Back to skill

Security audit

抖音社媒搜索与分析

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Douyin public-data command tool that uses a disclosed third-party API token and stores some results locally for later analysis.

Install only if you are comfortable sending Douyin keywords, links, and your GUAIKEI_API_TOKEN to the Guaikei API service. Review or delete the skill's local logs directory if the searched topics, creator URLs, or returned public comments are sensitive for your team.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

代码文件 src/api/search.js 只包含 createSearchTask 和 getSearchTask 两个对外函数,分别调用 /api/douyin/general-search/keyword 和 /api/douyin/general-search/info 接口,参数也仅对应关键词、排序、发布时间、时长、内容类型、数量等搜索过滤条件。这与声明中的第(1)项关键词搜索能力一致。但声明还列出了第(2)热榜查询、第(3)博主作品抓取、第(4)视频评论分析,当前代码片段中完全没有相关接口、参数或处理逻辑。因此,若将该代码块视为对该技能声明的实现,则声明范围明显大于实际行为,属于描述与代码能力不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音公开内容检索与分析的技能,应当体现对抖音数据源的访问、查询逻辑、抓取或分析流程。但提供的代码仅包含通用 CLI 参数处理函数:读取 flag 值、解析命令行参数、校验必填项、处理 boolean/default/help、以及生成帮助文本。代码没有任何网络请求、抖音接口调用、页面抓取、数据解析、搜索/排序/筛选、热榜获取、博主页处理或评论分析逻辑。因此该代码片段的实际行为与声明的核心用途存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是面向抖音公开内容的数据搜索与分析能力,而这段代码实际只是一个本地日志写入工具函数,并未体现任何抖音搜索、热榜查询、博主抓取或评论分析相关行为。虽然日志记录可作为辅助实现细节存在,但当前提供的代码块本身的功能与声明的核心能力完全不一致,且涉及未声明的本地文件系统写入能力。因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises substantial Douyin data retrieval and analysis capabilities: searching videos/posts, querying hot trends, fetching creator works, and analyzing comments. The supplied code does none of these. Instead, it merely reads the local package.json file to obtain the package name and caches the result. This is a materially different behavior from the declared purpose. While reading package metadata could be a harmless utility function, based on this code chunk alone it does not implement or directly support the advertised capabilities, so the description does not accurately represent the actual behavior shown.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 76)May include surrounding context.

md
## 1.0.2 - 2026-03-24

- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest description says the skill should be used 'when the user wants to check' brands, topics, events, or content performance on Douyin, but it does not define concrete trigger phrases, scope boundaries, or exclusion conditions. That makes invocation criteria overly broad for a manifest file and could cause unintended activation for general analysis requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description is entirely in Chinese and specifies searching '国内社媒之抖音', which implies a fixed language/locale context without offering user opt-in or explaining a justified regional constraint. Under the policy, language or locale restrictions should either be optional for the user or clearly documented as intentionally region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code sends the user-provided video URL and an authentication token to external API endpoints via requestApi, which is a network operation involving potentially sensitive data. In this file there is no confirmation prompt, user-facing log, or warning string disclosing that the data will be transmitted.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI help, status messages, and errors are presented in Chinese throughout the file, with no indication that users can select another language or locale. This creates a natural-language policy issue when a skill imposes a specific language without opt-in or documented locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The CLI persists full search output to a local JSON file, and that output includes user-provided query terms and returned social-media content/metadata. Even though the source data is public, silently storing it locally creates an undisclosed privacy and data-retention risk: sensitive investigative keywords, brand-monitoring topics, or collected comment data may remain on disk and be accessible to other local users, backups, or later processes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits multiple user-facing messages only in Chinese, such as error texts and retry logs. Because the file provides no language choice, opt-in, or documented region-specific scope, it appears to enforce a specific locale in violation of the language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains multiple user-facing error strings in Chinese, such as the validation errors printed via utils.printError. The policy for natural-language violations applies to all file types, and forcing a specific language without user opt-in can exclude users who do not understand that locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language metadata in the schema is entirely in Chinese, including the title and field descriptions, without any indication that the skill is region-specific or that users may choose another language. This can violate language/locale policy when a specific language is imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This manifest-style JSON describes the skill as handling "抖音获取作品评论, 命令行参数入参Schema详解" but provides no explicit activation phrases, scope limits, or negative examples clarifying when the skill should or should not be invoked. For manifest-like files, the absence of specific trigger constraints can make invocation boundaries ambiguous.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The title and description are written only in Chinese, which imposes a specific language on users or maintainers without any visible opt-in or justification in the file. Under the policy, forcing a specific language or locale without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON schema contains natural-language metadata entirely in Chinese, including the title and multiple description fields. For a general-purpose skill asset, this hard-codes a specific language/locale without indicating that the user can choose another language or that the schema is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The schema title and description are written only in Chinese, which can constitute a language/locale policy issue if the skill is expected to be generally usable without a documented locale restriction or user opt-in. There is no accompanying indication that this schema is intentionally limited to Chinese-speaking users or a China-specific workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON manifest/schema file contains natural-language titles and descriptions exclusively in Chinese, such as the title and multiple property descriptions. For a general-purpose skill artifact, forcing a single language without documenting opt-in or regional scope can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The title and parameter descriptions are written only in Chinese, which can constitute a language/locale policy issue when no user opt-in or region-specific justification is provided. Because this file is a manifest/config artifact consumed by broader tooling, the enforced locale may reduce accessibility for users who did not choose Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions throughout, including the top-level title/description and property descriptions. Under the stated policy, forcing a specific language without user opt-in can be a locale/language policy violation when no alternative or opt-in is documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file presents all user-facing instructions in Chinese and does not indicate that other languages are available or that Chinese is a deliberate user-selected locale. Under the natural-language policy rule, forcing a specific language without user opt-in is a locale-policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file title and all release notes are written in Chinese, and there is no indication that another language is supported or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy rule, a skill that effectively enforces a language without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

清单中的技能描述将能力限定为关键词搜索公开作品、热榜查询、博主作品抓取和视频评论分析四类。更新日志在 1.0.0 中写明“支持视频、图文、用户及社交数据搜索”,其中“用户搜索”属于额外能力表述,和当前 manifest 的能力边界不完全一致。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions, parameter descriptions, and examples only in Chinese. Under the policy rule for natural-language violations, forcing a specific language without offering user choice or documenting a justified locale constraint can be a policy issue.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16