Back to skill

Security audit

GUAIKEI抖音社媒数据复盘

Security checks for vulnerabilities and agentic risk

Overview

This Douyin analytics skill is coherent and purpose-aligned, but users should know it sends queries or links to a third-party API and saves some results locally.

Install only if you are comfortable sending Douyin keywords or links and your GUAIKEI_API_TOKEN to www.guaikei.com. Expect search, post, and comment results to be written to a local logs folder; delete those files if the results include sensitive business research or personal comment data you do not want retained.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音社媒分析的完整数据能力集合,但所给代码块仅包含 args.js,实现的是通用命令行参数解析和帮助文本生成。这属于基础支持组件,而不是声明中的核心业务功能。代码没有显示任何与抖音、视频、评论、热榜、博主作品、数据分析相关的逻辑,也没有网络访问、API 调用、数据抓取或内容评估行为。因此,就该代码块本身而言,其实际行为与声明用途存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

代码片段的实际功能仅是将字符串内容写入本地日志文件,涉及 fs/path 的文件系统操作和日志输出。这与声明的核心用途——抖音社媒数据搜索、抓取、分析与复盘——没有直接对应关系。虽然日志记录可能属于辅助实现细节,但当前提供的代码片段本身不展示任何已声明能力,反而明确执行了未声明的本地文件写入。因此该描述与代码行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Yes, this is a clear mismatch. The declared description promises substantial Douyin-focused functionality: keyword search, hot-topic retrieval, creator work scraping, and comment/interaction analysis. The actual code chunk does none of that. It simply reads package.json from the local filesystem, caches the package name, and returns it. While this may be a harmless utility file within a larger project, based on the supplied code chunk alone, the behavior is unrelated to the declared purpose.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 76)May include surrounding context.

md
## 1.0.2 - 2026-03-24

- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI persists fetched comment data to a local JSON file after completing its main task, but there is no user-facing disclosure or apparent necessity in the stated skill behavior. Because comment content and engagement data can include sensitive or regulated information, silent local retention increases the risk of unintended data exposure, over-collection, and leakage from shared systems or downstream tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code writes the full comment retrieval output to a local file without warning the user, creating undisclosed data persistence. In the context of a social-media analysis skill, comment text, metadata, and interaction details may contain personal data, so silent storage broadens exposure beyond the immediate command result.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file contains multiple user-facing strings in Chinese, including error and success messages, but offers no option to select another language or any indication that the skill is intentionally limited to a Chinese-speaking audience. That creates a natural-language policy concern because the skill effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI persists fetched Douyin post results to a local JSON file via log.taskWrite, which introduces data-retention behavior beyond simply returning analysis results to the caller. Even if the data is public social-media content, writing it to disk can create unintended local disclosure, accumulation of scraped data, and privacy/compliance risk if the host environment assumes transient processing only.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a Douyin analytics skill focused on searching content, retrieving rankings, fetching creator works, and analyzing comments. This utility persists arbitrary content into local files under a logs directory, which is behavior outside the described retrieval and analysis scope rather than an obvious implementation detail of those user-facing capabilities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code returns multiple natural-language messages in Chinese such as "请求失败", "响应解析失败", and "网络错误". Per the policy, forcing a specific language without offering a language or locale choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file emits user-facing status/error text only in Chinese ("GUAIKEI_API_TOKEN未配置或无效。" and "已使用配置的私有TOKEN"). Per the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is documented and justified, which is not shown here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and description fields are written only in Chinese, which imposes a specific language on users of this schema. The file does not indicate that the skill is region-specific or provide any opt-in or alternative locale, so this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This manifest-like JSON schema contains user-facing title and description strings only in Chinese. Because there is no accompanying opt-in, language selection, or documented region-specific justification in the file, it creates a natural-language locale policy concern under the requirement to avoid forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This JSON schema uses Chinese-only natural-language title and description fields throughout, including the top-level metadata and property descriptions. For a general-purpose skill asset, that imposes a specific language/locale without any visible opt-in or justification, which matches the language-policy concern for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This manifest-style JSON schema contains all user-facing title and description fields in Chinese only, which can constitute a language/locale policy issue when no opt-in, alternate locale, or justification is provided. The file gives no indication that the skill is intentionally region-specific or that users can select another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON manifest/schema contains user-facing natural-language metadata such as title and description values entirely in Chinese. Under the stated policy, forcing a specific language without user opt-in or a documented locale-specific justification is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The title and descriptions are entirely in Chinese, which imposes a specific language on users of this schema. The file does not indicate that the skill is region-specific or that users can opt into this locale, so it appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON schema contains natural-language titles and descriptions entirely in Chinese, including the top-level title/description and nearly all field descriptions. Because the file provides no indication that the skill is China-specific or that users can choose their preferred language, it may violate a language/locale policy that requires user opt-in rather than forcing a specific language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language description on L04 forces a specific language context for understanding the skill metadata, with no opt-in or alternative language provided. Under the language/locale policy, this can be a policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The README is entirely in Chinese and presents all usage guidance, warnings, and operational instructions in that language without indicating any user language choice or opt-in. Under the policy criteria, forcing a specific language without offering a choice can be a natural-language policy issue unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes four supported capabilities centered on keyword search for videos/images, hot-list lookup, creator posts, and comment analysis. The changelog states the skill supports retrieval of broader '公开内容检索(视频、图文、用户等)', which adds user search as a claimed behavior beyond the manifest's declared scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest's search capability is limited to keyword searching for videos and image-text content, while the changelog says the skill provides a general Douyin search interface for '视频、图文、用户及社交数据搜索'. That wording expands the apparent functionality to user search and generic social-data search not reflected in the manifest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all skill instructions and examples exclusively in Chinese, which can impose a fixed language requirement on users without opt-in or alternatives. The policy specifically calls for flagging language or locale constraints when the skill forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The function sends the user-supplied video URL and an authentication token to an external API via requestApi, but the code only includes developer-facing docstrings and no visible confirmation, print/log disclosure, or other user-facing warning. For code files, outbound transmission of user or system data should have some form of disclosure unless clearly surfaced elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16