Back to skill

Security audit

抖音热门视频检索

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Douyin public-data lookup tool that uses a third-party API and local result logs, with no evidence of hidden execution, account access, or destructive behavior.

Install only if you are comfortable using a GUAIKEI API token and sending Douyin keywords or links to www.guaikei.com. Treat returned comments and creator metrics as public personal/content data: keep local logs only as long as needed, avoid sharing them broadly, and comply with Douyin terms and applicable privacy rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (36)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill makes broad claims about real-time Douyin search, hotlist, post scraping, and comment analysis, but the reported implementation only contains partial validation logic and lacks the promised core capabilities. Such overclaiming is security-relevant because it can conceal what the code actually does, induce users to provide external tokens and data under false assumptions, and impair risk assessment by reviewers and agents.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill makes broad claims about real-time Douyin search, hotlist, post scraping, and comment analysis, but the reported implementation only contains partial validation logic and lacks the promised core capabilities. Such overclaiming is security-relevant because it can conceal what the code actually does, induce users to provide external tokens and data under false assumptions, and impair risk assessment by reviewers and agents.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill makes broad claims about real-time Douyin search, hotlist, post scraping, and comment analysis, but the reported implementation only contains partial validation logic and lacks the promised core capabilities. Such overclaiming is security-relevant because it can conceal what the code actually does, induce users to provide external tokens and data under false assumptions, and impair risk assessment by reviewers and agents.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill makes broad claims about real-time Douyin search, hotlist, post scraping, and comment analysis, but the reported implementation only contains partial validation logic and lacks the promised core capabilities. Such overclaiming is security-relevant because it can conceal what the code actually does, induce users to provide external tokens and data under false assumptions, and impair risk assessment by reviewers and agents.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 76)May include surrounding context.

md
## 1.0.2 - 2026-03-24

- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

Manifest 当前将技能范围限定为四类:关键词搜索、热榜、博主作品抓取和视频评论分析。更新日志在 L90-L91 声称技能提供“用户及社交数据搜索”,且返回“分享数”等社交数据,这比当前描述更宽,显示文档化的实际能力边界与 manifest 存在不一致。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation explicitly supports collecting creator profile data, public works lists, and comment content/interaction data, but provides no warning about privacy, consent expectations, retention, or lawful use. In a data-collection skill focused on scraping/searching Douyin content, this omission increases the risk of misuse, overcollection, and non-compliant handling of personal data even if the data is publicly accessible.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file's user-facing natural-language content, including the module description and JSDoc comments, is entirely in Chinese with no indication of language choice or opt-in. This can violate a language/locale policy when skills are expected to support user-selected language rather than unilaterally enforcing one.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JavaScript file contains natural-language comments and parameter documentation entirely in Chinese, including the module description and API function docs. Under the stated policy, forcing a specific language without user opt-in or a clearly documented regional justification is a locale/language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The CLI writes fetched comment data to a local JSON file automatically, but this file contains user/content data and may persist sensitive or regulated information longer than the operator expects. In shared environments, CI runners, or multi-user systems, silent local persistence increases the risk of unintended disclosure through filesystem access, backups, logs, or later exfiltration.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes the fetched Douyin results to a local JSON file without any user opt-in, retention control, or disclosure in the stated skill behavior. Because the returned data can include creator profile details and comment/interaction-derived content, this creates an unnecessary local data-retention surface that can expose sensitive or regulated data to other local users, backups, or downstream processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI writes the full search output to a local JSON file whose name includes the user's keyword, without any explicit consent, warning, or retention control. In this skill's context, results may contain sensitive research topics, operational interests, or scraped public content metadata, so silent persistence can expose user activity to other local users, backups, or later compromise of the host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple error and status strings in this file are hardcoded in Chinese, including API failures, validation errors, timeout/network messages, and retry logs. This forces a specific language for user-visible output without opt-in or documented locale constraints, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This JavaScript file contains multiple user-facing error strings in Chinese, such as the messages printed during keyword validation and option validation. Because the skill forces a specific language in its natural-language output without any visible user opt-in or justification that it is China/Chinese-specific, it matches the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This manifest-like JSON file describes the skill as '抖音评论获取' and '命令行参数入参Schema详解' but provides no explicit activation constraints, allowed invocation phrases, or negative examples. For manifest/config-style files, this can be considered an ambiguous trigger description because it does not clarify when the skill should or should not be used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The title and description are presented only in Chinese, which may impose a language choice on users without indicating any opt-in or alternative locale support. The policy calls for flagging language or locale restrictions unless the file offers a choice or documents a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON schema contains human-readable title and description fields exclusively in Chinese, which imposes a specific language on users and integrators. Under the policy, language-specific behavior should either be optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON schema contains user-facing title and description strings entirely in Chinese, including the field descriptions. Because the file does not offer any locale choice or indicate that the skill is intentionally region-specific, it may violate the language/locale policy requiring user opt-in or clear justification for a forced language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON schema contains human-readable title and description text exclusively in Chinese, which can constitute a language/locale policy issue when no opt-in or region-specific justification is provided. Because the file gives no indication that the skill is intended only for Chinese-speaking users or a China-specific deployment, it may force a locale implicitly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title and descriptions are entirely in Chinese, which imposes a specific language in user-facing schema metadata. The file does not indicate that the skill is region-specific or that users can opt into this locale, so it may violate the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON schema contains natural-language titles and descriptions exclusively in Chinese, such as the title and multiple property descriptions. Per the language/locale policy, forcing a specific language without offering user choice or documenting a justified locale restriction can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description is entirely in Chinese and describes the skill as a Douyin video search tool without any indication that users can choose another language or locale. Under the policy rule, natural-language metadata that implicitly constrains language without opt-in can be a locale/language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file title and all changelog content are presented only in Chinese, which can indicate a language-specific constraint for the skill documentation. There is no visible opt-in, alternative locale, or justification that the skill is intended exclusively for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

A language/locale policy issue applies across all file types when a skill effectively forces a single language without user opt-in or justification. This file presents all instructions and option descriptions only in Chinese, with no indication that the skill is China-specific or that another language option exists.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16