Back to skill

Security audit

快手评论分析与用户洞察

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it retrieves public Kuaishou search, creator-post, and comment data through a disclosed third-party API, with local result logging to consider.

Before installing, confirm you are comfortable sending Kuaishou keywords, profile/video URLs, and your GUAIKEI_API_TOKEN to guaikei.com. Also remember that fetched public comments, creator data, and search results are saved locally under logs, so clean that directory if the research targets or results are sensitive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (34)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents three concrete capabilities centered on search, creator works collection, and comment analysis. This code chunk does something narrower and different: it submits a KuaiShou post URL task and later queries task info/results, validating only that returned data is an object. There is no logic for keyword searching, profile-based work listing, or comment extraction/analysis in the supplied code. Because the actual behavior centers on post URL task management rather than the declared capabilities, this is a material description-behavior mismatch for this chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

这段代码仅是一个通用工具模块(args.js),负责读取命令行参数、识别选项、报错、生成 help 文本等。它没有访问快手、没有网络请求、没有处理视频/评论数据、没有分析用户问题或情绪证据。因此,代码实际行为与声明的技能核心功能明显不一致。虽然该模块可能作为整个项目的辅助组件存在,但就所提供代码块本身而言,其实际用途是 CLI 参数处理,而非声明中的快手评论洞察与抓取分析能力。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

该代码片段只是一个通用工具模块,负责打印横幅和格式化日志输出,不包含任何与快手视频搜索、主页作品抓取、评论获取、互动数据分析、用户问题归纳或情绪证据提取相关的逻辑。虽然横幅文案提到“快手运营全链路数据工具”,但这只是界面/日志文本,不能证明实现了声明中的核心能力。因此,代码实际行为与声明用途存在明显不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown skill file presents all operational instructions, warnings, and usage guidance solely in Chinese. That imposes a specific language requirement on users and downstream agents without any stated opt-in, alternative locale, or justification for a language-only policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description and keywords are entirely in Chinese, indicating the skill is presented in a single language with no visible opt-in, alternative locale, or justification that it is region-specific. This can violate language/locale policy when users are not given a choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest limits the skill to three capabilities: keyword video search, creator post retrieval, and video comment analysis for consumer insights. However, the README claims broader purposes such as '竞品监控', '趋势预测', and 'KOL 筛选', which materially expand the skill’s stated behavior into competitive intelligence and forecasting rather than only comment/consumer-insight workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Automatic saving of task results to logs/ without a warning means scraped public data, comment content, interaction metrics, and user-provided targets may be retained by default. Even if the source is public, retained local copies can expose research intent, target lists, or collected datasets to other local users, backups, or later unintended processing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes fetched comment results to a local JSON file after completing the task, which creates a new data-retention surface beyond simple retrieval/display. Because comment content can contain personal data, sensitive opinions, or account-linked context, undisclosed persistence increases the risk of unintended disclosure on shared systems or through later exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script stores comment data to a local JSON file without clear user-facing disclosure in the normal execution path. Silent persistence is risky because users may assume the tool only fetches/analyzes comments transiently, while the saved file can expose collected data to other local users, backups, or later compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The script reads an API token from the environment and sends requests through createPostTask and getPostTask, transmitting user-supplied URL data to an external service. Although the script logs progress, it does not clearly disclose that external API calls using the provided identifier/URL and token-backed authentication will occur.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI writes the full fetched results to a local JSON file without any visible opt-in, redaction, or retention controls. Comment/post data can contain personal data, profile identifiers, or sensitive business research, so silent persistence increases the risk of unintended local disclosure, especially on shared machines or in CI/automation environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code path saves result data to disk automatically and does not present an in-file warning or consent mechanism to the user. Even if the data is expected by the tool author, automatic persistence can violate user expectations and leak collected data to other local users, backup systems, or logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code persists the full search output to disk via log.taskWrite, which is a file-write operation that may store user-supplied keywords and returned results locally. Although the script prints status messages, there is no explicit disclosure here that results will be saved to a file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file defines GET and POST helpers that send request parameters, JSON payloads, and a TOKEN header over the network, but it contains no comments, logging, prompts, or other visible disclosure that user/system data and credentials are being transmitted. For code files, network calls that transmit user or system data should have some form of user disclosure unless the warning is provided elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code requires a token and places it into the TOKEN request header, and related error text references the GUAIKEI_API_TOKEN environment variable. There is no visible warning, comment, or user-facing notice in this file explaining that a sensitive credential is required and will be used for outbound authentication.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits all validation errors in Chinese via string literals, with no visible mechanism for language selection or locale opt-in. That creates a natural-language policy issue because users who do not read Chinese may receive forced locale-specific output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. The entire skill description and usage guidance are presented only in Chinese, with no indication that users may choose another language or that the tool is intentionally limited to a Chinese-speaking audience for a documented reason.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but this behavior is not surfaced in the manifest description. Silent persistence of scraped comment data and user-supplied target URLs can create unexpected local data retention, increasing the chance of accidental disclosure, reuse, or collection of sensitive business research artifacts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This changelog uses Chinese throughout, and there is no indication that the skill is region-specific or that users can opt into the language. Under the language/locale policy rule, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill documentation, headings, parameter descriptions, and examples are presented only in Chinese, with no indication that users may choose another language or locale. Under the policy rule for natural-language violations, this is a locale/language constraint that is not presented as optional or justified as region-specific compliance guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code sends a user-provided URL and a token to a remote API via postJson, but the file contains no confirmation prompt, comment, or user-facing notice describing that data transmission. Because network/HTTP calls that transmit user or system data require some form of disclosure for code files, this is a missing-warning issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This function performs a remote API call with the provided URL and token, but there is no confirmation, visible notice, or explanatory documentation in the file indicating that this data is sent off-box. Under the code-file criteria, network calls that transmit user or system data should include some form of disclosure unless already clearly documented elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This code sends user-provided search parameters and a token to remote API endpoints via postJson and getJson. While the network behavior is evident in code, this file contains no confirmation prompt, comment, docstring, or user-facing log that discloses the outbound transmission of potentially sensitive inputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command descriptions, help text, and examples are presented only in Chinese, which imposes a specific language on users without any opt-in or alternative. This is a natural-language policy concern because the skill does not offer locale selection or document a justified region-specific constraint in this file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.