Back to skill

Security audit

快手热点选题追踪助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Kuaishou public-data lookup tool that sends user-provided keywords or Kuaishou URLs to a third-party API and saves returned results locally.

Install only if you are comfortable sending Kuaishou search terms, profile URLs, video URLs, and your GUAIKEI_API_TOKEN to guaikei.com. Review or clear the generated logs directory if the returned public data, research topics, or competitor monitoring results should not persist locally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (46)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose says the skill performs Kuaishou keyword search and returns real-time search data. However, the supplied code is specifically for comment collection: it creates a comment task from a URL and later queries comment results, validating that returned data is an array of comments. There is no keyword-search logic, no search query parameter, and no indication of retrieving search-result data. This is a material purpose mismatch, not just an implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose emphasizes keyword search for real-time Kuaishou search data. However, the code operates on 'post' endpoints and requires a URL input, suggesting it fetches information/results for a specific Kuaishou post/task rather than performing keyword-driven search. This is a material behavior mismatch because the primary resource and interaction mode differ: post URL analysis vs keyword search data retrieval.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明的核心能力是“快手关键词搜索获取实时搜索数据”,即面向搜索词的检索与趋势/热点分析场景。但代码并没有任何关键词参数、搜索接口或搜索结果处理逻辑。相反,它要求传入快手视频URL或视频ID,并调用 comment.createCommentTask / comment.getCommentTask 来抓取评论,最终返回评论列表。这属于与声明明显不同的主要功能,而不是实现细节差异。因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill does Kuaishou keyword-based search and returns real-time search data. However, the code clearly implements a 'post' retrieval flow for a Kuaishou creator profile: it requires a profile URL or USER_ID, validates profile URLs, calls createPostTask/getPostTask, and reports '获取作品任务完成'. There is no handling of search keywords, no search endpoint logic, and no evidence of collecting real-time keyword search results. Logging output to a file is a supporting detail, not the main issue. The primary purpose is materially different from the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向快手实时搜索数据采集/查询的技能,但代码片段实际只是通用参数解析与帮助文本生成工具。它没有执行关键词搜索、没有访问快手、没有发起网络请求、没有处理或返回搜索结果,因此其主要用途与声明严重不符。这不属于正常的辅助实现细节,因为当前代码本身仅体现 CLI 基础设施能力,未体现所声明核心功能。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的核心能力是“快手关键词搜索并获取实时搜索数据”,这通常意味着与快手相关的数据查询、抓取或接口调用。但提供的代码片段没有任何与快手、关键词搜索、网络请求、数据获取或内容分析相关的逻辑。相反,它只是在本地文件系统中安全化文件名并写入日志内容。这不是单纯的辅助细节,因为该片段体现的实际能力是本地日志持久化,属于与声明主用途明显不同的功能,并且涉及未声明的本地文件系统访问。因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill should obtain Kuaishou realtime search data for keyword-based research workflows. However, the supplied code chunk contains only a helper that reads package.json from the local filesystem and returns the package name. There is no search logic, no network access, no Kuaishou API interaction, and no handling of keywords or realtime data. This is a material mismatch in primary purpose and actual capabilities, not merely a supporting implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description promises a Kuaishou keyword-search capability that obtains real-time search data for research and trend analysis. However, the code chunk contains only helper functions for URL normalization, URL type checks (video/profile), and URL-to-name conversion. These are materially different from the declared primary purpose. While such utilities could support a broader Kuaishou tool, the supplied code itself does not implement the advertised search/data retrieval behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The declared scripts expose posting and commenting actions even though the skill is presented as a read-oriented search/research tool. This mismatch is dangerous because hidden write capabilities can be invoked to publish content or interact with user accounts, expanding the blast radius from passive data retrieval to unauthorized account actions or spam.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script’s behavior is materially broader than the declared skill purpose: it accepts a video URL/ID and retrieves comment data rather than keyword-based hot-search data. This kind of scope mismatch is dangerous because users and platforms may grant trust, permissions, or deployment approval based on the manifest, while the code performs a different data-collection function.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The CLI schema and downstream logic clearly implement creator profile/post retrieval via a profile URL or USER_ID, which does not match the skill's declared purpose of keyword-based realtime hotlist/search analysis. This kind of capability mismatch is dangerous because users and higher-level agents may invoke the skill expecting search-trend data but instead collect creator-specific content, causing unintended data access, policy bypass, and incorrect downstream decisions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The success/output path labels the operation as post-task completion and returns postTask results, reinforcing that the skill performs post retrieval rather than hotlist or trend analysis. In agent settings, this semantic mismatch can mislead orchestrators into trusting the output as realtime search intelligence, increasing the risk of unauthorized collection and bad automated actions based on the wrong dataset.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description limits the skill to '关键词搜索获取快手实时搜索数据', which reads as keyword-based retrieval of real-time search data. However, the file later documents three capabilities, including fetching a creator's public works and retrieving video comments, which materially exceed that narrower description.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

Lines L080-L093 explicitly constrain the skill to three capabilities and say its responsibility is only to fetch data. Earlier sections, however, promote broader functions like '趋势预测', 'KOL 筛选', '批量操作', and '多格式导出', creating active tension between the stated boundary and the claimed behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says this skill is for "关键词搜索获取快手实时搜索数据" and content research/trend observation use cases. In contrast, the package description and keywords advertise broader capabilities such as mining viral videos, monitoring competitors, screening high-value KOLs, precision marketing, and account growth, which expands the claimed behavior beyond the manifest's narrower search/hotlist scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The package description and keywords are entirely in Chinese, which indicates the skill is presented as Chinese-only without any visible opt-in, language selection, or justification for a region-specific restriction. Under the policy, language or locale constraints should either be user-selectable or clearly documented as necessary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README presents all user-facing instructions in Chinese and does not offer an alternative language or state that the skill is intentionally limited to Chinese-speaking users. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README materially expands the skill’s described behavior from keyword/hotlist search into broader account monitoring, comment extraction, KOL screening, and bulk public-data mining. This scope mismatch is dangerous because reviewers and users may grant permissions, trust, or deploy the skill under a narrower understanding than what its documentation and likely implementation support.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The usage examples document commands for profile-post monitoring and video-comment extraction even though the skill is positioned as a hotlist/keyword-search tool. Operational examples are especially risky because they indicate real supported behavior beyond the declared scope, enabling covert expansion into surveillance-style data collection without corresponding review.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The changelog states the skill can fetch creator works and comment data, which exceeds the declared scope of keyword search and hot-search analytics. This is dangerous because undocumented or under-declared data access broadens the effective permission and privacy surface, making it harder for reviewers and users to understand what the skill actually does.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all instructions, parameter descriptions, and examples exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or an explicitly justified regional constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes this skill as providing Kuaishou keyword search realtime search data for research and trend observation. However, this file documents additional capabilities for fetching a creator’s posted works and retrieving comments on specific videos, which materially expand the skill beyond keyword-search/hotlist retrieval.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a skill for Kuaishou keyword search and obtaining real-time search/hotlist data for research and trend observation. This file instead creates and queries comment-collection tasks for a content URL via /api/kuaishou/comment/* endpoints, which is a different data domain and broader than keyword hot-search retrieval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code sends the supplied url to a remote API via postJson and includes an authentication token, but the file provides no confirmation prompt, user-facing log, or explanatory comment/docstring warning that external transmission occurs. Because network/HTTP calls that transmit user or system data are in scope for code-file warning checks, this lacks visible disclosure in the code shown.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:15