Back to skill

Security audit

抖音流量实时监控(平台流量分配)

Security checks for vulnerabilities and agentic risk

Overview

This Douyin monitoring skill matches its main purpose, but it automatically keeps local copies of searches, posts, and comments without clear in-skill opt-in or retention controls.

Install only if you are comfortable sending Douyin keywords or links to guaikei.com and having successful search, creator-post, and comment results saved under the skill's local logs directory. Avoid using it for sensitive monitoring targets unless you have a plan to protect and delete retained logs, and confirm your use complies with Douyin terms and applicable privacy rules.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/log.js:25
Finding

Automatic Undisclosed Retention of Queries and Scraped Data

Content
View full analysis
Remediation
View remediation
` or `--save` to enable persistence. 2. **Obtain explicit consent** - Clearly state before execution that results will be stored locally when persistence is enabled. - Document the destination, retained fields, and retention behavior in `SKILL.md` and `readme.md`. 3. **Avoid sensitive filenames** - Do not include raw search keywords or user-supplied URLs in filenames. - Use a random identifier, timestamp, or non-reversible identifier instead. 4. **Apply restrictive permissions** - When storage is requested, create directories and files with owner-only permissions where supported. - For example, use mode `0o700` for directories and `0o600` for files. 5. **Add retention controls** - Support automatic deletion after a configurable period. - Provide a documented cleanup command. - Set a maximum number or total size of retained files. 6. **Minimize stored data** - Store only fields explicitly requested by the user. - Consider redacting request parameters, profile identifiers, comments, and other metadata unless needed. 7. **Align documentation with behavior** - Clarify that “no write operations” refers only to remote Douyin actions. - Explicitly disclose any local filesystem writes and distinguish them from platform-side writes. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the implementation writes logs or fetched content to the local filesystem while the skill claims to be a read-only JSON-returning tool, that creates undisclosed local persistence and potential data leakage. Users and orchestrators may invoke it assuming no local side effects, but saved logs/content can expose searched keywords, URLs, returned public data, or operational metadata to other local users/processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation writes logs or fetched content to the local filesystem while the skill claims to be a read-only JSON-returning tool, that creates undisclosed local persistence and potential data leakage. Users and orchestrators may invoke it assuming no local side effects, but saved logs/content can expose searched keywords, URLs, returned public data, or operational metadata to other local users/processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation writes logs or fetched content to the local filesystem while the skill claims to be a read-only JSON-returning tool, that creates undisclosed local persistence and potential data leakage. Users and orchestrators may invoke it assuming no local side effects, but saved logs/content can expose searched keywords, URLs, returned public data, or operational metadata to other local users/processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation writes logs or fetched content to the local filesystem while the skill claims to be a read-only JSON-returning tool, that creates undisclosed local persistence and potential data leakage. Users and orchestrators may invoke it assuming no local side effects, but saved logs/content can expose searched keywords, URLs, returned public data, or operational metadata to other local users/processes.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 77)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This section documents scraping a creator's posts, extracting profile metrics, and collecting comments at scale, but provides no warning about privacy expectations, lawful basis, rate limits, or platform terms compliance. In a skill explicitly designed for monitoring competitors, public sentiment, and account tracking, the absence of safeguards increases the likelihood of misuse for surveillance, mass profiling, or platform-abusive collection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI persists full retrieved comment results to a local JSON file by default after printing them, without obtaining user consent or clearly disclosing that data will be stored on disk. Because comment data can contain personal information, usernames, text content, and behavioral metadata, this creates an unnecessary data-retention risk and can expose sensitive scraped data to other local users, backups, or downstream tooling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code returns user-facing status and error text only in Chinese, such as the authentication error message. Because the skill does not offer any language selection or document a justified locale restriction, it enforces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple error, empty-state, and success messages are emitted only in Chinese across the CLI flow. This creates a natural-language policy issue because the skill imposes a single locale on all users without offering a choice or clearly justifying the restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code creates and fetches a remote post task, transmitting the provided URL/sec_uid and authentication token to an external service, and later writes the retrieved results to a local JSON file. While there are status messages about task progress, there is no explicit warning that user input is sent over the network and that output is persisted locally, which is the kind of disclosure this rule asks for in code files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Search results are written to disk without a clear user-facing warning at execution time, so operators may believe output is transient JSON on stdout when it is actually retained locally. Because this skill is for traffic monitoring, competitor analysis, and comment/public-opinion tracking, the logged data can expose sensitive operational interests and collected content history to other local users or later compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits user-facing status and error messages only in Chinese, including validation errors at L07 and L11. The file provides no indication that the skill is region-specific or that users can choose their preferred language, which violates the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits multiple hard-coded Chinese error strings such as "请求失败", "响应解析失败", and the authentication guidance message. Because the file provides no opt-in, locale selection, or documentation that the skill is intentionally China/Chinese-specific, it imposes a specific language on users and violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JavaScript file contains multiple natural-language strings shown to users exclusively in Chinese, such as the validation errors on lines 6, 10, 14, 19, and throughout option validation. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest description and trigger wording are entirely in Chinese and present example invocations only in Chinese, which implies a fixed language/locale for use. The file does not state that users may interact in other languages or choose their preferred locale, so this can conflict with a language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON schema contains user-facing title and description strings exclusively in Chinese, such as the title and parameter descriptions. Because the file does not document that the skill is China-specific or offer any language choice, it may violate a language/locale policy requiring user opt-in or explicit scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The schema title and description are written only in Chinese, which imposes a specific language/locale in the skill artifact without indicating user opt-in or a documented regional limitation. Under the policy criteria, language-specific behavior should either offer a choice or clearly justify the locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON schema uses Chinese-only natural-language metadata in the title and description fields, which can impose a specific language/locale on downstream users or tools. The file does not offer any language choice or explain that the schema is intentionally region-specific, so it may violate a language/locale policy requiring opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema contains user-facing title and description fields entirely in Chinese, which effectively forces a specific language for users consuming the schema. The file does not mention that Chinese is optional, configurable, or required for a region-specific use case, so it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This JSON schema uses Chinese-language title and description text as the only documented natural-language interface metadata. For a general-purpose skill asset, that imposes a specific language/locale without any visible opt-in or justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The schema title and description are written entirely in Chinese, and all field descriptions in the file follow the same pattern. For a generally reusable CLI schema, this can amount to an implicit language constraint without any documented opt-in or justification for limiting the interface/documentation to a specific locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON schema contains human-readable title and description strings only in Chinese, including the top-level title/description and per-field descriptions. Because the file does not indicate that Chinese is optional or that the schema is intentionally region-specific, it imposes a specific language on consumers without user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes the skill as a Douyin traffic monitoring and structured search/comment/hotlist data tool, emphasizing author, engagement, tags, and links for analysis. This schema additionally defines play_addr as a video playback/download URL, which expands the output toward content retrieval/downloading rather than just monitoring metadata.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language description at L04 forces a specific language/locale for user-facing package metadata, which can violate language-choice policy when no opt-in or justification is provided. There is no indication elsewhere in this file that the package is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16