Back to skill

Security audit

抖音热点数据追踪

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform Douyin public-data lookups as described, but it automatically saves search, post, and comment results locally despite the main skill instructions claiming no writes.

Review before installing if you will run this in a shared, synced, backed-up, or committed workspace. The skill sends your Douyin keywords or links to www.guaikei.com and uses a GUAIKEI_API_TOKEN; it also saves search, post, and comment results under the skill's logs directory. Use a dedicated token, avoid private or sensitive investigations, and delete or protect logs if retained results could reveal business research or personal data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/log.js:29
Finding

Automatic Plaintext Retention of User Queries and Retrieved Data

Content
View full analysis
Remediation
View remediation
` option before writing results. 2. **Apply restrictive permissions** - Create the output directory with mode `0700`. - Create result files with mode `0600`. - Reject output paths that resolve outside an approved directory. Example: ```js await fs.promises.mkdir(outputDirectory, { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, content, { mode: 0o600, flag: "wx", }); ``` 3. **Minimize retained information** - Do not place search keywords in filenames. - Use random identifiers or timestamps instead. - Allow users to store only results, excluding request metadata where unnecessary. - Add configurable field redaction. 4. **Introduce retention controls** - Support automatic deletion after a configurable period. - Provide a documented command to purge saved results. - Warn users when existing logs are detected. 5. **Prevent accidental distribution** - Add `logs/` to `.gitignore`. - Exclude generated records from release archives and package manifests. - Document backup and synchronization risks. 6. **Align all documentation** - Clearly state in `SKILL.md` that successful search, post, and comment operations may create local files. - Distinguish “no Douyin-side write operations” from local filesystem writes. - Explain the stored fields, location, retention behavior, and permission model. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (41)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音公开数据的只读分析/抓取工具,核心能力应涉及访问抖音相关数据源并返回结构化结果。但提供的代码仅为通用参数解析模块,负责处理命令行选项、必填校验、布尔参数、位置参数与帮助文本生成。这类代码可作为支持性基础设施存在,但当前代码片段本身没有体现任何与抖音搜索、评论、作品抓取、热榜监控或舆情分析相关的业务行为。由于实际行为与声明的主要用途明显不一致,应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音数据检索与抓取的只读分析工具,但实际代码片段只包含日志保存功能,使用 Node.js 的 fs/path 在本地磁盘写入文件。该行为与声明中的核心能力(搜索、抓取、热榜、评论分析、结构化 JSON 输出)无直接对应关系,而且资源访问类型也不一致:声明强调抖音公开数据只读,代码则进行了本地文件写入。虽然日志功能可能作为辅助实现存在,但就该代码片段本身而言,其实际行为与声明目的明显不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 77)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire README is written in Chinese and includes user-facing operational guidance, warnings, and support instructions, but it does not indicate that other languages are supported or that Chinese is a required locale for a region-specific compliance reason. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill claims to be a read-only JSON-output toolbox, but it also persists fetched comment data to a local file via log.taskWrite(). This creates undisclosed local data retention of potentially sensitive or regulated content, increasing privacy, compliance, and operational risk if the host environment assumes the tool is non-persistent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code writes full comment results to a local JSON file without an explicit user warning, consent, or configuration control. Because comments may contain personal data, usernames, or sensitive text, silent persistence can expose data to other local users, backups, or later unintended processing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI persists fetched Douyin results to a local JSON file even though the skill is described as a read-only data retrieval tool. This creates an undisclosed local data-retention path that can expose scraped content, account metadata, or potentially sensitive monitoring results to other local users, backup systems, or downstream tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI silently writes fetched results to a local JSON file without an explicit user-facing warning or consent flow. In the context of trend monitoring, competitor tracking, and comment scraping, those outputs may contain sensitive business intelligence or personal data, so undisclosed persistence increases confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest emphasizes read-only access to public Douyin data and structured JSON output for analytics tasks. However, this CLI additionally writes the full search output to a local file via log.taskWrite, which is a side effect beyond merely returning read-only query results.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is described as a read-only Douyin analytics toolbox, but this utility performs local file writes to a logs directory. Even though the filename is sanitized against simple traversal characters, persisting arbitrary string content to disk expands the skill's capabilities beyond its declared read-only scope and can enable unintended local data storage, including writing sensitive scraped data or untrusted content to the host filesystem.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file includes hard-coded Chinese error strings presented directly to users, such as the fallback message at L037. Per the policy, forcing a specific language without offering user choice or documenting a justified locale restriction is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The authentication failure message at L053 is explicitly shown in Chinese and does not provide any mechanism for language selection. This suggests the skill enforces a single language for user-visible output, which violates the language/locale policy unless clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains multiple user-facing error strings exclusively in Chinese, but there is no indication that the skill is region-specific or that users can opt into this locale. That creates a natural-language policy issue because the skill effectively forces a specific language without documented justification or user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON schema includes user-facing title and description fields only in Chinese, which can impose a language requirement on users without offering a locale choice. The policy allows language constraints when they are explicitly justified or optional, but no such justification or opt-in is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema includes title and description strings only in Chinese, which can violate a language/locale policy when the skill is not explicitly documented as Chinese-only or region-specific. Because the file provides no user opt-in or justification for the fixed locale, it may impose a language constraint on downstream users or tooling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language title and field descriptions are entirely in Chinese, which can impose a language constraint on users or downstream developers without any opt-in or documented locale limitation. The file does not state that it is intended only for a Chinese-language or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The human-facing title and description fields are written entirely in Chinese, including parameter descriptions, with no indication that the skill is China-specific or that users can choose another language. This can violate language/locale policy expectations when a skill is intended for a broader audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON schema is a manifest/config-type file, so only SQP-3 applies here. Multiple title and description fields are exclusively in Chinese, which can constitute a language/locale policy violation when the skill does not offer user opt-in or explain that it is intentionally limited to a Chinese-only context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This manifest file contains user-facing title and description fields entirely in Chinese, with no indication that the skill is region-specific or that users can choose another language. Under the policy rule for natural-language violations, forcing a specific language without documented justification or opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This JSON schema contains natural-language titles and descriptions exclusively in Chinese, which can amount to a language/locale policy issue when no user opt-in or justification is provided. The file does not indicate that the schema is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This manifest file describes the skill's capabilities in broad terms but provides no explicit activation conditions, trigger phrases, or exclusion boundaries. In a skill-discovery or auto-invocation context, such a general description could match common analysis requests too broadly and increase the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file is natural-language documentation, and all visible content is presented only in Chinese. Under the policy rule, forcing a specific language without user opt-in can be a locale/language policy violation when no alternative or choice is documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

该 markdown 文档从标题到参数说明、示例注释均仅使用中文表述,未见任何用户可选择其他语言的说明。根据语言/locale 策略,若技能以单一语言强制呈现而无用户选择或明确合理性说明,属于自然语言层面的策略风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The code uses toLocaleString() with no explicit locale selection, which makes output depend on the runtime environment's default language/region settings. This can violate language/locale policy expectations because the skill does not offer user opt-in or document a justified locale constraint.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16