Back to skill

Security audit

抖音数据分析与市场调研

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Douyin public-data research command tool, with expected third-party API use and local result logs that users should understand before installing.

Install only if you are comfortable sending Douyin keywords or links, plus your GuaiKei API token, to www.guaikei.com. Treat fetched comments and creator data as public but still potentially sensitive user-generated content, and clean up the local logs directory if you do not want results retained on disk.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the actual code does not perform the promised Douyin queries and instead accesses local files or package metadata, the skill's declared trust boundary is inaccurate. This is risky because operators may route user tasks and secrets to the skill expecting a constrained external-data workflow, while the real implementation can interact with the local environment in unexpected ways.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the actual code does not perform the promised Douyin queries and instead accesses local files or package metadata, the skill's declared trust boundary is inaccurate. This is risky because operators may route user tasks and secrets to the skill expecting a constrained external-data workflow, while the real implementation can interact with the local environment in unexpected ways.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the actual code does not perform the promised Douyin queries and instead accesses local files or package metadata, the skill's declared trust boundary is inaccurate. This is risky because operators may route user tasks and secrets to the skill expecting a constrained external-data workflow, while the real implementation can interact with the local environment in unexpected ways.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 77)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON schema includes title and field descriptions only in Chinese, which imposes a specific language on users and downstream consumers. Under the policy, locale or language constraints should be optional, user-selectable, or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description lists very broad trigger conditions such as Douyin/TikTok data analysis, market research, product selection, trends, market capacity, and competition structure. In an agent routing context, this can cause the skill to activate for loosely related analytics requests and expose user prompts or route execution to a skill that may be unnecessary or inappropriate, increasing the chance of over-collection or unintended external data access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill description, usage guidance, error-handling instructions, and support text are presented only in Chinese, with no indication that users may choose another language. Under the policy, a skill that effectively requires a specific language without user opt-in can be a locale/language policy violation unless the constraint is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly supports collecting creator profile data, public works, interaction metrics, and video comments, but provides no privacy, data-minimization, or platform-compliance guidance. In a data research skill, this omission can normalize bulk collection and downstream misuse of personal or quasi-personal data, especially when combined with large limits and direct profile/video URL inputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file’s human-readable strings in comments and JSDoc are consistently Chinese-only, which constitutes a natural-language locale constraint. The policy allows locale constraints only when user choice or a justified region-specific limitation is explicitly documented, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI persists fetched comment data to a local JSON file automatically after successful execution, without explicit user notice or consent. Because comment payloads can contain personal or sensitive user-generated content, this creates a data retention/privacy risk and increases exposure if the host machine is shared, compromised, or the working directory is synced to cloud storage or source control.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Multiple user-visible strings, including error and success messages, are emitted only in Chinese, which forces a specific language without offering user choice. This can violate language/locale policy when the skill is intended for broader use and no locale constraint or opt-in is documented in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code persists the full command output, including request details and fetched results, via log.taskWrite(). This is a file write affecting user data, but this file does not provide a specific warning or confirmation before saving the data locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code stores both query metadata and full search results in a local JSON log file without any warning, consent, or retention policy. Because search terms may reveal business strategy or sensitive interests and results may include user-generated content, silent retention increases privacy and confidentiality risk beyond what users would expect from a query/analysis skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JavaScript file contains multiple user-facing error strings in Chinese, such as the messages printed for invalid keywords and options. Because the skill does not offer a language choice or document that it is intentionally Chinese-only, it creates a natural-language locale policy concern under the rule for forced language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest-style JSON file contains user-facing natural-language strings only in Chinese, including the title and parameter descriptions. Because the file provides no alternative locale, opt-in, or justification for a Chinese-only experience, it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This JSON schema embeds all human-readable titles and descriptions in Chinese, including the top-level title/description and every property description. Because the file provides no indication that the skill is region-specific or that users can choose another language, it may violate the policy against forcing a specific language or locale without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON schema contains human-facing title and description fields exclusively in Chinese, which imposes a specific language on consumers of the skill metadata. The provided file does not indicate that the schema is region-specific or that users can opt into this locale, so it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The schema title and property descriptions are written entirely in Chinese, which imposes a specific language on users or integrators without any visible opt-in, fallback, or statement that the skill is intended only for a Chinese-speaking context. Under the policy rule for natural-language violations, this is a language/locale constraint that is not documented as optional or justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The human-facing title and descriptions in this schema are entirely in Chinese, which imposes a specific language on users without indicating that the skill is region-specific or offering a language choice. Under the stated policy, forcing a locale or language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This manifest-type file contains natural-language titles and descriptions exclusively in Chinese, including the top-level title/description and all property descriptions. Under the policy rule, forcing a specific language without documented user choice or justification is a locale/language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The only natural-language description is written in Chinese and presents the skill behavior in that locale without indicating that users may choose another language. Under the language/locale policy, a forced locale can be a violation unless the constraint is explicitly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document title and all user-facing changelog content are presented in Chinese, with no indication that other languages are supported or that the skill is intentionally restricted to a Chinese-speaking audience. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. The file content, headings, parameter descriptions, and examples are all presented only in Chinese, with no indication that language selection is optional or intentionally limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This file's natural-language content is entirely in Chinese, including the module description and function documentation, with no indication that language choice is configurable or intentionally limited to a Chinese-only audience. Under the stated policy, forcing a specific language without user opt-in can constitute a locale/language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16