Back to skill

Security audit

快手数据助手

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a disclosed Kuaishou public-data CLI integration, but users should know it sends queries and links to a third-party API and saves results locally.

Install only if you are comfortable using the GuaiKei third-party API for Kuaishou research. Treat GUAIKEI_API_TOKEN as a secret, use the skill only for public Kuaishou data, and periodically review or delete the generated logs if saved comments, profile URLs, keywords, or video metadata should not remain on disk.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill provides Kuaishou/Kwai social-media data assistant capabilities. However, the actual code is only a reusable utility for parsing CLI arguments and generating help text. This is a supporting utility module and does not itself perform any of the declared product behavior such as fetching rankings, analyzing content, inspecting comments, or retrieving creator/work data. Because the supplied code chunk’s behavior is materially unrelated to the declared end-user purpose, this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises Kuaishou/Kwai analytics and research capabilities, but the supplied code chunk does not implement any such behavior. It simply reads package.json from the local filesystem and returns the package name. This is a materially different primary purpose from the declared description. While this could be a small supporting utility within a larger skill, based on this code chunk alone the actual behavior shown is unrelated to the declared end-user functionality, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and one-line value proposition claim support for features such as '快手热榜', '作品详情', '评论回复分析', and general '达人数据', but the later capability boundary explicitly limits the skill to only three functions: keyword search, creator post listing, and video comment retrieval. This is a semantic mismatch between the advertised behavior and the documented/implemented routing scope, which could cause an agent to invoke the skill for unsupported tasks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not clearly warn users that collected public video/comment data and analyzed outputs will be persisted to local storage. In a data-scraping and comment-analysis tool, silent retention increases the risk of unintended storage, sharing, or later exfiltration of potentially sensitive research datasets, especially on shared workstations or CI/server environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation is written entirely in Chinese, including headings, parameter descriptions, and examples, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or China-specific audience. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The code reads GUAIKEI_API_TOKEN from the environment and sends the normalized URL and limit to remote API functions to create and retrieve a comment task. Although network access is part of the apparent purpose, this file itself lacks a clear user-facing warning or comment that the input URL and authentication token will be used in external API requests.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes Kuaishou data assistance and comment analysis/research capabilities, which implies fetching and analyzing platform data. This file not only retrieves comment data but also writes the full JSON result to a local file via log.taskWrite, introducing local persistence behavior not evident from the skill description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script silently persists fetched comment data to a local file, which may include user-generated content or sensitive research data. Because this happens automatically and without explicit user consent or path control, it can create unintended data retention, privacy, and workspace exposure risks, especially on shared systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script persists the full output payload to disk via log.taskWrite, which includes request metadata and retrieved results. While the script logs network progress, there is no visible disclosure near the write operation, confirmation prompt, or comment/docstring warning that execution will create a local file artifact.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JavaScript file contains natural-language comments, thrown error messages, and help output entirely in Chinese, such as the module description, parameter errors, and help text. Under the policy rule for language/locale constraints, this is a violation because the skill enforces a specific language without user opt-in or any documented justification for being Chinese-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains multiple user-visible error strings in Chinese, such as the messages printed on validation failures. Because the skill forces a specific language in its natural-language output without any visible opt-in or documented locale constraint in this file, it matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The visible skill name, value proposition, and usage guidance are primarily written in Chinese, with no statement that users may interact in another language or choose their preferred locale. Under the policy, language or locale constraints should be opt-in or explicitly justified; this file does not provide that choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The package description is written primarily in Chinese and presents the skill's behavior and scope only in that language, with only limited English terms mixed in. For a general-purpose package manifest, this can amount to a language policy issue because it does not clearly offer users a language/locale choice or document a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The changelog content is presented in Chinese, and there is no indication that users can choose another language or that the locale restriction is intentional and documented. Under the policy criteria, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The retry/error message string is hard-coded in Chinese, which indicates the skill may enforce a specific language in its user-facing output. Under the policy, language constraints should be optional, user-selectable, or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The thrown error and retry log messages are written in Chinese with no evidence of localization or user choice. This can violate language/locale policy when the skill does not explicitly offer opt-in or document a justified region-specific restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This code sends the user-provided keyword, filters, and token to remote API endpoints via postJson, but the function contains no comment, docstring, or user-visible notice explaining that data is transmitted off-box. For code files, outbound network operations that transmit user or system data should have some form of disclosure unless clearly covered elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The getSearchTask function performs a network call with keyword, sort, time, duration, limit, and token, yet there is no inline warning, docstring, or other visible disclosure in the file. Under the code-file criteria, network transmission of user or system data should not be silent unless the warning is clearly documented elsewhere.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest presents the skill as a Kuaishou/Kwai research assistant, but does not mention dependency on environment-hosted credentials. Accessing process.env for GUAIKEI_API_TOKEN is an additional capability involving host environment data, which is not directly disclosed by the stated purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits user-facing status and error messages only in Chinese, such as the validation errors at L07 and L11. The file provides no language selection, opt-in, or justification for a Chinese-only locale, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple error strings are hardcoded in Chinese, including token and network failure messages, with no indication that users can opt into another language. This creates a natural-language policy concern because the skill appears to enforce a specific language/locale without user choice or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code performs outbound HTTPS GET and POST requests and includes a TOKEN header plus query/body data, but the file contains no comments, docstrings, prompts, or user-facing notices disclosing that user or system data may be sent to a remote service. For code files, network transmission without any visible disclosure can warrant a missing-warning finding when the warning is absent from the file itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The thrown error string is written only in Chinese (重试${maxAttempts}次后失败). This creates a language/locale policy issue because the skill emits user-visible natural language in a fixed language without offering a choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code contains natural-language strings shown to users entirely in Chinese, including a warning and an informational message. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation unless the skill clearly documents that it is region- or language-specific.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:15