Back to skill

Security audit

抖音作品查询 抖音关键词搜索

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Douyin public-data lookup tool, with the main cautions that it sends queries to a third-party API and saves some results locally as JSON logs.

Install only if you intend to send Douyin search terms, links, IDs, and your GUAIKEI_API_TOKEN to guaikei.com. Treat saved logs as potentially sensitive business or personal-data records, especially comment exports, and delete or protect them when no longer needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:19
Finding

Unbounded HTTP Response Buffering Can Cause Memory Exhaustion

Content
View full analysis
{ res.setEncoding("utf-8"); let body = ""; res.on("data", (chunk) => (body += chunk)); ``` ### Technical Analysis The HTTP client concatenates every response chunk into the `body` string without enforcing a maximum response size. The configured request timeout limits elapsed request time but does not constrain the number of bytes that can be received during that interval. The application supports responses containing up to 10,000 results, so legitimate responses may already be substantial. A compromised, malicious, or malfunctioning `www.guaikei.com` endpoint could return an unexpectedly large response. Node.js would continue allocating memory as chunks are appended until the response ends, the process reaches its memory limit, or the host becomes resource constrained. TLS protects the connection in transit, but it does not protect the client from an oversized response returned by the authenticated remote server. ### Attack Path 1. A user or Agent invokes one of the Douyin CLI workflows. 2. The application sends an HTTPS request to the fixed third-party API endpoint at `www.guaikei.com`. 3. The remote endpoint, or infrastructure controlling its response, returns an excessively large response body. 4. The `data` callback repeatedly appends each chunk to the unbounded `body` string. 5. Process memory usage grows until the Node.js process slows down, crashes, or is terminated by the operating system. 6. If the Skill executes inside a shared Agent runtime, the resulting resource exhaustion may also disrupt other tasks in that runtime. ### Impact Assessment Successful exploitation does not grant additional filesystem or operating-system privileges. It ...[truncated 441 chars]
Remediation
View remediation
{ receivedBytes += Buffer.byteLength(chunk, "utf8"); if (receivedBytes > MAX_RESPONSE_BYTES) { req.destroy(); reject(new NetworkError("Response exceeds the maximum permitted size")); return; } body += chunk; }); ``` 2. Inspect and reject an excessive `Content-Length` header before consuming the response, while retaining streaming enforcement because the header may be absent or inaccurate. 3. Select the maximum size based on measured legitimate payloads for the documented 10,000-result limit. 4. Consider streaming JSON parsing or pagination instead of loading the complete response into memory. 5. Apply process or container memory limits so one invocation cannot exhaust the entire Agent host. 6. Add tests for oversized fixed-length responses, chunked responses, missing `Content-Length`, and responses that remain active while continuously sending data. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:25
Finding

Fetched Douyin Data Is Automatically Retained in Plaintext Files

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (53)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明将技能整体描述为“抖音作品查询工具”,核心场景是搜索热门/爆款/最新作品与作品数据查询;虽然声明中第四项提到“视频评论分析”,但本代码片段只涉及评论任务创建与结果查询接口(/api/douyin/comment/url、/api/douyin/comment/info),没有体现作品搜索、热榜、博主作品抓取等主要能力。因此代码行为与声明的主要用途存在明显偏差。这里不是发现了危险的未声明能力,而是声明范围远大于该代码实际实现内容,且实际代码的中心能力是评论获取而非作品查询。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code chunk is narrowly focused on one declared sub-capability: retrieving Douyin hot-search/hot-list data. It does not show implementation for the tool's broader primary description around querying Douyin works by keyword, filtering by likes/date/duration/content type, fetching latest posts, scraping a creator's public works, or analyzing video comments. Because the declared purpose presents a multi-capability tool while the supplied code only implements the hot-list endpoint, the description overstates what this code chunk actually does. There is no evidence of undeclared harmful behavior; the mismatch is that most declared capabilities are not represented in the supplied code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

代码行为与声明的第一项能力基本一致:支持关键词搜索抖音作品,并带有综合排序/最多点赞/最新发布、发布时间、视频时长、内容类型、数量限制等参数,也符合“抖音作品查询/爆款/最新”等描述的一部分。但所给代码块只包含 general-search 的创建与结果查询接口,没有任何热榜接口、用户主页作品列表接口、或评论抓取/分析接口调用。因此,若将该代码块视为该技能的实际实现,则其实际能力明显少于声明的四大能力,存在描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

代码行为集中在“按视频/图文链接获取评论内容”的单一功能:解析参数 --url 和 --limit,校验抖音作品链接,调用 comment.createCommentTask / getCommentTask 获取评论列表,并输出 JSON 结果。这与声明中将技能描述为“抖音作品查询工具”且重点列出关键词搜索、热榜、博主作品抓取、评论分析四大能力不一致。虽然声明包含“视频评论分析”这一项,与代码部分吻合,但当前代码块并未体现其余核心能力,因此描述对该代码块的实际行为有明显扩大和失真。未发现额外越权或无关资源访问,主要问题是声明范围远大于实际实现。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

代码片段的实际功能非常单一:它是一个“hot”命令行入口,核心行为是获取并输出抖音热榜结果。虽然声明中包含“实时热榜查询”这一能力,因此这部分是匹配的,但声明将技能整体描述为覆盖作品关键词搜索、最新发布查询、爆款查询、博主作品抓取、评论分析等多项能力,而当前代码片段没有展示这些能力的实现或相关调用。基于该片段可见行为,其主要目的更像是热榜获取工具,而不是完整的多功能抖音作品查询工具,因此存在明显描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述涵盖多个独立能力,尤其强调关键词搜索热门/最新/爆款作品、热榜查询和评论分析;但给出的代码只处理 url/sec_uid + limit 输入,并调用 createPostTask/getPostTask 来获取博主公开作品列表。代码中没有任何关键词参数、排序参数、日期范围、视频时长、内容类型、热视频榜单、评论链接或 aweme_id 相关处理逻辑。因此,实际行为仅匹配声明中的第(3)项“博主作品抓取”,与整体声明的主要用途和能力范围存在明显不一致,属于描述显著夸大能力的情况。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

