Back to skill

Security audit

抖音作品实时搜索

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently provides Douyin public-data search and analytics through a third-party API, with local result logging that users should manage carefully.

Install only if you are comfortable sending Douyin queries, links, and IDs to guaikei.com with your GUAIKEI_API_TOKEN. Review and delete the local logs directory as needed because saved results may include public usernames, comments, profile IDs, links, and IP-region labels.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (51)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding alleges undeclared local filesystem write behavior and a primary use of logging to disk, which is materially different from the stated read-only analytics purpose. Undeclared write capability increases risk because users may invoke the skill expecting passive data retrieval while it persists local artifacts, which can expose sensitive search terms, API responses, or user-provided links on disk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding alleges undeclared local filesystem write behavior and a primary use of logging to disk, which is materially different from the stated read-only analytics purpose. Undeclared write capability increases risk because users may invoke the skill expecting passive data retrieval while it persists local artifacts, which can expose sensitive search terms, API responses, or user-provided links on disk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding alleges undeclared local filesystem write behavior and a primary use of logging to disk, which is materially different from the stated read-only analytics purpose. Undeclared write capability increases risk because users may invoke the skill expecting passive data retrieval while it persists local artifacts, which can expose sensitive search terms, API responses, or user-provided links on disk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding alleges undeclared local filesystem write behavior and a primary use of logging to disk, which is materially different from the stated read-only analytics purpose. Undeclared write capability increases risk because users may invoke the skill expecting passive data retrieval while it persists local artifacts, which can expose sensitive search terms, API responses, or user-provided links on disk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding alleges undeclared local filesystem write behavior and a primary use of logging to disk, which is materially different from the stated read-only analytics purpose. Undeclared write capability increases risk because users may invoke the skill expecting passive data retrieval while it persists local artifacts, which can expose sensitive search terms, API responses, or user-provided links on disk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding alleges undeclared local filesystem write behavior and a primary use of logging to disk, which is materially different from the stated read-only analytics purpose. Undeclared write capability increases risk because users may invoke the skill expecting passive data retrieval while it persists local artifacts, which can expose sensitive search terms, API responses, or user-provided links on disk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding alleges undeclared local filesystem write behavior and a primary use of logging to disk, which is materially different from the stated read-only analytics purpose. Undeclared write capability increases risk because users may invoke the skill expecting passive data retrieval while it persists local artifacts, which can expose sensitive search terms, API responses, or user-provided links on disk.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 72)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger list contains broad phrases like '抖音热门' and '抖音搜索', which can cause the skill to activate on loosely related requests. In an agent setting, overbroad routing is dangerous because it may send user prompts, keywords, links, or analysis tasks to a third-party API unexpectedly, increasing data exposure and causing unintended external calls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON schema uses Chinese titles and descriptions throughout, including the top-level metadata and field descriptions, but provides no indication that the skill is intentionally China/Chinese-locale specific or that users can choose another language. That creates a natural-language locale policy concern because the file effectively forces one language without opt-in or justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The package manifest markets the skill primarily as a real-time Douyin search tool, but the exposed scripts also enable hot-list retrieval, creator post crawling, and comment analysis. This capability mismatch can mislead reviewers, users, or policy enforcement into approving broader data-collection behavior than the description suggests, increasing the risk of undisclosed scraping or privacy-impacting use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest includes very broad trigger phrases such as generic Douyin search and hot-video requests, which can cause the skill to activate for common user intents beyond narrowly scoped real-time lookups. Overbroad routing increases the chance of unnecessary invocation of a scraping-oriented tool, leading to excessive data access, policy bypass in tool selection, or unanticipated collection of content and comments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill documentation, command mapping, and natural-language invocation examples are written only in Chinese, and the examples assume Chinese-language user phrasing. There is no statement that the skill is China/Chinese-only or any opt-in choice for other languages, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly promotes collecting public video, author, comment, and hot-list data and exporting structured logs, but the warning section does not clearly explain data-handling risks, retention, sensitivity of comment/author data, or safe use constraints. Even when data is publicly accessible, bulk collection and local export increase privacy, compliance, and accidental disclosure risk, especially if logs are reused, shared, or stored insecurely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation explicitly supports fetching public creator posts and comment data at scale, but provides no warning about privacy sensitivity, platform terms, or downstream handling of personal data. In this skill context, the omission increases risk because users are encouraged to collect social-media content and identifiers in real time, which can lead to unreviewed profiling, retention, or misuse of user-generated data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language comments and parameter descriptions are exclusively in Chinese, which imposes a specific language on maintainers or users reading the skill source. The file does not indicate that the skill is region-specific or offer any language/locale opt-in, matching the policy's language-choice concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file contains user-facing natural-language documentation exclusively in Chinese, including the function descriptions and parameter meanings. Under the stated policy, forcing a specific language without offering choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends the user's search keyword and an authentication token to a remote API via requestApi, which is a privacy-relevant network operation. Although the function is documented for developers, there is no user-facing warning, confirmation, or visible disclosure in this file about transmitting that data off-system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The GET request places the search keyword and filtering parameters into the query string, which is more likely to be recorded in logs, proxies, browser history, monitoring systems, and upstream infrastructure than a request body. If the token is also conveyed in a way that can be logged by the request helper or surrounding infrastructure, user search activity and possibly credentials could be exposed beyond the intended recipient.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code contains multiple user-facing strings in Chinese, including status messages and errors, and provides no option for users to select or opt into that locale. The policy explicitly flags language or locale constraints when a specific language is forced without user choice or clear justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest centers the skill around '实时搜索抖音最新作品' and lists multiple capabilities, but this entrypoint's documented purpose is specifically '获取抖音博主作品列表'. That behavior aligns only with the manifest's blogger-scraping sub-capability, not with the broader claimed real-time search function implied by the skill name and primary description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script reads GUAIKEI_API_TOKEN from the environment and sends requests with user-supplied URL data through post.createPostTask and post.getPostTask. While network access is central to the tool's purpose, this file does not visibly inform the user that their input and token-authenticated requests will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The CLI silently writes fetched results to a local JSON file after completing the request. Because the returned data may include creator content metadata and user-request-derived data, undisclosed persistence can create privacy, retention, and data exposure risks, especially on shared systems or agent runtimes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file writes fetched results to local storage without warning the user in its interface or help output. Silent local persistence increases the chance that sensitive or unexpectedly large result sets remain on disk where other local users, processes, backups, or logs can access them.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16