Back to skill

Security audit

快手爆款短视频拆解

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Kuaishou public-data lookup tool that sends user-provided search or URL inputs to a third-party API and saves results locally.

Install only if you intend to use GuaiKei's third-party Kuaishou data API. Expect your keywords, Kuaishou URLs or IDs, limits, and API token to be sent to www.guaikei.com, and expect retrieved results to be saved locally under logs/. Avoid collecting or retaining more public comments or profile data than you need, and review platform, privacy, and internal data-handling rules before bulk exports.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (34)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the actual code is unrelated to Kuaishou analytics and instead accesses local filesystem/package metadata, then the skill is materially misrepresented. This kind of mislabeling is dangerous because it can mask unauthorized local inspection or other non-obvious behavior behind a benign-looking analytics description, increasing the likelihood of unsafe execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the actual code is unrelated to Kuaishou analytics and instead accesses local filesystem/package metadata, then the skill is materially misrepresented. This kind of mislabeling is dangerous because it can mask unauthorized local inspection or other non-obvious behavior behind a benign-looking analytics description, increasing the likelihood of unsafe execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the actual code is unrelated to Kuaishou analytics and instead accesses local filesystem/package metadata, then the skill is materially misrepresented. This kind of mislabeling is dangerous because it can mask unauthorized local inspection or other non-obvious behavior behind a benign-looking analytics description, increasing the likelihood of unsafe execution.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s user-facing instructions, examples, and operational guidance are all presented in Chinese, with no indication that the user can choose another language. This can violate a language/locale policy when a skill effectively forces one language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that all task results are automatically saved to a local logs/ directory, but it does not warn users that outputs may contain URLs, keywords, comments, profile data, or other potentially sensitive business or personal information. In a data-scraping and analytics tool, silent retention increases the risk of unintended local exposure, over-collection, and mishandling of regulated or confidential data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly supports bulk retrieval of up to 10,000 comments from a video but provides no warning about privacy, consent, retention, or downstream use of user-generated data. In a social-media analytics skill, this materially increases the risk of mass collection, profiling, or misuse of commenter data, especially if operators assume the capability is unrestricted and compliance-free.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends user-supplied data (url, sort, limit) and an authentication token to remote API endpoints via postJson, but the file contains no confirmation prompt, comment, or user-facing disclosure describing that network transmission. Because this is a code file and the warning is not visible here, it meets the missing user warning criterion for network operations involving user or system data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The getPostTask function performs a network request that includes the provided URL, sorting options, limit, and token, but the file has no docstring, comment, or user-facing message warning about this data transmission. Under the code-file criteria, network calls that transmit user or system data should have some visible disclosure unless already clearly covered elsewhere.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes analytics and retrieval capabilities such as keyword search, creator works, video details, and comments. In addition to retrieving comments, this CLI persists the full output to disk via log.taskWrite, which is a behavior not reflected in the stated description and goes beyond a purely retrieval/analysis action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This CLI sends the supplied profile URL/USER_ID along with an API token to external APIs, but the user-facing flow shown here does not provide an explicit notice that inputs will be disclosed over the network. In a data-analysis skill, network access is expected, which lowers severity, but the lack of clear disclosure can still cause unintended sharing of identifiers or metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The tool writes retrieved results to a predictable local JSON file as a side effect, without explicit user notice or an opt-in control. If results include personal data, engagement metrics, or proprietary research inputs, silent persistence can expose data to other local users, backups, or downstream tooling unexpectedly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script writes full search results and request metadata, including user-provided keywords and query parameters, to a local file. In a search/analysis skill this creates an unnecessary persistence channel for potentially sensitive research data, which can be exposed to other local users, backups, or later processes if log storage is not tightly controlled.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code emits user-facing status and error messages only in Chinese, such as the validation errors on these lines. The file provides no indication that the skill is China-specific or that users can opt into a language/locale, which conflicts with the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The code sends JSON payload data to a remote host and includes a TOKEN header, but there is no confirmation prompt, user-visible log, or inline warning indicating that user or system data may be transmitted over the network. Because this utility performs outbound API calls with credential-bearing headers, it should provide some disclosure unless that behavior is explicitly documented elsewhere in skill markdown.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits user-facing warning and info messages only in Chinese, which can violate a language/locale policy when the skill is not explicitly scoped to Chinese-speaking users. There is no indication in the file that the user can opt into a language or that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON manifest contains user-facing natural-language metadata entirely in Chinese, but provides no indication that the skill is region-specific or that users can opt into a preferred language. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The entire skill documentation is presented in Chinese and does not indicate whether other languages are supported or whether the language requirement is intentional and limited to a China-specific audience. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy issue unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This markdown file contains a prominent user-facing title in Chinese with an English parenthetical label, but it does not explain whether the skill is intended specifically for Chinese-speaking users or offers language choice. That can conflict with language/locale policy expectations when a skill appears to assume a language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The entire skill documentation is presented only in Chinese, with no indication that language choice is optional or that the skill is region-specific. Per the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file presents descriptions, examples, and runtime messages exclusively in Chinese, which imposes a language choice on all users. Under the policy, fixed language behavior without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill description focuses on Kuaishou data analysis and comment retrieval, but the code directly reads process.env.GUAIKEI_API_TOKEN to obtain credentials. Credential access may be operationally necessary, but it is not disclosed in the stated purpose and is an additional capability outside the user-facing description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code reads an API token from the environment and then sends the normalized video URL and limit to external comment APIs. While the script prints status messages, it does not clearly disclose that user-supplied data is being transmitted to a remote service, which is the relevant warning criterion for code files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script persists the full output, including retrieved comments and request metadata, to a JSON file via log.taskWrite. There is no visible confirmation, print statement, or inline documentation warning the user that the command will create a local file containing the results.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The manifest describes Kuaishou analytics and content retrieval functions, but does not mention credential handling. Reading GUAIKEI_API_TOKEN from the environment is not inherently wrong, yet it is a capability outside the stated end-user function and may matter for trust and deployment review.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:15