Back to skill

Security audit

抖音社媒运营专家

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Douyin data lookup skill, but it needs Review because it sends the API token in URL query strings and automatically saves retrieved social data locally.

Install only if you are comfortable sending Douyin keywords, video or creator identifiers, and your GUAIKEI_API_TOKEN to guaikei.com. Treat generated logs as sensitive working files: delete them when no longer needed, do not commit or redistribute them, and consider token rotation because the current implementation authenticates through URL query parameters.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:94
Finding

API Credential Exposed in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:5
Finding

Automatic Plaintext Retention of Retrieved User and Comment Data

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.slice(0, 200); } if (!safeFilename) { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename) ...[truncated 3135 chars]
Remediation
View remediation
` or `--save` so users knowingly opt into durable storage. 3. Create saved files with restrictive permissions: ```js await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, flag: "wx", }); ``` 4. Create the `logs/` directory with permissions such as `0700` where supported. 5. Add a data-minimization mode that omits stable user identifiers and `ip_label` unless explicitly requested. 6. Provide configurable retention and automatic deletion, such as deleting logs after a specified number of days. 7. Add `logs/` to `.gitignore` to reduce accidental source-control publication. 8. Warn users before saving records that include usernames, comments, stable identifiers, or IP-region labels. 9. Avoid placing raw search terms or identifiers in filenames; use a random identifier or cryptographic digest instead. 10. Document backup, deletion, retention, and access-control expectations for saved datasets. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (49)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音运营分析的数据能力技能,但代码片段实际只是底层通用参数解析模块(parseArgs/readValueAfterFlag/buildHelp),用于处理命令行输入和帮助信息生成。它不访问抖音、不处理网络请求、不解析视频/评论/博主数据,也没有任何与社媒运营分析直接相关的实现。因此代码实际行为与声明用途存在明显且实质性的不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

代码片段的实际功能只是一个通用日志落盘工具,与声明中的抖音搜索、热榜抓取、博主作品抓取、评论分析等核心能力无关。它没有体现任何抖音平台访问、网络请求、数据抓取、搜索、评论分析或用户画像处理逻辑。虽然日志功能可能作为辅助实现存在,但就该代码片段本身而言,其主要目的与声明用途明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音运营分析的外部数据查询/抓取技能,应具备访问抖音相关数据源并返回搜索、热榜、作品或评论数据的能力。但提供的代码片段仅是一个本地辅助函数,使用 fs 和 path 读取项目根目录下的 package.json,返回其中的 name 字段。其主要行为与声明用途 materially different,且访问的资源是本地文件系统而非抖音数据资源。虽然这可能是某个支持性工具文件,但就该代码片段本身而言,完全不能体现声明中的核心能力,因此应判定为明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

