locale, so this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON schema uses Chinese titles and descriptions throughout, which imposes a specific language/locale in natural-language metadata. The file does not indicate that the skill is China-specific or provide any user opt-in or alternative locale, so it may violate the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This manifest/config file contains user-facing natural-language metadata entirely in Chinese, including the title and parameter descriptions, with no indication that the skill is region-specific or that users can opt into another language. Under the language/locale policy check, this can be considered a locale constraint that is not documented as optional or justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions throughout, such as the title and every property description. For an organizational policy that disallows forcing a specific language without user opt-in, this is a locale/language constraint with no visible alternative language option or justification in the file.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16