Back to skill

Security audit

抖音趋势洞察

Security checks for vulnerabilities and agentic risk

Overview

This Douyin data skill is coherent, but it needs review because it sends its API token in URL query strings and automatically saves collected video/comment data locally.

Review before installing. Use this only if you trust the publisher and guaikei.com with your token, search terms, profile/video links, and returned public datasets. Use a revocable token with limited quota, avoid collecting sensitive or regulated data at scale, and periodically delete the generated logs directory. Prefer official support channels over the personal contact listed in the skill text.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:103
Finding

API Token Exposed in URL Query Strings

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (43)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the actual code mainly performs token checks and marketing prompts rather than the advertised analytics functions, the skill can still mislead users into disclosing secrets or accepting unnecessary third-party onboarding flows. In this context, the mismatch lowers trustworthiness and increases the chance of social-engineering-style misuse, even if the direct technical impact is less severe than arbitrary code execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the actual code mainly performs token checks and marketing prompts rather than the advertised analytics functions, the skill can still mislead users into disclosing secrets or accepting unnecessary third-party onboarding flows. In this context, the mismatch lowers trustworthiness and increases the chance of social-engineering-style misuse, even if the direct technical impact is less severe than arbitrary code execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the actual code mainly performs token checks and marketing prompts rather than the advertised analytics functions, the skill can still mislead users into disclosing secrets or accepting unnecessary third-party onboarding flows. In this context, the mismatch lowers trustworthiness and increases the chance of social-engineering-style misuse, even if the direct technical impact is less severe than arbitrary code execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the actual code mainly performs token checks and marketing prompts rather than the advertised analytics functions, the skill can still mislead users into disclosing secrets or accepting unnecessary third-party onboarding flows. In this context, the mismatch lowers trustworthiness and increases the chance of social-engineering-style misuse, even if the direct technical impact is less severe than arbitrary code execution.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 72)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The primary activation description, usage guidance, and trigger phrases are written as Chinese-only instructions, with no statement that users may interact in other languages or choose their preferred locale. This creates a natural-language locale constraint that is not explicitly justified as region-specific policy and could conflict with organizational language-choice requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest-style JSON uses Chinese-only natural-language strings for the title and parameter descriptions, which can impose a language/locale constraint on users without any opt-in or documented regional limitation. Under the policy, locale-specific language is a violation unless the skill offers language choice or clearly justifies the restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README explicitly promotes bulk collection of public videos, author data, comments, and hot-list data, plus automatic export to JSON logs, but provides only minimal usage restrictions and no meaningful privacy, retention, consent, or downstream-handling guidance. Even when data is public, large-scale aggregation and local logging of comments and author identifiers can create privacy, compliance, and misuse risks such as profiling, unauthorized redistribution, or accidental exposure of scraped datasets.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

该 markdown 文件全文以中文编写,且未说明这是面向特定中文用户群体的区域性技能,也未提供其他语言选项或用户选择机制。按规则,未经过用户选择而隐含强制特定语言/locale 的自然语言内容可构成语言策略违规。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes the full comment-analysis output to a local JSON file, including user-requested content and metadata, even though the skill is presented as a query/analytics tool. Persisting scraped comments creates unnecessary data retention, increases the chance of leaking collected content to other local users/processes, and expands the skill's behavior beyond what a user would reasonably expect from a read-oriented command.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language strings throughout the file, including status and error messages, are presented only in Chinese. Under SQP-3, forcing a specific language without user opt-in or documented justification is a policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI persists the full fetched post results to a local JSON file via log.taskWrite(...) after completing a data-retrieval task, but the skill description only presents retrieval/analysis behavior and this file provides no notice or opt-in for local retention. This creates an unnecessary data-retention surface: scraped public content, metadata, and query targets can remain on disk, be accessed by other local users/processes, or be unintentionally exfiltrated through backups and logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code silently writes fetched Douyin results to a local JSON file without any user warning, confirmation, or visible contract in the command interface. Even if the source data is public, silent persistence can violate user expectations, expand privacy/compliance risk, and expose research targets, collected content, and interaction data to anyone with filesystem or backup access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code emits user-facing status and error messages exclusively in Chinese, such as validation errors and save confirmations. This creates a natural-language locale constraint without offering a language choice or documenting that the skill is intended only for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple error strings in this file are hard-coded in Chinese, including authentication, parsing, timeout, and network errors. This imposes a specific language on users without any opt-in or locale selection, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The authentication error path embeds a personal contact number in a user-facing exception message that is unrelated to the runtime authentication mechanism. This unnecessarily discloses personal contact information, creates a social-engineering/support-impersonation risk, and is especially suspicious in a data-collection skill because it directs users to an off-platform individual rather than a documented support channel.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code formats all user-facing output in Chinese string literals, including headings and labels, with no indication that the skill is China-specific or that users can opt into another language. That creates a natural-language policy concern if the organization requires not forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains user-facing documentation and error/output strings entirely in Chinese, such as the validation messages and formatted result labels. Under the policy rule for language or locale constraints, this is a natural-language policy concern because the skill appears to require a specific language without any opt-in or alternative locale support.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest-style JSON file contains user-facing natural-language strings exclusively in Chinese, including the title and parameter descriptions. Under the policy rule for language/locale violations, this can be considered a forced language choice because the file provides no opt-in, alternative locale, or justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The schema title and description are written only in Chinese, which imposes a specific language/locale in the skill's natural-language interface metadata. In this file there is no indication that the skill is region-specific or that users can opt into this locale, so it may conflict with an organizational language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON schema embeds user-facing natural-language strings entirely in Chinese, which can impose a fixed language/locale on downstream consumers. The file does not indicate that the skill is China-specific or that users can opt into this locale, so it may violate language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON schema contains human-readable title and description fields entirely in Chinese, including field descriptions throughout the file. For a general-purpose skill artifact, this can constitute a language/locale policy issue because it fixes one language without documenting opt-in, alternatives, or a region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The title and property descriptions are written entirely in Chinese, which can constitute a language/locale policy issue when the skill does not offer language choice or explain that it is intentionally China/Chinese-specific. In this schema, there is no natural-language indication that the locale restriction is optional or justified for a region-specific deployment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This JSON schema contains user-facing natural-language titles and descriptions exclusively in Chinese, such as the schema title and per-field descriptions. Because the file does not document that the skill is China-specific or offer any language/locale choice, it may violate a language/locale policy that requires opt-in or justified locale constraints.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:24