Back to skill

Security audit

快手数据智能助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Kuaishou public-data lookup tool that sends user-provided targets to a third-party API and saves results locally, with no evidence of hidden execution, credential theft, or destructive behavior.

Install only if you are comfortable sending Kuaishou search terms, profile/video URLs, request parameters, and your GUAIKEI_API_TOKEN to www.guaikei.com, and remember that fetched results are saved locally in logs for later review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents an end-user data acquisition tool for Kuaishou with three concrete data capabilities. However, the supplied code chunk only implements a reusable CLI argument parser and help-text builder. This is not merely a supporting detail tied specifically to the declared behavior; it is generic infrastructure with no observable logic for accessing Kuaishou, performing searches, retrieving works, fetching comments, or analyzing interaction data. Therefore, the code chunk's actual behavior does not accurately represent the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a data collection and analysis tool for Kuaishou with three major external-data capabilities. However, the supplied code chunk does not implement any of those behaviors. It merely accesses the local filesystem, reads package.json, caches the name field, and returns it. This is materially different from the declared purpose, so the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to obtain and configure an external API token, but it does not clearly disclose that searched keywords, profile/video URLs, and retrieved data will be transmitted to a third-party service. This creates a transparency and data-handling risk: users may unknowingly send sensitive research targets, monitoring subjects, or collected data off-platform, which is especially relevant for market intelligence and competitor monitoring use cases.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and all user-facing instructions are written exclusively in Chinese, with no indication that other languages are supported or that the Chinese-only scope is optional. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

comment.createCommentTask(...) and comment.getCommentTask(...) transmit user-supplied data to an external service, and the file also uses an API token from the environment. The code does not clearly disclose in help text or preflight messaging that input data will be sent over the network.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes obtaining video comments and interaction data for analysis, but this file additionally writes the full output payload to disk via log.taskWrite. Local persistence is a separate storage/export capability that is not mentioned in the stated three supported abilities for the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code persists the full output, including requested URL and fetched comments, via log.taskWrite(...). While the script prints status messages, it does not disclose before execution that it will save retrieved data to disk, which is a user-impacting file write operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code persists the full task output to disk via log.taskWrite, creating a file named from the URL-derived identifier and timestamp. Although the script logs progress messages, there is no explicit disclosure in this file that user-requested data will be saved locally rather than only printed to stdout.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes capabilities for searching videos, fetching creator works, and obtaining comment data, but does not mention local result archival or file persistence. This code writes the full search output to a JSON file, which is an additional data-retention capability beyond the stated assistant behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code emits user-facing status and error messages exclusively in Chinese, such as the validation errors on L07 and L11. For a general utility file, this hard-coded locale imposes a language choice without user opt-in or any documented justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code emits all user-visible error strings in Chinese, which can violate language/locale policy when the skill is not explicitly limited to Chinese-speaking users. There is no indication in this file that the language is configurable, optional, or justified as a region-specific tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest description is entirely in Chinese and presents the skill as a Chinese-language assistant ('快手数据智能助手') without indicating any language choice or opt-in. Under the policy, language-specific behavior should either offer user choice or clearly justify the locale constraint; this file does neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

All user-facing documentation is presented exclusively in Chinese, with no indication that other languages are supported or that Chinese is a required, justified locale constraint. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Line L1 presents the skill documentation entirely in Chinese, which can indicate a fixed language choice rather than offering users a language or locale option. Because the file provides no explanation that the skill is region-specific or limited to Chinese-speaking users, this may conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file contains hard-coded Chinese-only messages such as '创建任务重试', '查询任务重试', and '评论结果格式错误'. This is a natural-language locale restriction with no indication that users can opt into another language or that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script stores retrieved search results to a local file without clearly warning the user in the normal execution flow that data will be persisted. Even though this is a data-research tool, silent local storage can expose potentially sensitive research datasets, query terms, or collected comments to other local users, backups, or unintended retention.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file uses Chinese exclusively in comments, thrown error messages, and generated help output, which indicates the skill is effectively fixed to a single language. Under the policy, locale or language constraints should either be optional for the user or clearly documented as justified for a region-specific tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

Multiple error messages in this file are fixed Chinese strings, which can force a specific language experience on users or operators. The file does not indicate any locale selection, fallback, or documented justification for restricting messages to Chinese.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code sends JSON payloads and a TOKEN header over network requests via postJson and getJson, which may transmit user or system data to an external service. There is no confirmation prompt, warning comment, or user-facing log in this file to disclose that outbound transmission occurs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The thrown error string 重试${maxAttempts}次后失败 is hardcoded in Chinese, which imposes a specific language on users of this utility. The file does not indicate any user language choice, localization mechanism, or region-specific justification for this locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module contains user-facing natural-language text in Chinese, including the banner title, with no indication that users can choose another language or locale. This can violate language/locale policy when a skill implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.