Back to skill

Security audit

快手竞品分析与品牌对比

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Kuaishou public-data research wrapper that sends requested queries to a third-party API and saves returned results locally.

Install only if you are comfortable sending your Kuaishou keywords or URLs and GUAIKEI_API_TOKEN to guaikei.com, and remember that successful results are saved locally in logs and may include public comments, profile/video links, and competitive research terms.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (34)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码仅包含 scripts/utils/args.js,一个通用 CLI 参数解析与帮助文本生成模块。其功能是读取命令行参数、校验类型、处理默认值/必填项/别名/布尔参数、生成 help 文本,并返回解析结果或抛出参数错误。它没有任何网络请求、快手平台访问、视频搜索、作品抓取、评论采集、互动数据分析或品牌对比逻辑。因此,这段代码的实际行为与声明的核心用途存在明显不一致,属于材料性描述-行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description at L04 describes competitor comparison, content performance, interaction data, and trend analysis at a high level, but does not mention the explicit third capability stated in the provided manifest context: analyzing video comments. The package scripts clearly expose a dedicated comment operation via comment-cli.js, indicating a concrete behavior that is more specific than the package.json description claims.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest limits the skill to three concrete functions: keyword video search, creator post retrieval, and comment analysis. However, the README claims broader outcomes such as '趋势预测', 'KOL筛选', and deep competitor monitoring/data mining, which overstates what the described operations actually support and creates a semantic mismatch between declared scope and documented behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Automatically saving task results without warning users that scraped comments, links, profile URLs, or other public data may be stored on disk creates a real data-handling risk. In competitor analysis and social monitoring contexts, these artifacts may contain personal or sensitive business intelligence, and undisclosed retention can lead to accidental disclosure or over-collection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code sends a user-provided URL and an auth token to an API via postJson, which is a data-transmitting network operation covered by the missing-warning rule for code files. While retry errors are logged, there is no confirmation prompt, user-facing disclosure, or explanatory comment/docstring in this file warning that this data is transmitted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The getJson call transmits the URL, limit, and token to a backend endpoint, which is a network operation involving potentially sensitive data. The file contains retry error logging, but no user-facing warning, confirmation, or descriptive comment indicating that these values are sent externally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI help text and runtime status/error messages are presented in Chinese throughout the file, which forces a specific language for all users. The file does not offer a locale option, fallback, or any indication that the language restriction is intentional and documented as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI persists fetched comment results to a local JSON file automatically after successful execution, without any explicit user confirmation, warning, or opt-out shown in this file. Because comment data may include user-generated content and interaction metadata, silently storing it increases the risk of unintended retention, secondary exposure on shared systems, and compliance/privacy issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code forces Chinese-language descriptions, status messages, and errors throughout the CLI, including help text and runtime output. That is a natural-language locale policy concern because users are not offered any language/locale opt-in and the file does not document a justified region-specific restriction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI persists fetched作品数据 to a local file using a filename derived from user input. Even if the data is obtained for analysis, writing it to disk creates an additional data-retention and disclosure surface that is not obvious from a read/analysis-oriented interface; local logs may later be exfiltrated, shared unintentionally, or violate least-privilege expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI writes the full search output to a local JSON file after completing a search, even though the stated skill capability is search and analysis rather than persistent local storage. This creates an unnecessary data-at-rest surface: keywords, request metadata, and returned content may remain on disk and be accessible to other local users, backup systems, or later processes without the user's clear awareness.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code records both query parameters and the full result payload to local storage, which may include sensitive business-intelligence queries, competitor research terms, and large datasets. In the context of a competitor-radar skill, these artifacts can reveal user strategy and collected intelligence if the host is shared, compromised, or routinely backed up.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Search results and request details are silently written to a local file without any explicit warning in this file's normal execution flow or help output. Silent persistence undermines user expectations and can leak potentially sensitive search terms and retrieved content to local disk where they may be indexed, shared, or exfiltrated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file embeds user-facing natural-language strings in Chinese, beginning with the top-level description and continuing throughout error and help messages. Because the skill does not offer a language selection mechanism or document a justified locale restriction, it appears to force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

User-visible errors such as missing-value and unknown-option messages, along with generated help text, are all emitted only in Chinese. Under the policy, forcing a specific language across the interface is a natural-language policy issue unless users can opt in or the locale limitation is clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code defines GET and POST helpers that send request parameters, JSON payloads, and a TOKEN header to a remote host via HTTPS. There is no confirmation prompt, user-facing log, or inline warning indicating that user/system data and credentials will be transmitted off-box.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file contains user-facing warning and info strings in Chinese only ("警告: 你的 GUAIKEI_API_TOKEN 未正确配置" and "已使用配置的私有TOKEN"). Because this is a general utility module and there is no indication that the skill is intentionally limited to Chinese-speaking users, this creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits all user-visible error strings in Chinese, which can force a specific language on users regardless of their locale. The file does not show any user opt-in, fallback, or documented justification for a Chinese-only interface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The package description and keywords are entirely in Chinese and centered on the Kuaishou platform, with no indication that users can choose another language or locale. The policy calls for flagging language or locale constraints when a skill appears to force one without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The README is entirely in Chinese and presents all instructions and user-facing guidance in a single language. Under the policy, forcing a specific language without user opt-in can be a natural-language policy issue unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

Line L13 broadly promises returning all visible and valuable data, and other sections explicitly include comment content and interaction data collection. Line L69 then states the tool does not involve obtaining user privacy data; while the code is not shown, this documentation pairing risks contradiction by minimizing the sensitivity of harvested public user-generated data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The README states that all task results are automatically saved to a logs/ directory, but does not clearly describe retention, sanitization, or the kinds of scraped URLs, comments, and interaction data that may be persisted. Even when data is public, silent local archiving increases the risk of unintended data retention, exposure through shared workspaces, and downstream misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all instructions, parameter descriptions, and examples exclusively in Chinese. Under the policy criteria, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative language or explicit locale limitation is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The retry log message is emitted in Chinese only, which imposes a specific language in user-visible output. The file does not indicate any user opt-in, fallback, or documented region-specific justification for this locale choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.