Back to skill

Security audit

快手数据分析GuaiKei作品详情

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Kuaishou public-data tool that sends user-supplied queries to GuaiKei and saves returned results locally.

Install only if you are comfortable sending Kuaishou search terms or URLs, plus a GUAIKEI_API_TOKEN, to GuaiKei's API. Be aware that returned public comments or post data may be saved locally under logs, so clean that directory if the results should not be retained.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the static analysis is correct that the actual implementation lacks Kuaishou data access and instead only performs local filesystem or package-metadata operations, then the skill is materially misrepresented. A skill that claims one purpose while doing unrelated local operations undermines user trust and can conceal unwanted persistence or data collection, making review and safe consent difficult. In an agent ecosystem, this mismatch is dangerous because users may authorize execution expecting external data retrieval, not local side effects.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the static analysis is correct that the actual implementation lacks Kuaishou data access and instead only performs local filesystem or package-metadata operations, then the skill is materially misrepresented. A skill that claims one purpose while doing unrelated local operations undermines user trust and can conceal unwanted persistence or data collection, making review and safe consent difficult. In an agent ecosystem, this mismatch is dangerous because users may authorize execution expecting external data retrieval, not local side effects.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the static analysis is correct that the actual implementation lacks Kuaishou data access and instead only performs local filesystem or package-metadata operations, then the skill is materially misrepresented. A skill that claims one purpose while doing unrelated local operations undermines user trust and can conceal unwanted persistence or data collection, making review and safe consent difficult. In an agent ecosystem, this mismatch is dangerous because users may authorize execution expecting external data retrieval, not local side effects.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file presents all user-facing instructions, activation guidance, warnings, and support information exclusively in Chinese. That effectively forces a specific language/locale for use of the skill without documenting user choice or an explicit locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documentation forces a specific language/locale for all users, and there is no indication that users can choose another language or that the Chinese-only presentation is optional. Under the stated policy, language constraints should be opt-in or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI persists fetched comment data to a local JSON file using a filename derived from runtime inputs, but it gives no explicit user-facing disclosure or consent prompt before writing potentially sensitive third-party data to disk. In a social-media data analysis skill, comment contents may contain personal data, usernames, or sensitive text, so silent persistence increases the risk of unintended retention, local exposure, and compliance/privacy issues on shared or monitored systems.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script persists the full fetched results to a local JSON file after completing the query. This creates a secondary data store on disk that may contain scraped profile/post data and metadata, increasing exposure if the host is shared, monitored, or later compromised. In this skill context, local persistence is adjacent to the stated analytics function, but doing it silently and by default makes the behavior more privacy-sensitive than a pure query tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script writes collected query results to a local file without an explicit warning or consent mechanism in this workflow. Silent persistence can surprise users, expand the data retention surface, and expose potentially sensitive collected data to other local users, backups, or malware. Because this is a social-media analytics skill, stored results may include content or account data that users expect to be transient.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code persists the full search output to disk via log.taskWrite, including request metadata and results, but this file itself does not provide a user-facing warning at the point of write. For a code file, file writes that may store user-provided keywords and retrieved data should have some visible disclosure unless clearly covered elsewhere in the skill description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This JavaScript file contains natural-language comments, thrown error messages, and help text entirely in Chinese, including user-visible CLI output such as parameter errors and usage text. Because the file does not indicate that the skill is region-specific or provide any opt-in for language selection, it can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code contains hard-coded Chinese user-facing strings for error reporting, which imposes a specific language on users without any visible opt-in or locale selection. The policy explicitly flags language or locale restrictions unless the skill offers a choice or clearly documents a justified regional scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code constructs and sends HTTPS requests containing serialized parameters, request data, and a TOKEN header to a remote host. There is no confirmation prompt, user-facing log/print, or warning in this file that user or system data may be transmitted off-host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The GET helper appends parameters to the URL query string and includes a TOKEN header for outbound HTTPS requests. This is a network operation that may expose user or system data, but the file contains no visible warning, prompt, or log disclosing that behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JavaScript file contains multiple user-facing error strings in Chinese, such as at L05, L10, L14, L18, L23, L50, L54, L59, and L64. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not evident in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language description is entirely in Chinese and provides no indication that other languages are supported or that the skill is intentionally limited to Chinese-speaking users. Under the policy rule for language/locale constraints, this can be considered a language-choice violation because no user opt-in or justification is stated in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown documentation presents all user-facing instructions and parameter descriptions in Chinese only. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code sends the provided URL and limit to a remote API and includes an authentication token, but the file contains no confirmation prompt, warning comment, or user-facing disclosure about transmitting that data. Because these are external HTTP requests involving potentially sensitive user input and credentials, the absence of any local warning is a quality/safety concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This function performs a remote GET request that includes the URL and limit parameters and uses the token for authentication, yet there is no visible disclosure to the user that their data is being sent to an external service. The existing retry error logs describe failures but do not warn about the underlying network/data transmission behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI's descriptions, help examples, validation errors, and status messages are presented in Chinese throughout the file. Under the policy, forcing a specific language without user opt-in is a natural-language policy issue unless the locale limitation is explicitly justified or the user is given a language choice.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest presents the skill as a Kuaishou data assistant but does not mention credential handling or environment-based secret access. Reading GUAIKEI_API_TOKEN is understandable for API-backed access, but it is still an undeclared capability relative to the stated purpose and available description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Error messages in this file are presented only in Chinese, including user-directed guidance about checking environment variables and contacting support. For a general-purpose skill, hardcoding a single language without opt-in can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The thrown error string is written only in Chinese (重试${maxAttempts}次后失败), which forces a specific language in user-visible output. The file does not show any language selection, localization mechanism, or documentation justifying a fixed locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module comment and banner text are written entirely in Chinese, including the primary user-facing label shown at runtime. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:15