Back to skill

Security audit

快手关键词搜索、竞品分析与舆情监控工具

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Kuaishou public-data CLI integration, with expected token use, network calls, and local result logging for its stated purpose.

Install only if you are comfortable sending Kuaishou keywords, creator/video URLs, request parameters, and your GUAIKEI_API_TOKEN to guaikei.com. Use it only for public Kuaishou data, comply with platform terms and applicable privacy rules, keep the token secret, and periodically clear or protect the local logs directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码片段仅实现了通用的命令行参数解析与帮助信息生成功能,是基础工具模块,不包含任何与快手相关的搜索、抓取、评论分析、竞品分析、舆情监控或数据处理逻辑,也未显示访问快手公开数据或其他外部资源。其实际主要用途与声明的业务功能存在明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a full-featured Kuaishou data collection and analysis tool. However, the supplied code chunk does not implement any Kuaishou-related behavior, networking, scraping, searching, or analysis. It simply accesses the local filesystem to read package.json and returns the package name. While this could be a supporting utility in a larger project, evaluated on this code chunk alone it does not match the declared purpose and instead performs unrelated local metadata access.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description is entirely in Chinese and includes trigger phrases only in Chinese, which can cause the skill to operate as if a specific language/locale is required. The policy allows locale constraints only when the skill offers opt-in choice or clearly documents and justifies the restriction; this file does neither.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest advertises broad trigger phrases such as 短视频运营, 热点追踪, 爆款挖掘, and 数据分析, which can match many generic content-analysis requests outside a narrowly scoped Kuaishou tool. This increases the chance the agent invokes the skill in unintended contexts, potentially causing unnecessary data collection, off-target scraping, or disclosure of externally sourced content when the user did not specifically request Kuaishou analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description promotes collection of public Kuaishou data, comments, works, opinion monitoring, and competitor analysis without any notice about privacy, platform terms, or responsible handling of personal data that may appear in comments and creator profiles. In an agent setting, this omission can normalize silent scraping or analysis of user-generated content and lead to compliance, privacy, or reputational harm if the skill is invoked without informed user awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not clearly warn users that fetched public data, search keywords, URLs, and analysis outputs may be written to disk. In a competitor-analysis and social-monitoring tool, those artifacts can reveal sensitive business interests, monitoring targets, and collected datasets, creating confidentiality and retention risks on shared machines or improperly secured environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document instructs users to collect blogger works and video comment data at scale, but it provides no warning about privacy, consent, platform terms, retention, or downstream handling of potentially personal data. In a competitive-analysis and public-opinion monitoring context, that omission increases the chance the tool will be used for profiling, surveillance, or non-compliant scraping workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The tool saves fetched results to a local file without warning, confirmation, or an explicit user request. In a data-collection/competitive-analysis context, this can create an unexpected local record of targets and retrieved content, which may later be exposed through backups, source control, shared directories, or multi-user hosts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The user-facing descriptions, examples, warnings, and runtime messages in this script are all hard-coded in Chinese. For a general-purpose search CLI, this imposes a specific language/locale without any opt-in, fallback, or documented justification that the tool is intended only for Chinese-speaking users or a China-specific environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple user-visible error strings are hard-coded in Chinese, including validation and network failure messages, with no opt-in or locale selection. This is a natural-language policy concern because the skill appears to enforce a specific language rather than offering user choice or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code performs outbound HTTPS GET and POST requests, includes a TOKEN header, and sends serialized request data, but the file contains no confirmation prompt, logging, or comments/docstrings disclosing that user or system data may be transmitted. For code files, undisclosed network transmission is in scope when there is no visible warning and the operation is not clearly disclosed here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains multiple user-facing error strings in Chinese, such as the messages printed for invalid keywords and options. Because the skill forces a specific language in its natural-language output without any user opt-in or documented regional justification, it appears to violate the language/locale policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README instructs users to configure GUAIKEI_API_TOKEN but does not include basic guidance on treating the token as a secret, such as avoiding hardcoding, screenshots, shell history leakage, or committing it to version control. While using an environment variable is standard practice, the missing warning can still lead to accidental credential exposure, especially for less technical users following setup instructions verbatim.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L1 presents the skill primarily in Chinese, and the file contains no indication that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific audience. This can violate language/locale policy when users are not given an explicit choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The file presents all operational instructions in Chinese, which can amount to a language/locale policy constraint when no user opt-in or alternative language option is provided. SQP-3 applies to all file types and covers natural-language policies that force a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's user-facing descriptions, help examples, status messages, and error text are consistently in Chinese, which imposes a specific language on users without any visible opt-in or alternative locale. This matches the policy concern for language/locale constraints expressed in natural language within code string literals.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest presents the skill as a public-data acquisition and analysis tool for Kuaishou content, but this file requires a secret token from process environment variables to operate. Using credentials may be implementation-specific, yet the capability to consume secrets is not justified by the user-facing purpose stated in the manifest itself.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The CLI writes fetched results to a local JSON file automatically after successful execution. Even if the source data is public, the collected dataset, query target, and timestamps may be sensitive in aggregate, and silent persistence increases the chance of unintended disclosure on shared systems or in synced workspaces.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JavaScript file contains natural-language comments, error messages, and help output entirely in Chinese, including the main description, thrown errors, and generated CLI help text. Under the policy rule for language/locale, this forces a specific language without any visible opt-in or alternative locale support.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code emits all user-facing error messages in Chinese only, and later success/error output is also Chinese. This creates a language-policy concern because the skill forces a specific language without any visible user choice or documented locale constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The functions require a token value and then place it into the outbound TOKEN header, which means the skill handles sensitive credentials. There is no comment, docstring, prompt, or log message explaining this sensitive credential usage in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The thrown error string on L21 is written only in Chinese ("重试${maxAttempts}次后失败"). This creates a language-specific user-facing message without any indication of localization support or user choice, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file contains natural-language comments and user-visible warning/info strings in Chinese, including the warning at L26 and info message at L31, with no indication that the skill is China-specific or that users can opt into a language. This can violate language/locale policy when a skill imposes a specific language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JavaScript file contains user-facing natural-language strings in Chinese, including the module description and banner text. Because the file does not indicate that the skill is region-specific or provide any user opt-in for language selection, it may violate a language/locale policy requiring user choice or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:15