Back to skill

Security audit

快手内容研究助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Kuaishou public-data research tool that calls a third-party API and saves results locally, with no evidence of hidden execution, credential theft, platform write actions, or persistence beyond result logs.

Install only if you are comfortable sending Kuaishou keywords, profile/video URLs, and your GUAIKEI_API_TOKEN to guaikei.com. Treat saved logs as retained research data and delete or protect them if they contain sensitive competitive analysis or personal data from public comments.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (44)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says the skill performs Kuaishou keyword search and returns real-time search data. However, the code chunk does not implement keyword search at all. It calls /api/kuaishou/comment/url to create a comment-fetch task and /api/kuaishou/comment/info to retrieve comment results, requiring a url and limit. This indicates the actual behavior is collecting comment data for a specific Kuaishou URL, not searching by keyword or returning search-result/trend data. That is a material purpose and capability mismatch, not just an implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description emphasizes keyword-based Kuaishou search and real-time search data retrieval. However, the supplied code is centered on creating and fetching a task using a post URL (url) and querying /api/kuaishou/post/* endpoints. There is no evidence of keyword input, search query handling, or search-result retrieval. This is a material behavior mismatch because the primary function shown is post/url-based data retrieval, not keyword search.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的核心能力是“快手关键词搜索”和“获取实时搜索数据”,意味着代码应接受关键词并返回搜索结果、热点或趋势相关数据。但实际代码的主流程完全围绕评论抓取展开:参数为视频URL/视频ID和评论数,调用 comment.createCommentTask / comment.getCommentTask 获取评论,输出结果也明确标记为 command: "comment",并将评论结果保存到文件。代码没有任何关键词搜索、搜索结果获取、实时热点分析或趋势数据处理逻辑。因此其主要用途与声明存在实质性不符,属于明显的描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose says the skill does Kuaishou keyword-based search and fetches real-time search data. However, this code accepts a blogger profile URL or USER_ID, validates it as a profile URL, then calls createPostTask/getPostTask to obtain that account's作品/帖子列表 with sorting and limit parameters. There is no keyword parameter, no search-query handling, and no indication that it retrieves platform-wide real-time search data. The primary function is account/post collection, which is materially different from keyword search. The file logging is secondary, but the main mismatch is substantial enough to flag.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向快手平台的关键词搜索与实时数据获取技能,但给出的代码仅实现了通用命令行参数解析和帮助信息生成,属于底层工具代码。代码没有体现任何与快手、关键词搜索、实时数据、内容研究或趋势分析相关的实际行为,也没有访问网络、调用平台接口或处理搜索结果。因此该代码块与声明用途存在明显不匹配,且当前代码的主要目的与声明的核心功能 materially different。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明的核心能力是快手关键词搜索和实时数据获取,但代码实际只是一个本地日志写入模块。它使用 fs 和 path 在本地 logs 目录创建/写入文件,属于文件系统操作能力,而这些能力未在描述中体现。更重要的是,代码没有任何与快手平台、搜索、爬取、API 调用、实时数据处理相关的行为,因此其实际行为与声明用途存在明显的实质性不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a user-facing capability for querying Kuaishou search data. The actual code chunk contains only a helper that reads package.json from the local filesystem and returns the package name. This is materially unrelated to Kuaishou search, trend analysis, or any real-time data retrieval. While it may be a benign internal utility, the supplied code does not match the declared primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

声明的核心能力是“快手关键词搜索获取实时搜索数据”,这意味着代码应体现搜索请求、结果抓取/解析、关键词处理或数据获取逻辑。但提供的代码片段只处理输入 URL:将 http 规范化为 https、校验是否为快手视频/主页链接、支持部分短码/数字 ID 判断,并生成基于 URL 的名称。这属于辅助性的链接处理功能,且与“关键词搜索”这一主要用途 materially different。虽然都与快手有关,但该代码的实际行为并不能支撑声明中的主要功能,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a skill for Kuaishou keyword search and real-time search data to support content research and trend observation. This file instead accepts a profile URL or user ID, creates a 'post' task, retrieves that creator's works, and stores the results, which is a materially different capability centered on account/post scraping rather than keyword search.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description and the full markdown instructions are presented only in Chinese, and there is no indication that users can choose another language. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The package presents itself as a content research and analysis skill, but its declared npm scripts include posting and commenting operations. That mismatch expands the capability surface from passive analysis to active account actions, which can enable unauthorized posting, spam, or abuse if a user installs or runs the skill expecting read-only behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Posting and commenting are write actions that are not justified by the stated goal of content research, trend observation, and competitive analysis. In this context, undocumented write capabilities are risky because they may be used to manipulate platform content, act on user accounts unexpectedly, or hide higher-risk behavior behind a benign research label.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not clearly warn users that scraped search results, account URLs, comments, or other research data may persist on disk. This creates a real privacy and data-retention risk because operators may unknowingly store sensitive business research or personal data from public profiles, which could later be exposed through backups, shared workspaces, or misconfigured access controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill documentation, including headings, parameter descriptions, and usage examples, is written in Chinese with no indication that other languages are supported. This creates a natural-language locale constraint that is not presented as optional or justified as a region-specific requirement.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes the skill as a Kuaishou keyword-search tool for obtaining real-time search data for content research. This file documents additional capabilities to fetch a creator's works and retrieve comments from specific videos, which are materially broader than keyword search results and trend observation alone.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a skill for Kuaishou keyword search and obtaining real-time search data for content research. This file instead creates and queries comment collection tasks for a specific URL via /api/kuaishou/comment/*, which is a distinct content/comment scraping capability rather than keyword search behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends a user-provided URL to a remote API and includes an authentication token, which is a network operation involving potentially sensitive user or system data. While retry errors are logged, there is no user-facing warning, confirmation, or explanatory comment/docstring in this file describing that data will be transmitted externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The function performs a remote API request that transmits the target URL together with an authentication token, but the file contains no visible disclosure beyond error logging. Under the code-file criteria, network calls that transmit user or system data should have some form of warning, comment, or other user-facing explanation unless already clearly disclosed elsewhere.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill for "关键词搜索获取快手实时搜索数据" used for keyword-based content research, but this file creates and queries tasks against /api/kuaishou/post/url and /api/kuaishou/post/info using a post URL parameter rather than a keyword. That indicates the implemented behavior includes URL-based post analysis/retrieval, which is materially different from the stated keyword-search scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill for Kuaishou keyword search and realtime search data used for content research and trend observation. This CLI instead creates a comment retrieval task, fetches comment results for a specific video, and persists them to a local JSON file, which is a materially different content-collection workflow than keyword search.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

comment.createCommentTask and comment.getCommentTask perform network-backed operations using an API token and send user-supplied video identifiers/URLs to an external service. The code logs status but does not clearly disclose to the user that their input will be sent to a remote API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Comment results are written to local storage without an explicit warning or opt-in in this file. In agent environments, silent persistence can expose collected data to other processes, future tasks, or operators and increases privacy/compliance risk beyond the immediate command execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI persists the full search output to a local JSON file whose filename also embeds the user’s keyword and options. This creates an unannounced local data trail containing potentially sensitive research terms and retrieved content, which may be exposed to other local users, backups, logs, or later compromise of the host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits user-facing error messages in Chinese, and additional user-visible output at L35-L37 is also Chinese-only. That enforces a specific language/locale in the skill's interface without offering a choice or documenting a justified locale restriction, which matches the policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:15