T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:99- Finding
API Token Exposed Through URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to perform the advertised Douyin data retrieval, but it needs review because it handles an API token insecurely and automatically saves scraped result datasets locally.
Install only if you are comfortable sending Douyin keywords, profile or video URLs, and a GUAIKEI API token to guaikei.com, and with retrieved public Douyin results being saved locally by default. Prefer a low-privilege or revocable token, avoid running it on shared or CI machines, review and delete the logs directory regularly, and use the data only where Douyin terms and privacy law allow it.
src/utils/request.js:99API Token Exposed Through URL Query Strings
src/douyin/search-cli.js:258Automatic Plaintext Retention of Complete Result Datasets
The reported implementation focuses on token handling and promotional guidance for obtaining a private token rather than the advertised analysis features. This is risky because it encourages users to provision secrets to a skill whose real behavior is unclear, increasing exposure of credentials and enabling deceptive or unnecessary secret collection.
The reported implementation focuses on token handling and promotional guidance for obtaining a private token rather than the advertised analysis features. This is risky because it encourages users to provision secrets to a skill whose real behavior is unclear, increasing exposure of credentials and enabling deceptive or unnecessary secret collection.
The reported implementation focuses on token handling and promotional guidance for obtaining a private token rather than the advertised analysis features. This is risky because it encourages users to provision secrets to a skill whose real behavior is unclear, increasing exposure of credentials and enabling deceptive or unnecessary secret collection.
The reported implementation focuses on token handling and promotional guidance for obtaining a private token rather than the advertised analysis features. This is risky because it encourages users to provision secrets to a skill whose real behavior is unclear, increasing exposure of credentials and enabling deceptive or unnecessary secret collection.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。
Without declared permissions the skill's intent is opaque and cannot be validated.
The trigger list mixes specific phrases like '抖音搜索' with broader phrases such as '短视频选题', '抖音舆情', and '抖音数据分析', which can overlap with common strategy, writing, or analysis requests that do not necessarily require this scraping skill. Although nearby text narrows scope somewhat, the trigger list itself lacks explicit exclusions for these broad phrases and could cause unintended invocation.
The README explicitly states that scraped results are automatically saved as JSON logs, including video, author, and comment data, but it does not clearly warn users that potentially sensitive or regulated third-party content will persist on local disk. This creates a real data-handling risk: users may unknowingly retain large volumes of scraped content and comments, increasing exposure to privacy, compliance, and accidental disclosure issues if logs are shared, synced, or left unsecured.
The file documents large-scale scraping of Douyin search results, creator posts, hot topics, and comments, including up to 10,000 records, but provides no guidance on privacy, lawful use, rate limiting, consent boundaries, or platform terms. In an agent skill context, this omission increases the chance the tool will be used for unauthorized collection, profiling, or policy-violating surveillance of user-generated content and creator activity.
The CLI writes fetched comment results to a local JSON file automatically after execution, but this side effect is not clearly disclosed in the skill description or in runtime prompts. Because comment data may contain personal identifiers, opinions, or sensitive content, silent persistence increases the risk of unintended retention, local data exposure, and mishandling on shared systems.
Comment results are saved locally without any explicit warning, confirmation, or consent flow, which creates a transparency and privacy problem. In the context of a scraping/analysis skill that processes social-media comments at scale, undisclosed storage makes accidental collection and retention more dangerous, especially on multi-user machines or automation hosts.
The code reads a credential from GUAIKEI_API_TOKEN and sends the normalized URL and limit to createPostTask/getPostTask, which implies transmission of user-provided data to an external service. This file does not clearly warn the user that invoking the CLI will send that data off-host.
The CLI writes the full scraped results to a local JSON file automatically, without any opt-in, path disclosure, or redaction. Because the data may include comments, author identifiers, URLs, and analysis output, this creates an unintended local data retention channel that can expose collected data to other local users, backups, log collectors, or later compromise of the host.
The CLI persists the full search output to a local JSON file automatically after execution, but there is no explicit user consent, warning, or visibility into where the file is stored. In this skill’s context, search queries and returned Douyin content may contain sensitive research targets, monitoring subjects, or business-intelligence data, so silent local persistence can create unintended data exposure on shared machines, CI runners, or multi-user environments.
This code contains hard-coded Chinese user-facing error strings, and the success/error output later in the file continues the same pattern. For a general utility module, forcing a specific language without offering user choice or documenting a locale-specific scope is a natural-language policy violation under the language/locale rule.
This code returns user-facing error text in Chinese, such as "请求失败", without offering a language choice or indicating that the skill is intentionally limited to a Chinese-speaking context. That creates a natural-language locale policy issue because the file forces a specific language for runtime messages.
The authentication error message is entirely in Chinese and includes locale-specific support instructions, with no evidence of user opt-in to that language. This forces a specific language/locale in a user-visible path and therefore violates the natural-language policy criteria.
The user-facing strings in this module are entirely in Chinese, including warnings and status messages, with no indication that the skill is China-specific or that users can opt into another language. This creates a natural-language locale policy issue because the skill implicitly forces one language on all users without documented justification.
This JavaScript file contains user-facing natural-language strings exclusively in Chinese, including the module description and banner text. Under the policy for natural-language constraints, forcing a specific language without explicit user choice can be a locale-policy violation unless clearly documented as region-specific.
The file’s docstrings, validation errors, and formatted result messages are all hard-coded in Chinese, including user-visible strings such as error messages and search result labels. This imposes a specific language/locale on users without any apparent opt-in or configuration path, which matches the language/locale policy violation criteria.
The manifest description and usage guidance are presented entirely in Chinese and assume Chinese-language interaction, but do not state that the skill is Chinese-only or offer an alternative language option. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy issue unless clearly justified and documented.
The natural-language fields in this schema, including the title and descriptions, are entirely in Chinese and do not indicate that the skill is region-specific or that users may choose another language. Under the policy rules, a fixed language without opt-in or justification is a locale-policy concern.
The schema title and description are written only in Chinese, which imposes a specific language on users or downstream tooling without indicating that the schema is locale-specific or offering an alternative. Under the policy, language constraints should be justified or optional rather than implicit.
This JSON schema uses Chinese-only natural-language metadata in the title and field descriptions, which can amount to a language/locale policy constraint if the skill is expected to support users more generally. There is no accompanying indication that the schema is intentionally region-specific or that language choice is configurable.
This manifest-style JSON file uses Chinese-only natural-language titles and descriptions for the skill inputs, but it does not state that the skill is intended only for Chinese-speaking users or offer any language choice. Under the policy, forcing a specific language without opt-in can be a locale/language policy violation.
Detected: suspicious.exposed_secret_literal