Back to skill

Security audit

快手达人发现与洞察

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Kuaishou public-data lookup tool, with expected third-party API use and local result logging.

Before installing, confirm you trust guaikei.com with your Kuaishou queries and API token. Be aware that successful runs save full JSON results locally under logs, so clear those files if the search terms, creator targets, or comment data are sensitive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (28)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill requires access to a sensitive environment variable (GUAIKEI_API_TOKEN) but does not declare an explicit tool scope such as permissions or allowed-tools. That omission weakens least-privilege guarantees and can cause the runtime or calling agent to grant broader capabilities than necessary, increasing the risk of unintended secret exposure or misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README presents all user-facing instructions and operational guidance exclusively in Chinese. Under the policy, forcing a specific language without offering the user a language or locale choice is a natural-language policy violation unless clearly justified as region-specific, which is not stated here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest limits the skill to three capabilities: keyword video search, creator post retrieval, and video comment analysis. The README claims additional outcome-level capabilities such as '趋势预测' and '竞品监控', which imply broader analytical or monitoring functions not stated in the manifest and therefore overstate what the skill is for.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes on-demand retrieval and analysis of public Kuaishou data, but these lines describe persistent monitoring and trend tracking use cases such as competitor monitoring and scheduled capture of newly published content. That is a semantic expansion of scope beyond the manifest's stated three abilities.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script writes fetched comment-analysis results to a local JSON file after completing the requested operation, but this persistence is not disclosed in the stated read/analysis behavior. Comment data can contain personal or sensitive user-generated content, and silent local retention increases the risk of unintended exposure, over-collection, or later misuse on shared systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script stores retrieved comment data to a local JSON file without explicit user notice or consent in the command flow. Because comments and interaction data may include personal information or sensitive content, undisclosed storage creates privacy and compliance risk, especially on multi-user machines or automated environments.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script persists fetched post results to a local JSON file automatically, even though the primary stated function is data retrieval and analysis. This can create unintended local data retention of scraped content and metadata, increasing the risk of sensitive or regulated data being exposed to other users, backups, or later compromise of the host system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code writes fetched post data to a local JSON file without user confirmation or an obvious disclosure in this file. In the context of influencer discovery and comment analysis, stored output may contain personal data, content metadata, or business-sensitive research, so silent persistence increases privacy and data-governance risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI writes the full search output to a local JSON file named with the keyword and query parameters. This creates persistent storage of potentially sensitive business research data and exceeds the apparent user expectation of a search/read-only operation, increasing exposure to local disclosure through shared workstations, backups, or later collection by other processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script silently writes both query details and returned results to disk without explicit notice in the execution flow. Because this skill is used for influencer discovery and competitive research, stored keywords, links, and analytics may reveal user intent, campaign planning, or other commercially sensitive data to anyone with local access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Multiple user-visible error strings in this file are written only in Chinese, with no mechanism for locale selection or user opt-in. That creates a language policy issue because the skill forces one language for runtime messaging regardless of user preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code emits user-visible warning and info messages only in Chinese ("警告: 你的 GUAIKEI_API_TOKEN 未正确配置" and "已使用配置的私有TOKEN"). For a general-purpose skill utility file, forcing a specific language without user opt-in can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file’s natural-language instructions, descriptions, and examples are consistently Chinese-only, which can impose a language constraint on users without stating that the skill is region- or language-specific. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

As a manifest file, this description falls under vague-trigger review. The description says the skill supports discovering Kuaishou creators 'through natural language' and a wide range of analysis tasks, but it does not define what requests should or should not invoke the skill, which can lead to overly broad routing for common research or analysis queries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file presents all usage instructions, parameter descriptions, and examples only in Chinese. Under the policy for natural-language issues, forcing a specific language without user opt-in can be a locale-policy violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This code sends the provided url to /api/kuaishou/comment/url and includes an authentication token, but the file contains no confirmation prompt, user-facing notice, or explanatory comment about transmitting that data to an external API. Because this is a code file, safety-relevant network transmission should have some visible disclosure unless clearly covered elsewhere in the skill description or strongly implied by the skill's stated purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The getCommentTask function performs a network request to /api/kuaishou/comment/info containing the user-supplied url and authentication token, but there is no user-facing disclosure, prompt, or comment noting that this data is transmitted. Under the code-file criteria, outbound data transmission without any visible warning is a reportable quality/safety issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code performs an HTTP POST that transmits user-provided search data and an authentication token, but the file contains no confirmation prompt, user-facing notice, or explanatory comment about that transmission. Under the code-file criteria for SQP-2, network calls that send user or system data should have some visible disclosure unless the warning is provided elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This function sends keyword, sort, time, duration, limit, and a token to a remote endpoint, but there is no prompt, visible notice, or explanatory comment in the file describing that data transmission. That matches the missing-warning criterion for code files involving network calls that transmit user or system data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest explains content discovery and comment analysis features, but does not mention credential handling or dependence on environment-provided secrets. While this may be an implementation detail, accessing process environment for authentication is a capability outside the stated end-user purpose and should be declared if part of the skill's operational model.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes Kuaishou creator/video/comment discovery features, but does not mention handling local credentials or reading process environment variables. This file directly accesses process.env.GUAIKEI_API_TOKEN, which is an extra capability beyond the user-facing discovery purpose, even if it is used to authenticate the backend request.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The manifest focuses on Kuaishou search, creator-work retrieval, and comment analysis, but does not mention accessing environment-based credentials. While authentication may be operationally necessary, reading process.env.GUAIKEI_API_TOKEN is an additional capability not justified by the stated natural-language purpose alone.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This utility emits all user-facing errors, warnings, and help text in Chinese, such as at L007-L012, L090-L103, and L128-L135. That forces a specific language/locale for all users without offering a language choice or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This helper sends JSON payloads over the network and includes a TOKEN header, but there is no confirmation, logging, comment, or other user-visible disclosure in the file indicating that request data and credentials will be transmitted to an external service. For a shared request utility, this is a safety-relevant operation that is not self-disclosed here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The getJson helper constructs a URL with query parameters and sends it together with a TOKEN header to a remote host, but the file provides no visible disclosure or warning that user/system data may be transmitted externally. This is a network/data-transfer behavior that should be documented or surfaced to users unless already clearly disclosed elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.