Back to skill

Security audit

抖音高赞视频检索

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Douyin public-data lookup tool, with disclosed third-party API use and local result logs that users should be aware of.

Install only if you are comfortable sending Douyin search terms or links and your GUAIKEI_API_TOKEN to www.guaikei.com. Review or delete the generated logs if the queries, comments, or account research are sensitive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (42)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个包含四大能力的综合工具,但当前代码片段实际只覆盖其中的“博主作品抓取”这一项,且还是通过 CLI 调用 post 接口获取作品列表。代码没有显示任何关键词检索、高赞视频/图文搜索、热榜查询或评论抓取/分析相关逻辑,因此从“声明的整体功能范围”与“实际实现的能力”来看存在明显不一致。虽然已实现的博主作品抓取能力与声明中的第(3)项一致,但声明将技能定位为支持四大能力的完整工具,而此代码仅呈现单一子功能,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码仅包含 src/utils/args.js 中的通用参数处理函数:readValueAfterFlag、parseArgs、buildHelp。这些函数只处理命令行输入校验、flag/alias 映射、布尔值与字符串参数解析、重复参数检查、帮助文本生成等基础设施功能。没有看到任何与抖音平台交互、网络请求、视频/图文检索、热榜读取、用户主页解析、评论抓取或互动数据分析相关的实现。根据评估标准,虽然参数解析可作为支持性实现细节,但当前提供的代码块本身的实际行为与声明的主要用途明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音内容检索与分析的技能,但给出的代码片段只是一个读取本地 package.json 中技能名称的辅助函数。其主要行为是使用 fs/path 访问本地文件系统并返回 name 字段,属于元数据读取的内部实现细节,和声明的四项核心功能没有直接对应关系。就当前代码片段而言,实际行为与声明用途存在明显偏离,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The supplied code is a narrow validation helper module, not a full implementation of the declared multifunction Douyin search/analysis tool. It contains: (1) regex-based extraction of Douyin URLs, (2) acceptance of profile/share URLs or sec_uid-like strings for user identification, and (3) limit-range formatting. This aligns only indirectly with one declared capability (creator works lookup) as supporting input handling. It does not perform searches, fetch trending data, retrieve works, or analyze comments. Because the declared description presents a broad tool with four concrete runtime capabilities, while this code chunk only provides limited input validation utilities, the description does not accurately represent what this chunk actually does.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 76)May include surrounding context.

md
## 1.0.2 - 2026-03-24

- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON schema uses Chinese-only natural-language metadata for the title and description, and the field descriptions throughout the file are likewise Chinese-only. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This markdown file presents all user-facing instructions, warnings, and usage guidance only in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The function sends a token plus the provided Douyin profile URL to an external API via requestApi, which is a data-transmitting operation. While the docstring describes parameters, it does not disclose to the user that their input and token will be sent over the network, and there is no confirmation prompt or user-facing notice in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This function performs a GET request that includes the user's URL and limit along with the token, which can affect privacy and involves external data transmission. The code lacks any visible confirmation, print/log notice, or explicit user warning about this network operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code sends the user's search keyword and a token to an external API via requestApi, which is a data-transmitting network operation. In this file there is no confirmation prompt, user-facing log, or warning comment/docstring disclosing that user input and credentials are sent over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The GET request includes the user's search parameters and token, which is a safety-relevant network transmission of user and credential data. This file contains no visible confirmation prompt, user-facing logging, or warning text explaining that the query details and token are sent externally.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes fetched comment data to a local JSON file after printing results, creating undeclared local persistence of potentially sensitive or regulated user-generated content. In this skill context, comment retrieval is expected, but silent storage is riskier because operators may assume transient processing only while the tool leaves a recoverable artifact on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The tool saves fetched comments to a local JSON file without any user-facing warning or consent in this file, which can surprise users and create unintended retention of scraped social-media content. In a comment-analysis skill this is somewhat contextually related, but the lack of notice and opt-in increases privacy, compliance, and data-handling risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Multiple user-visible strings in this file, including errors and success messages, are written only in Chinese, which imposes a specific language on all users. There is no indication of user opt-in, locale detection, or documented region-specific scope in this file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI persists fetched Douyin results to a local file after completing what is presented as a query/search operation, without an explicit opt-in or prominent disclosure. This creates an unexpected data-at-rest side effect: searched profile data and metadata remain on disk, which can expose user activity or scraped content to other local users, backups, or later processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The tool silently writes the full JSON response to a local file without user-facing warning beyond the source code, violating least surprise for a search utility. In this skill context, the output may include public profile/work data and operational metadata, and silent storage increases privacy and compliance risk because data is retained even when the user only intended a transient query.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The option descriptions, examples, and notices shown to users are all presented only in Chinese. This creates a language policy issue because the skill does not offer a language choice, fallback, or documented locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI writes both request parameters and full search results to a local file, which creates a privacy and data-retention risk. Search keywords may contain sensitive research topics, user interests, or internal investigation terms, and storing them by default without clear notice, consent, redaction, or retention controls can expose that data to other local users, backups, or log collection systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The user-facing messages at L25 and L29 are hard-coded in Chinese, which can violate a language or locale policy when no user language selection or opt-in is provided. This is a natural-language policy issue because the file enforces a specific language in its visible output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains multiple user-visible error messages in Chinese, which forces a specific language for users interacting with the skill. Under the policy, language-specific behavior should offer user opt-in or be clearly justified as locale-specific, neither of which is present in this file.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This manifest-style JSON file describes the skill only as fetching Douyin comments, but it does not define any explicit trigger phrases, scope boundaries, or exclusion conditions. In manifest files, missing specificity about invocation conditions can lead to ambiguous or overly broad activation by an agent orchestrator.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The title and description fields force a specific language in the natural-language metadata. Because this file does not indicate that the schema is intentionally region-specific or provide any user opt-in for language/locale, it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The schema title and description are written only in Chinese, which creates a language-specific constraint in natural-language metadata without indicating user opt-in or a region-specific requirement. Under the policy, forcing a specific language without choice or justification can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The title and property descriptions use Chinese exclusively, which can amount to a language policy issue if the skill environment expects language choice rather than a forced locale. The file does not document that the skill is intended only for Chinese-speaking users or offer any opt-in or alternative language.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16