Back to skill

Security audit

抖音定向舆情监测助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Douyin public-data analysis tool, but users should understand it sends queries and its API token to a third-party service and saves result logs locally.

Install only if you are comfortable sending Douyin keywords or links and the GUAIKEI_API_TOKEN to www.guaikei.com. Use it for public Douyin data only, avoid collecting more comments or profile data than needed, and periodically delete or protect the generated logs directory if results contain user/comment metadata.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

代码文件 src/utils/args.js 仅实现 readValueAfterFlag、parseArgs 和 buildHelp 三个通用工具函数,用于解析 CLI 参数、检测重复/缺失参数、处理布尔与字符串选项、生成帮助文本。这属于基础命令行支持组件,而声明描述的是一个面向抖音舆情监测的数据采集与分析技能,涉及外部平台数据访问、搜索/抓取、评论互动分析、热榜查询和报告生成。当前代码片段没有表现出这些核心能力,因此就该代码片段而言,描述与实际行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

从提供的代码看,它只是一个通用日志工具函数 taskWrite(filename, content),用于校验参数、清理文件名、创建目录并写入本地文件。声明描述的是一个面向抖音舆情监测的数据采集与分析型技能,涉及外部平台数据获取和分析输出;而该代码既没有网络请求、抖音接口调用、数据解析,也没有分析逻辑。虽然日志写入可被视为辅助实现细节,但当前代码片段本身与声明功能没有直接对应,表现出的实际行为主要是本地文件写入,因此该片段与声明用途存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音数据采集与舆情分析的完整技能,但给出的代码片段只是一个本地辅助函数,使用 fs 和 path 读取 package.json 中的 name 字段并缓存返回。该代码没有体现任何抖音接口调用、关键词检索、评论抓取、热榜查询、数据分析或报告生成行为。虽然单个片段可能只是项目中的一部分,但就当前提供的代码而言,其实际行为与声明的核心用途明显不一致,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 76)May include surrounding context.

md
## 1.0.2 - 2026-03-24

- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description states the skill will '进行分析并输出舆情报告', and the entire user-facing description is presented only in Chinese, indicating a fixed language/locale expectation. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file uses Chinese throughout, including the title and all update descriptions, with no indication that the language is optional or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation explicitly supports collecting Douyin posts, comments, and interaction metrics at scale, but it provides no warning about privacy, lawful basis, platform terms, retention, or downstream handling of potentially personal data. In a sentiment-monitoring skill, this omission increases the risk that users will perform broad collection and profiling without appropriate safeguards, especially when comments and creator metrics can contain identifiable or sensitive information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code performs a POST request to an external Douyin comment API using a user-provided URL and an authentication token. The file contains no confirmation prompt, user-facing log, or warning text disclosing that data will be transmitted off-system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This GET request sends the video URL and token to an external endpoint to fetch comment data. There is no visible prompt, log, or inline warning in this file informing users that their request parameters and credentials are transmitted over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool writes the full comment results to a local JSON file without a clear user-facing warning or disclosure in this CLI, creating an undisclosed data retention behavior. In a sentiment-monitoring skill, the collected comments may include user-generated content and metadata, so unexpected storage can expose sensitive information to other local users, backup systems, or downstream tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The calls to post.createPostTask and post.getPostTask use the provided URL and token, indicating network transmission of user and credential-related data. This file shows progress logs, but those messages do not explicitly disclose that data is being sent to an external service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI persists fetched Douyin post results to a local JSON file after successful execution. These results may contain scraped profile and post metadata that users may not expect to be retained on disk, creating unnecessary data exposure on shared systems, in backups, or through later compromise; this is especially relevant because the file write is not clearly disclosed in this code path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill writes fetched results to a local JSON file without any clear user-facing disclosure in this file. Silent persistence can violate user expectations and privacy requirements, and may expose collected data to other local users, backup systems, or later malware on the host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits all user-facing error messages in Chinese, which imposes a specific language on users without any visible opt-in or locale selection. Under the policy, forcing a language without user choice is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The schema title and description are written only in Chinese, which imposes a specific language on users without any opt-in or indication that the skill is intentionally region-specific. The policy allows locale constraints when they are explicitly documented and justified, but this file provides no such justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON schema contains user-facing natural-language fields such as the title and descriptions exclusively in Chinese. Because the file does not offer a language choice or document that the schema is intentionally limited to a Chinese-only audience, it may violate the language/locale policy requiring opt-in or justified constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The schema title and description are written only in Chinese, which imposes a specific language on consumers of the skill metadata. The file does not document that it is intended only for a Chinese-speaking or region-specific context, nor does it offer any language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and description are written only in Chinese, which imposes a specific language on users through the natural-language interface text. There is no indication that the skill is region-specific or that another language option is available, so this appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This JSON schema uses Chinese-only natural-language metadata in the top-level title and description. Because SQP-3 applies to all file types, this can be treated as a locale policy issue when the skill does not offer any language choice or document a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The title and property descriptions are written entirely in Chinese, which imposes a specific language/locale in the skill's natural-language interface metadata. The file does not indicate that this is an opt-in language choice or a region-specific constraint, so it may violate the language/locale policy for broadly used skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions throughout, including the top-level title/description and property descriptions. Because the file provides no user choice, opt-in, or justification that the skill is region-specific, it can violate a language/locale policy requiring neutrality or user selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README uses Chinese throughout and does not provide an opt-in language choice or explain that the skill is intentionally limited to Chinese-speaking users. This is a natural-language locale constraint that may violate organizational language-choice policy when presented to a broader audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

Natural-language policy violations include forcing a specific language without user opt-in. This file's headings, parameter descriptions, and examples are all presented only in Chinese, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This file uses Chinese-only natural-language comments and parameter descriptions, which can amount to an implicit language constraint for maintainers or operators. The file does not indicate that the skill is intentionally region- or language-specific, nor does it offer any language choice.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16