该代码片段是底层工具函数,功能范围仅限失败重试与指数退避,属于通用可靠性支持组件。按照评估标准,单纯的支持性实现细节通常不应判定为不匹配;但这里提供的代码片段本身完全没有任何与声明中核心能力相关的行为、资源访问或平台逻辑。声明描述的是一个面向抖音的数据采集与分析技能,而实际代码展示的是独立的重试模块,主用途明显不同,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音运营分析的数据能力技能,但提供的代码片段只是一个通用的 TOKEN 管理模块。它验证 token 的长度和字符格式,并在未配置时输出告警与获取 TOKEN 的提示。这与抖音搜索、热榜、达人主页、评论分析等核心行为没有直接关系。虽然令牌管理可能是某技能的辅助基础设施,但就该代码片段本身而言,其实际行为与声明的主要用途明显不匹配,因此应判定为描述与行为不一致。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 72)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill says it 'must trigger' for broad content-operations requests, including cases that may not actually require Douyin data access. Over-broad routing can cause unintended invocation, unnecessary third-party data transmission, and collection/processing beyond user intent, which is especially sensitive here because the skill depends on an external API service.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Broad trigger phrases such as generic analytics/content-planning terms can unintentionally activate the skill in unrelated contexts. That increases the chance of misrouting user requests and unnecessarily exposing prompts or identifiers to the external data provider, creating privacy and least-surprise risks.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The overview states that the skill automatically scans Douyin content daily, clusters results, and generates a polished daily report. However, the rest of the file only defines manual invocation of four data-retrieval CLIs and repeatedly says the skill's responsibility is to fetch data and hand it to upper-layer analysis, so the documentation actively overstates what the code does.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description uses strong mandatory routing language such as '必须触发' and a very broad set of scenarios and keywords, which can cause the orchestrator to invoke this skill even when user intent is ambiguous. In a skill that performs external data retrieval and social-media analysis, overbroad activation increases the chance of unnecessary data access, misrouting, and unintended handling of user requests outside the precise Douyin-only scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly states that scraped Douyin data and task results are automatically written to JSON log files, but it does not prominently warn that public video, author, and comment data may be persisted locally. This creates a real privacy and data-handling risk because operators may unknowingly retain scraped content on disk, where it can be exposed through backups, shared workstations, or accidental redistribution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JavaScript file uses Chinese-only natural-language documentation throughout, including module and parameter descriptions, with no indication that language is selectable or justified by a region-specific requirement. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI writes full comment results to a local JSON file automatically after execution, and those results may contain user-generated content, profile identifiers, or analysis data that operators may not realize is being persisted. In a social-media analytics skill, silent local retention increases privacy and data-handling risk because the file can later be accessed by other local users, backup systems, or unrelated processes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code contains user-facing natural-language strings entirely in Chinese, including status, error, and success messages. Under the policy, forcing a specific language without user opt-in or clear justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends the user-supplied URL plus limit to external API methods (createPostTask and getPostTask). Although the tool prints status messages, it does not clearly disclose that input data will be transmitted off-system, and this file contains no confirmation, warning comment, or docstring describing that behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

After completing the request, the skill unconditionally writes the full result payload to a file via log.taskWrite. This is a file write involving potentially sensitive fetched data, but the file contains no prior warning, confirmation, or help text indicating that results will be saved locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The CLI writes the full search output, including query terms and returned Douyin content data, to a local JSON file by default without explicit user consent, visibility, or retention controls. In a social-media analytics skill, this can create unintended local data persistence, exposing potentially sensitive business research, monitoring targets, or collected public-content metadata to other local users, backup systems, or later compromise.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

A skill intended for Douyin search, hotlist lookup, creator work retrieval, and comment analysis does not inherently require accepting a caller-provided filename and writing arbitrary string content to disk. While internal logging may be reasonable, exposing a general-purpose file write helper is a broader capability than the manifest’s business purpose justifies.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest frames the skill as a read-oriented Douyin analytics and content-operations tool: searching videos, querying hot trends, fetching creator works, and analyzing comments. This file creates directories and writes arbitrary content into a local logs folder, which is a state-changing filesystem capability not described in that operational scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file contains multiple hard-coded Chinese user-facing error messages, including authentication and network failures, with no indication that the user can choose language or locale. This can violate a language/locale policy when the skill is not explicitly documented as Chinese-only or region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The user-facing strings in this code are entirely in Chinese, including warnings and status messages, with no indication that the skill supports other languages or that Chinese-only output is an intentional, documented regional constraint. This can violate language/locale policy expectations because users are not given any opt-in or alternative locale handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file formats all user-facing messages in Chinese string literals, including headings and labels, with no indication that the skill is China-specific or that users can opt into this locale. That creates a natural-language policy issue because it forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JavaScript file contains natural-language comments and user-facing error/result strings exclusively in Chinese, including validation errors and formatted output. Because the file does not offer a language choice or document that the skill is intentionally limited to a Chinese-speaking or region-specific context, it may violate the language/locale policy requiring opt-in or justified constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest-type JSON file contains user-facing natural-language fields entirely in Chinese, including the title and parameter descriptions. Under the policy rule, forcing a specific language without opt-in or documenting a justified locale constraint is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:25