该代码块的实际功能与声明中的“关键词搜索视频/图文”部分基本一致:支持关键词、综合/最多点赞/最新发布排序、发布时间、时长、内容类型、数量限制,并返回搜索结果。但声明将技能描述为包含四大能力,而当前代码块只体现了搜索 CLI 功能,没有看到热榜查询、博主作品抓取、评论分析相关参数、调用或处理逻辑。因此描述明显宽于该代码块实际行为,存在能力层面的不匹配。未发现代码执行与声明无关的敏感或额外未声明能力。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音内容检索与分析的业务技能,核心能力应包括访问抖音作品数据、热榜数据、博主主页作品和评论信息等。但提供的代码片段仅包含 parseArgs、readValueAfterFlag 和 buildHelp 等通用参数处理函数,功能局限于命令行输入解析和帮助文本生成。该代码没有任何网络请求、抖音接口调用、数据抓取、作品过滤、评论处理或热榜分析实现。因此,代码实际行为与声明用途存在明显且实质性的偏差。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a feature-rich Douyin data retrieval and analysis tool. However, the supplied code chunk only implements taskWrite, a helper for writing log content to a local file under a logs directory. It sanitizes filenames and uses Node.js filesystem APIs to create directories and write files. This is not one of the declared user-facing capabilities, and none of the described Douyin-related behaviors are evidenced in this code. While logging can be a supporting implementation detail, this chunk by itself does not match the declared primary purpose and instead shows an unrelated filesystem utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a full-featured Douyin data retrieval and analysis tool. However, the supplied code chunk does not implement any Douyin-related querying, scraping, filtering, ranking, or comment analysis. It merely accesses the local filesystem to read package.json and return the package name. This is materially different from the declared primary purpose, so the description does not accurately represent the actual behavior of the provided code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音数据查询与分析的完整工具,但提供的代码片段只是一个 TOKEN 管理模块,功能集中在校验 GUAIKEI_API_TOKEN 的格式并打印配置提示。它没有表现出任何与抖音作品搜索、热榜、博主作品列表、评论抓取相关的逻辑,也没有访问抖音资源或处理相关输入。因此,代码实际行为与声明的核心用途明显不符。令牌校验本身可视为配套实现细节,但在当前片段中它是唯一可见功能,且还包含未在描述中提及的营销/引流提示,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码仅包含一个 utils 模块,用于打印横幅和 INFO/SUCCESS/WARN/ERROR 日志,输出目标是 stderr/console.error。虽然横幅文案提到“抖音数据智能分析助手”,但没有任何网络请求、参数处理、抖音接口调用、数据筛选、排序、抓取、评论读取或结果返回逻辑。因此,当前代码片段的实际行为与声明描述的核心能力明显不符,属于实质性描述-行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a broad Douyin works/query skill with four major capabilities. However, the supplied code chunk only formats hot-list data into a markdown message titled '抖音最新热榜'. This aligns partially with the declared hot-list capability, but does not reflect the broader primary purpose of searching works, filtering by date/duration, scraping creator works, or analyzing comments. There is no evidence in this chunk of those other capabilities or of general work-query behavior. Therefore, the description materially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 72)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description forces Chinese-language usage and examples, but does not indicate that the skill is China-specific or provide any user opt-in for language/locale. Under the policy, a skill should not impose a specific language unless the constraint is explicitly justified or optional.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger phrases are very broad and include generic terms like '热门' and '热榜', which can cause the skill to activate for common user requests beyond the user's intended scope. In an agent environment, overbroad activation can lead to unnecessary external data access, unintended handling of social-media content, or the skill being selected in contexts where a narrower tool should have been used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README promotes collecting public videos, account data, comments, and exporting them to local JSON logs, but it does not present a clear privacy/data-handling warning at the point of use. Even when data is public, bulk collection and local retention can create privacy, compliance, and misuse risks, especially for comments and account-level datasets that may contain personal information or sensitive behavioral data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file uses only Chinese for user-facing documentation content, including headings and change descriptions. Under the policy rule, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes fetched Douyin comment results to a local JSON file automatically, and comments may contain personal data, usernames, or other sensitive content. Because this persistence happens without an explicit opt-in or warning in this file, users may unknowingly leave scraped data on disk where it can be accessed by other local users, backup systems, or downstream tooling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file's natural-language strings, including status and error messages, are consistently written in Chinese, and there is no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-only audience. This can violate language/locale policy when a specific language is forced without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

User-facing help text, option descriptions, status messages, and error messages are written only in Chinese throughout the file. This imposes a fixed language/locale with no opt-in or alternative, which matches the policy-violation criterion for forced language without user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool writes full search results to a local file automatically, without clear user consent or warning. Search queries and returned content may contain sensitive business interests, investigative topics, or account-linked data, and local persistence increases the risk of unintended disclosure on shared systems or through backups and log collection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code emits user-facing validation and status messages in Chinese only, such as the error strings on L07 and L11. This imposes a specific language on all users without any opt-in, fallback, or documented region-specific justification, which matches the locale policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code builds outbound HTTPS GET and POST requests, includes a TOKEN header, and sends URL parameters and JSON request bodies to a remote host. While the file has technical docstrings and retry logging, it does not contain any user-facing disclosure, confirmation, or warning that user/system data and credentials may be transmitted over the network.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16