Back to skill

Security audit

快手作品批量下载

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Kuaishou public-data retrieval tool, with disclosed network use, token use, and local result logging.

Install only if you are comfortable sending Kuaishou queries, URLs or IDs, request limits, and your GUAIKEI_API_TOKEN to guaikei.com. Treat saved logs as collected public content data that may include comments, author metadata, and source links; store or delete them according to your privacy and platform-compliance obligations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

If the actual implementation is only generic argument parsing or a narrower URL-based workflow, the current description creates a trust gap between declared and real behavior. That can lead to unsafe automation decisions, incorrect user expectations, and reduced ability to detect unauthorized capability expansion later.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the actual implementation is only generic argument parsing or a narrower URL-based workflow, the current description creates a trust gap between declared and real behavior. That can lead to unsafe automation decisions, incorrect user expectations, and reduced ability to detect unauthorized capability expansion later.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the actual implementation is only generic argument parsing or a narrower URL-based workflow, the current description creates a trust gap between declared and real behavior. That can lead to unsafe automation decisions, incorrect user expectations, and reduced ability to detect unauthorized capability expansion later.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the actual implementation is only generic argument parsing or a narrower URL-based workflow, the current description creates a trust gap between declared and real behavior. That can lead to unsafe automation decisions, incorrect user expectations, and reduced ability to detect unauthorized capability expansion later.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation promotes bulk searching, downloading, and comment collection from Kuaishou without any warning about privacy, consent, retention, or platform terms-of-service implications. In the context of a downloader/scraper skill, this omission increases the likelihood of misuse for large-scale content harvesting or collection of user-generated data without appropriate safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script persists the full output, including request metadata and fetched comments, via log.taskWrite(...). While it logs progress messages, there is no user-facing disclosure in this file that execution will create a local file containing the retrieved data, which is a safety-relevant side effect beyond simply printing results.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Lines L183-L186 persist the full command output, including request metadata and fetched results, to disk via log.taskWrite. Although the script prints status messages for task progress, there is no user-facing disclosure here that execution will create a local file containing the retrieved data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code presents command descriptions, help text, and notices entirely in Chinese, which imposes a specific language on users. The file does not provide any opt-in, locale selection, or justification that the skill is intentionally restricted to a Chinese-language audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript utility uses Chinese-only natural-language strings in comments, help text, warnings, and thrown error messages, such as the title comment at L002 and user-facing help/output at L128-L135. The file does not offer a language choice or document that it is intentionally restricted to a Chinese-speaking context, which violates the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code contains natural-language strings such as "日志文件名必须是非空字符串" and "日志内容必须是非空字符串" that force Chinese output for all users. The policy requires either user opt-in for a specific language/locale or clear documentation that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The success and failure messages shown to users are fixed in Chinese (for example, "已保存到" and "日志写入失败"). This is a language-policy issue because the skill does not offer a language choice or state that it is a justified locale-specific tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Multiple error messages are hard-coded in Chinese, including parsing, timeout, authentication, and validation failures. This imposes a specific language on users without any visible locale selection, opt-in, or documented region-specific justification in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code performs outbound HTTPS GET and POST requests, serializes request data, and sends a TOKEN header, but there is no confirmation prompt, visible logging, or explanatory comment/docstring warning that user or system data may be transmitted externally. Because this is a code file, network calls that transmit data or credentials should include some form of disclosure unless clearly documented elsewhere in the skill description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation mentions logs and local downloading but does not clearly foreground the fact that media files and logs may be stored on disk, potentially containing user queries, URLs, or retrieved content. This is a transparency and data-handling issue that can affect privacy, storage consumption, and compliance expectations, especially in shared or managed environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy issues. This README presents the skill entirely in Chinese without offering an alternative language or user opt-in, which can amount to forcing a specific language absent documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file applies to SQP-2, and it explicitly states that all task results are automatically saved to the logs/ directory. Because the skill processes video, author, and comment data, the README should warn users that local files containing collected data and source links will be created and may need handling or cleanup.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The title uses Chinese and the file contains no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy rule for language/locale constraints, forcing a single language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The natural-language content in this file appears to assume a single language/locale without offering alternatives or stating that the skill is region- or language-specific. The policy requires flagging language or locale constraints when they are forced without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file presents argument descriptions, examples, and runtime messages only in Chinese, which forces a specific language for users regardless of preference. The policy allows locale constraints only when justified or when the user is given a choice, neither of which is evident in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The thrown error string is hard-coded in Chinese (重试${maxAttempts}次后失败). This imposes a specific language on users without any indication of locale selection, opt-in, or documented region-specific scope, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This file uses Chinese for comments and user-visible warning/info messages such as "警告: 你的 GUAIKEI_API_TOKEN 未正确配置" and "已使用配置的私有TOKEN". The stated policy flags language/locale constraints when a skill forces a specific language without user opt-in, and no alternative language handling or locale justification is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The banner string is hard-coded in Chinese ("快手运营全链路数据工具"), which indicates a fixed language choice in user-facing output. The file provides no indication that users can select a different language or that this locale restriction is documented as intentional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits all user-visible error messages in Chinese, which enforces a specific language for users regardless of their locale or preferences. The policy explicitly calls out forced language or locale behavior as a natural-language violation when no user choice or documented justification is present.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.