Back to skill

Security audit

抖音作品搜索

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Douyin public-data query tool that uses a third-party API token and saves local JSON result logs, so users should treat outputs as retained data.

Install only if you are comfortable sending Douyin keywords, links, IDs, and retrieved public content to guaikei.com using your GUAIKEI_API_TOKEN. Treat the token as a secret, and remember that search/post/comment results are saved locally in logs and may include public nicknames, comments, links, and engagement data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (51)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill routes user requests and queried content to a third-party API using GUAIKEI_API_TOKEN, yet the description frames the tool mainly as a Douyin query utility rather than emphasizing third-party data transfer and token-backed external dependency. In this context, incomplete disclosure of external processing and token use can cause users to unintentionally send query terms, links, and retrieved content to an outside service, creating privacy, compliance, and secret-handling risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill routes user requests and queried content to a third-party API using GUAIKEI_API_TOKEN, yet the description frames the tool mainly as a Douyin query utility rather than emphasizing third-party data transfer and token-backed external dependency. In this context, incomplete disclosure of external processing and token use can cause users to unintentionally send query terms, links, and retrieved content to an outside service, creating privacy, compliance, and secret-handling risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill routes user requests and queried content to a third-party API using GUAIKEI_API_TOKEN, yet the description frames the tool mainly as a Douyin query utility rather than emphasizing third-party data transfer and token-backed external dependency. In this context, incomplete disclosure of external processing and token use can cause users to unintentionally send query terms, links, and retrieved content to an outside service, creating privacy, compliance, and secret-handling risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill routes user requests and queried content to a third-party API using GUAIKEI_API_TOKEN, yet the description frames the tool mainly as a Douyin query utility rather than emphasizing third-party data transfer and token-backed external dependency. In this context, incomplete disclosure of external processing and token use can cause users to unintentionally send query terms, links, and retrieved content to an outside service, creating privacy, compliance, and secret-handling risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill routes user requests and queried content to a third-party API using GUAIKEI_API_TOKEN, yet the description frames the tool mainly as a Douyin query utility rather than emphasizing third-party data transfer and token-backed external dependency. In this context, incomplete disclosure of external processing and token use can cause users to unintentionally send query terms, links, and retrieved content to an outside service, creating privacy, compliance, and secret-handling risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill routes user requests and queried content to a third-party API using GUAIKEI_API_TOKEN, yet the description frames the tool mainly as a Douyin query utility rather than emphasizing third-party data transfer and token-backed external dependency. In this context, incomplete disclosure of external processing and token use can cause users to unintentionally send query terms, links, and retrieved content to an outside service, creating privacy, compliance, and secret-handling risk.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 72)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is entirely written in Chinese and presents the trigger and usage model only in that language, with no indication that other languages are supported or that Chinese is a documented requirement. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions for the skill interface, which effectively forces a specific language for users or integrators without any opt-in or justification. The policy allows locale constraints only when they are optional or clearly documented as region-specific, which is not indicated here.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description lists activation phrases such as "热门视频" and "爆款视频", which are broad natural-language terms that could match general conversation rather than a clearly scoped skill invocation. The file does not provide exclusions, negative examples, or tighter contextual limits to distinguish when this skill should activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README states that scraped videos, author data, and comments are automatically exported to JSON logs, but it does not prominently warn that these files may contain sensitive or regulated personal data and will persist on local disk. In a scraping/analytics skill, silent retention increases the chance of accidental disclosure, insecure sharing, or long-term storage beyond user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README tells users to obtain and set GUAIKEI_API_TOKEN, but does not give an upfront, prominent warning that the token is a secret and must not be exposed through logs, shell history, screenshots, shared terminals, or committed environment files. Because this skill depends on a third-party API credential, weak secret-handling guidance materially raises the risk of credential leakage and unauthorized API use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file defines invocation mappings for AI interpretation, and terms like '搜一下' and '找' are common everyday phrases rather than narrowly scoped commands. The trigger description does not include sufficient exclusion conditions or negative examples to prevent accidental invocation outside the intended Douyin-search context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Phrases like '热点' and '今天什么火' are broad colloquial expressions that commonly occur in everyday conversation. Because the rule does not require platform-specific context or list exclusions, it may route unrelated trend questions to this skill unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The code reads the credential-like environment variable GUAIKEI_API_TOKEN and exits based on its presence, but this file does not show a confirmation prompt, user-facing warning, or explicit comment/docstring explaining that credential access occurs. Under the code-file criteria, access to sensitive environment variables should have some visible disclosure unless clearly documented elsewhere.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI writes the full fetched comment dataset to a local JSON file after already printing it, creating a persistence behavior that is broader than a transient query/display tool. Because comment content may include personal data or sensitive business intelligence, local storage increases the risk of unintended retention, later exfiltration, or access by other local users/processes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JavaScript file contains multiple user-facing strings in Chinese, including status, error, and success messages, but does not provide any user opt-in or locale selection. Under the policy rule, forcing a specific language without choice is a natural-language policy violation unless the tool is explicitly documented as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI persists the full fetched Douyin results to a local JSON file after completing the query, even though the skill is described primarily as a query/display tool. Scraped post metadata can contain sensitive or regulated content, and silently storing it creates unnecessary data retention, disclosure risk on shared systems, and behavior beyond user expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code writes scraped results to disk without warning, confirmation, or an explicit user-selected output destination. Silent file creation can expose collected data to other local users, backups, or downstream processes, especially when operators expect the tool to only print structured results to stdout.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The tool sends user-provided keywords and filters to an external API using a bearer-like token, but the user-facing flow shown here does not clearly warn that inputs leave the local machine. In a search/scraping skill, remote transmission is expected, but lack of transparency can create privacy and compliance issues if users assume local-only processing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI writes full search results, including the user's query parameters and returned content, to a local JSON file after execution. This creates an undeclared persistence channel that may retain sensitive search activity or scraped content on disk, increasing privacy and data-handling risk beyond simple query/display behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Search results are silently persisted to a local JSON file without any user-facing warning or consent. Because the output includes user queries, timestamps, and returned data, this can leak browsing or investigative activity to other local users, backups, or later compromise of the host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code includes natural-language comments and user-visible CLI messages exclusively in Chinese, such as error text and help output. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly documented and justified, which is not present in this file.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes a read/query-oriented Douyin search and analysis skill: searching hot content, fetching rankings, creator works, and comments. This module implements persistent local file writing of caller-supplied content into a logs directory, which is not an obvious requirement of those end-user capabilities and expands the skill into filesystem persistence.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16