Back to skill

Security audit

快手竞品洞察分析

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Kuaishou public-data lookup tool that uses a third-party API and saves results locally, with those behaviors broadly disclosed.

Install only if you are comfortable sending Kuaishou search terms, profile links, video links, and query parameters to guaikei.com using your API token. Protect the GUAIKEI_API_TOKEN and remember that returned results are saved locally under logs, which may contain sensitive research targets or comments.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向快手竞品分析的数据工具,核心应涉及对快手视频、达人主页或评论数据的获取与分析。而提供的代码仅是一个通用参数解析模块,负责处理命令行输入、校验参数、生成帮助文本和报错。它没有网络请求、没有快手相关 API/页面访问、没有数据抓取、没有分析处理,也没有实现声明中的三大功能。因此该代码片段的实际行为与声明用途存在明显且实质性的不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是面向快手竞品分析的数据获取与分析能力,而实际代码片段并未实现任何关键词搜索、作品抓取、评论分析或平台流量洞察逻辑。它的功能仅是将内容写入本地日志文件。虽然日志记录可能属于内部辅助实现细节,但当前提供的代码片段本身与声明的三项核心能力没有直接对应关系,且涉及未声明的本地文件系统写入能力。因此,该描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The instruction line addresses the agent in Chinese and requires it to follow the described usage pattern, while the overall skill content is entirely Chinese and does not mention any option for another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README requires users to obtain and use a third-party API token but does not clearly warn that user-supplied keywords, profile URLs, and video links will be transmitted to an external service. In a competitive-intelligence and monitoring tool, those inputs may reveal business strategy, target lists, or research interests, so the omission can mislead users about data exposure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes this capability as obtaining comment content and interaction metrics from a video link, which implies retrieval and output of analysis data. Here, the code additionally writes the full result set to disk via log.taskWrite, creating local persistence that is not described in the skill's stated capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code persists the full output, including request metadata and retrieved comments, to disk via log.taskWrite. Although the script prints status messages, there is no user-facing warning or confirmation here that execution will create a local file containing collected data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI persists the full fetched results to a local JSON file after completing the request, which creates an additional data-retention channel beyond the advertised network fetch capability. Because creator-work data and associated metadata may be sensitive in enterprise or multi-user environments, silent local persistence can expose data to other local users, backup systems, or later unintended reuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script writes fetched result data to a local JSON file without any explicit user consent or warning in this file, creating unintended persistent storage of potentially sensitive competitive-analysis data. This increases the risk of data leakage through shared disks, developer workstations, CI runners, or endpoint backup/telemetry systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code presents all user-facing descriptions, help text, status messages, and errors in Chinese only. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not present in this file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI persists full search output to a local JSON file, including user-supplied keywords and returned competitor-analysis data, even though the skill is described as a retrieval/analysis tool rather than a data-retention tool. This creates an unnecessary local data trail that can expose sensitive research activity, leak commercially sensitive intelligence to other local users/processes, or violate least-privilege expectations if logs are stored without user consent or retention controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JavaScript file contains natural-language comments, error messages, and help text entirely in Chinese, including all user-facing CLI output. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This manifest contains user-facing natural-language fields such as the description and keywords exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or justification can be a locale-policy violation, and no alternative language or documented regional limitation is provided here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The entire skill description and operating instructions are presented only in Chinese, with no indication that users may choose another language or that the restriction is required for a region-specific compliance reason. This can violate language/locale policy where user-facing skills must not force a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

该 markdown 文件标题及全部说明内容均以中文呈现,未见任何关于语言选择、用户可切换语言,或该技能仅面向中文用户/区域场景的说明。根据规则,未提供用户选择或明确合理化的语言限定,属于自然语言层面的语言/locale 策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The retry error message is hard-coded in Chinese, which imposes a specific language on users without any opt-in or indication that the skill is intentionally region-specific. This matches the language/locale policy violation category for natural-language content in code string literals.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The thrown error message is hard-coded in Chinese, creating a language-specific user experience with no visible opt-in or documented justification in this file. Natural-language policy checks apply to string literals in code, so this is in scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This retry status message is hard-coded in Chinese and provides no mechanism for locale choice. That constitutes a language/locale policy issue under the natural-language policy rule for all file types.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest focuses on competitor insight functions such as searching videos, fetching creator works, and analyzing comments. Accessing process.env.GUAIKEI_API_TOKEN introduces credential handling that is not user-visible or described as part of the tool's scope, even though it may support backend API access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest focuses on competitor-analysis functions over Kuaishou content, but does not mention handling local credentials or environment-based authentication. Accessing process.env.GUAIKEI_API_TOKEN is an additional capability beyond the user-facing analytical purpose, even if likely used to call a backend service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits user-facing validation and status/error messages only in Chinese, such as the filename/content errors and save-status text. The applicable policy flags language or locale constraints when they are imposed without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The thrown error string is hard-coded in Chinese ("重试...次后失败"), which imposes a specific language on users regardless of their locale or preference. This is a natural-language policy issue because the file provides no opt-in, localization mechanism, or documented justification for the language constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The user-facing warning and info strings are written only in Chinese, which imposes a specific language on users without any visible opt-in or documented locale restriction. Under the policy rule, hard-coded language in natural-language output can be a locale-policy violation when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits multiple user-facing validation errors in Chinese, which effectively forces a specific language for interaction. The file does not provide an opt-in, fallback, or documented region-specific justification, so it appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.