Back to skill

Security audit

快手带货达人筛选

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Kuaishou public-data retrieval tool that sends user-selected queries to a third-party API and saves results locally.

Install only if you are comfortable sending Kuaishou keywords, profile/video URLs, request parameters, and your GUAIKEI_API_TOKEN to guaikei.com. Review and delete the generated logs if the collected public comments or creator data should not remain on disk or enter backups/source control.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是面向快手达人筛选与数据分析的业务能力,而实际代码只是一个通用日志落盘工具,使用 Node.js 的 fs/path 模块在本地文件系统创建目录并写入文件。该行为不对应声明中的三大能力,也引入了未声明的本地文件写入资源访问。虽然日志工具可能属于实现细节,但此片段本身的实际功能与所述业务目的并不一致,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description promises higher-level behavior such as filtering creators by keywords, likes, category, and market, then combining interaction, content-performance, and sales-effectiveness data to produce collaboration priority. In this file, the only exposed code entry points are three scripts for search, post retrieval, and comment analysis; there is no surfaced capability corresponding to creator matching or cooperation-priority ranking.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description uses broad activation cues such as requests about creator matching, filtering, or collaboration candidates, which can cause the skill to trigger in contexts broader than the user intended. Over-broad routing increases the chance of unnecessary scraping or data retrieval actions being invoked on ambiguous requests, especially in an agent ecosystem where tool selection is automatic.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest says the skill analyzes creators and comments, but it does not clearly disclose that it retrieves public creator content and comment interaction data. This weakens informed consent and transparency, making it easier for users or orchestrators to invoke collection of third-party data without understanding the privacy and compliance implications.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest says this skill is for creator matching and explicitly lists three capabilities: keyword video search, creator post retrieval, and video comment analysis. The README reframes it as a general-purpose '快手数据挖掘' tool for competitor monitoring, trend prediction, hot-topic tracking, and broad market analysis, which materially expands the claimed purpose beyond the manifest’s matching-focused scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states that all task results are automatically saved under logs/ but does not clearly warn that scraped public-platform data, URLs, keywords, and analysis outputs may persist on local disk. This creates a data exposure risk: shared workstations, CI runners, backups, or source-control mistakes could unintentionally disclose collected datasets and analysis artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI persists fetched comment data to a local JSON file automatically after successful execution, without user consent, opt-in, or any warning that potentially sensitive third-party content and metadata will be retained on disk. In this skill’s context, comment datasets may contain personal data, usernames, or interaction details from social platforms, increasing privacy, compliance, and accidental disclosure risk if the host environment is shared or logs/artifacts are collected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command descriptions, examples, warnings, and runtime messages are presented only in Chinese, which imposes a language choice on users without opt-in. The policy allows locale constraints only when they are explicitly documented and justified, which is not evident in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language comments, error messages, and help output entirely in Chinese, which imposes a specific language on users of the CLI. Under the policy, forcing a language or locale without user opt-in or clear justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code contains user-facing error strings in Chinese, and additional user-visible status/error messages later in the file are also Chinese-only. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Multiple error messages presented by this utility are fixed Chinese-language strings such as '请求失败' and '网络错误'. This enforces a specific language in user-visible text without offering locale selection or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The manifest description is entirely in Chinese and does not indicate that the skill can operate in other languages or adapt to the user's preferred locale. Under the language/locale policy, this can be a violation when no opt-in or documented locale limitation is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

All user-facing instructions and descriptions are presented only in Chinese, and the README does not indicate whether other languages are supported or whether Chinese-only use is a deliberate, justified locale constraint. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

Line L07 states the tool provides '趋势预测' services, but the rest of the README only documents data retrieval workflows such as keyword search, post scraping, and comment analysis. This is not just incomplete wording: it suggests a predictive capability that is not supported by the described implementation details in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all user-facing instructions, parameter descriptions, and examples exclusively in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code persists the full search output to disk via log.taskWrite, which is a file-write operation covered by the warning requirement for code files. While the script logs progress messages and mentions the API token in help text, there is no visible disclosure here that search inputs and results will be saved locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code sends request payloads and a TOKEN header to a remote host via HTTPS, which is a safety-relevant network operation. In this file there is no confirmation prompt, user-facing log, or inline warning explaining that user-supplied data and credentials are being transmitted externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The getJson helper builds query parameters, includes the TOKEN header, and issues an outbound HTTPS request. The file contains no visible warning, logging, or explanatory comment indicating that request metadata and authentication are sent to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The thrown error string at L21 is written only in Chinese (重试${maxAttempts}次后失败). This imposes a specific language in a user-visible message without offering language choice or documenting a justified locale constraint, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module comment and banner text are written in Chinese, and the printed user-facing banner is hardcoded to Chinese with no indication of language selection or locale opt-in. This can violate language/locale policy requirements when a skill imposes a specific language on users without offering a choice or documenting a justified regional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits all user-facing error messages in Chinese, which imposes a specific language on users without any visible opt-in or locale selection. Under the language/locale policy, hard-coding a single language can be a natural-language policy violation when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.