Back to skill

Security audit

抖音运营助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Douyin public-data retrieval tool, with the main caveat that some results are automatically saved locally as logs.

Install only if you are comfortable sending Douyin keywords or links to www.guaikei.com and storing fetched results locally under the skill's logs directory. Keep GUAIKEI_API_TOKEN private, avoid sensitive monitoring queries on shared machines, and use the skill only for public Douyin data and internal analysis.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (40)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation truly performs local filesystem writes, directory creation, and content saving while the skill markets itself as a read-only external data tool, that undisclosed side effect creates avoidable risk. Hidden local writes can store sensitive query data, create persistence artifacts, or be abused for unexpected disk usage and privacy violations, especially because the skill handles user-supplied keywords and links sent to a third-party API.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation truly performs local filesystem writes, directory creation, and content saving while the skill markets itself as a read-only external data tool, that undisclosed side effect creates avoidable risk. Hidden local writes can store sensitive query data, create persistence artifacts, or be abused for unexpected disk usage and privacy violations, especially because the skill handles user-supplied keywords and links sent to a third-party API.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation truly performs local filesystem writes, directory creation, and content saving while the skill markets itself as a read-only external data tool, that undisclosed side effect creates avoidable risk. Hidden local writes can store sensitive query data, create persistence artifacts, or be abused for unexpected disk usage and privacy violations, especially because the skill handles user-supplied keywords and links sent to a third-party API.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation truly performs local filesystem writes, directory creation, and content saving while the skill markets itself as a read-only external data tool, that undisclosed side effect creates avoidable risk. Hidden local writes can store sensitive query data, create persistence artifacts, or be abused for unexpected disk usage and privacy violations, especially because the skill handles user-supplied keywords and links sent to a third-party API.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 77)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list includes broad phrases such as data analysis, trend tracking, and monitoring terms that can match many ordinary user requests. Over-broad routing can cause the agent to invoke this skill unexpectedly, sending user keywords or links to the third-party domain www.guaikei.com without sufficiently specific user intent, increasing privacy and data-minimization risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The package description forces a single language/locale in the skill metadata, with no indication that users may opt into Chinese or that the skill is intended only for a Chinese-speaking audience. Under the policy, a language-specific constraint should either offer user choice or be explicitly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file uses Chinese throughout, including the title and all release notes, with no indication that the skill is region-specific or that users may choose another language. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The CLI silently persists fetched comment results to a local JSON file after already printing them to stdout, which creates an undisclosed secondary data sink. Comment data can contain personal data, usernames, or sensitive content, and writing it to disk increases retention, local exposure, and the chance of later unintended access or exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code writes fetched Douyin comment data to a local file without user-facing warning, consent, or control. Because comments may include personal or sensitive information, undisclosed local storage expands the privacy and compliance risk beyond the stated behavior of returning structured JSON.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code contains multiple user-facing strings in Chinese, including errors and success messages, and provides no opt-in or fallback for other languages. That creates a natural-language policy concern because the skill effectively forces a specific language for all users without documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command descriptions, help text examples, and runtime status/error messages are presented in Chinese throughout the file. This forces a specific language experience without offering users a locale choice or documenting that the skill is intentionally Chinese-only.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI writes the full fetched Douyin results to a local JSON file after completing the request. Because the tool handles scraped profile and post data and does not clearly disclose local persistence, this creates an unexpected data-retention channel that can expose collected data to other local users, backup systems, or later unintended processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The program silently saves scraped results to disk without a user-facing warning or consent mechanism. For a data-collection tool, undisclosed persistence increases privacy and compliance risk because operators may believe output is only emitted to stdout while a second copy is retained locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI persists full search output and request metadata to a local JSON file, including the raw keyword and returned Douyin data, without any explicit consent, retention control, or masking. In this skill’s context, queries may reflect monitoring targets, competitor research, or potentially sensitive comment/author data, so silent disk persistence creates a meaningful privacy and data exposure risk on shared hosts or developer machines.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON schema contains user-facing title and description text exclusively in Chinese, which can impose a language-specific experience without any opt-in or documented locale limitation. Under the policy, language constraints should either offer user choice or clearly justify the locale-specific scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The schema title and description are written only in Chinese, which can amount to a language/locale policy issue when no opt-in, alternative locale, or region-specific justification is provided. Because this is natural-language metadata that constrains how the skill is presented, it may exclude users expecting a different language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The title and description fields use Chinese-language natural text, but the file does not indicate that the schema is intended only for Chinese-speaking users or offer any language/locale choice. Under the policy rule for natural-language constraints, this can be interpreted as forcing a specific language without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON schema contains user-facing title and description strings entirely in Chinese, including parameter descriptions, with no indication that the skill is region-specific or that another language is available. That creates a natural-language locale policy concern because the skill appears to impose a specific language on users without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This JSON schema uses Chinese-only natural-language title and description fields, which can constitute a locale policy violation when no user opt-in or region-specific justification is provided. The file does not indicate that the schema is intentionally limited to Chinese-speaking users or a China-specific deployment context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This manifest-style JSON schema uses Chinese-only natural-language title and description fields for the skill and its parameters. Because the file provides no indication that the language is optional, localized, or region-specific, it can conflict with a policy requiring language choice or explicit locale justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This JSON schema uses Chinese-only natural-language title and description fields throughout, which can constitute a language/locale policy issue when no opt-in, alternative locale, or justification is provided. Because these user-facing strings define how the skill's data is presented, the file effectively hard-codes a single language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

该文件标题及全文说明均仅以中文提供,没有说明这是面向特定中文用户群体的区域性技能,也未提供其他语言或语言选择。按规则,强制单一语言且无用户选择或明确合理约束,属于自然语言层面的语言/地区策略问题。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This code sends a user-provided video URL and an authentication token to an external API via requestApi, but there is no confirmation prompt, user-facing log, or comment disclosing that data transmission. Because network transmission of user or system data is a safety-relevant operation for code files, the lack of visible disclosure is a quality concern.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16