Back to skill

Security audit

快手市场趋势洞察

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Kuaishou public-data research tool that uses a third-party API token and saves local result logs, with no evidence of hidden execution or unrelated access.

Install only if you are comfortable sending Kuaishou queries, profile/video URLs, and returned public data through guaikei.com using your GUAIKEI_API_TOKEN. Treat saved logs as retained copies of comments and research results, especially on shared or synced machines, and use the tool only for public data and lawful, platform-compliant analysis.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

从这段代码看,功能范围非常窄:只调用 /api/kuaishou/comment/url 和 /api/kuaishou/comment/info 两个接口,围绕评论任务创建与查询展开,输入是视频 url 和 limit,输出是评论数据数组。它与声明中的第(3)项“视频评论分析”基本一致,没有发现额外的越权能力或不相关资源访问。但声明将技能整体描述为一个包含三大能力的快手市场分析工具,而该代码片段并未实现视频关键词搜索或博主作品抓取,因此若将“声明是否准确代表该代码块实际行为”作为判断标准,则存在描述范围明显大于当前代码实际能力的情况。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向快手市场分析的数据采集与分析技能,包含明确的三类业务能力。但提供的代码片段只是配置常量,没有任何与数据抓取、搜索、分析、评论处理或快手接口访问相关的实现。从当前代码可见的实际行为与声明的核心功能严重不符,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

代码仅包含 args.js 工具函数:readValueAfterFlag、parseArgs 和 buildHelp,作用是解析命令行参数并生成帮助信息。这属于底层通用支持模块,不涉及快手平台访问、视频/达人/评论数据处理、市场规模分析、类目增长分析或达人结构分析。根据评估标准,若代码的主要行为与声明用途 materially different,则应判定为不匹配。虽然参数解析器可作为更大技能的配套实现细节,但就所给代码块本身而言,它没有实现声明中的任何核心能力,因此描述与行为不准确。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向快手市场/视频/达人分析的数据采集与分析技能,而实际提供的代码只是本地日志工具函数 taskWrite,使用 fs 和 path 在本地 logs 目录写文件。它既不访问快手平台资源,也不执行搜索、抓取、评论分析等核心能力。日志写入本身可视为辅助实现,但当前代码片段只包含该辅助能力,和声明的主要用途明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a feature-rich Kuaishou analysis/scraping skill with three concrete data-access capabilities. However, the supplied code chunk contains only utility functions for printing a banner and formatted logs to stderr. It does not access Kuaishou, perform searches, fetch profile works, retrieve comments, analyze interaction data, or implement any market opportunity/risk analysis. Because the actual code's purpose is merely support logging and not the declared functional behavior, this is a clear description-behavior mismatch for the provided chunk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description and the entire SKILL.md instruct agents and users exclusively in Chinese, which effectively forces a specific language/locale. The file does not offer an opt-in language choice or document a justified region-specific language requirement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest explicitly advertises creator-content scraping and public-comment retrieval but provides no warning about privacy, consent, platform Terms of Service, retention, or downstream handling of collected data. In a market-intelligence skill, normalizing large-scale collection of comments and creator data without disclosure increases the risk of misuse, noncompliant data processing, and unsafe deployment by downstream users who may treat the capability as approved and low-risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README says all task results are automatically saved to logs/, but does not clearly warn that fetched comments, content metadata, and potentially sensitive business research outputs may be written to disk. This can create unintended local data exposure, especially on shared systems, developer workstations, synced folders, or environments where logs are broadly accessible.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script persists the full comment retrieval output, including user-generated comment content and request metadata, to a local JSON file after already printing the result to stdout. In a market-insight skill, this creates unnecessary secondary storage of potentially sensitive or regulated data, increasing exposure through leftover files, broader filesystem access, backups, or later misuse beyond the user’s immediate request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code writes fetched comment data to disk without warning or consent, even though comments can contain personal data, identifiers, or sensitive user-generated content. Silent persistence expands the data lifecycle and attack surface, especially in shared environments where local files may be accessible to other users, processes, backup systems, or incident responders.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

User-facing descriptions, help examples, and runtime messages are presented in Chinese throughout the CLI, indicating a forced locale for interaction. The policy allows locale constraints only when users are given a choice or when the constraint is clearly documented and justified; this file does neither.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI persists fetched post data to a local JSON file after completing the request, which creates an additional data-retention surface beyond simply returning results to the caller. Because the scraped content may include public profile data and potentially comments or other collected content, silent local persistence can expose data to other local users, backup systems, or later unintended processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script writes scraped results to a local JSON file without any explicit user consent in this code path, which can surprise operators who expect transient retrieval only. Unannounced persistence increases privacy, compliance, and workstation exposure risks because scraped data remains on disk after command completion.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI writes full search output to a local JSON file named with user-supplied query data, creating persistent storage beyond the advertised read-only retrieval behavior. This can leak potentially sensitive research queries and retrieved data to disk, especially on shared hosts or agent runtimes where local artifacts are accessible to other users or later tasks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Search results are silently persisted to disk without clear user-facing disclosure in normal execution flow. Even if the data is not highly sensitive by design, saved result sets and query history can reveal business research interests, targets, or investigative activity, which increases privacy and operational risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This JavaScript file contains natural-language comments and user-facing CLI messages entirely in Chinese, including errors and help output. Under the stated policy, forcing a specific language without user opt-in or a documented locale-specific justification is a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JavaScript file contains multiple user-facing error messages in Chinese, such as the validation errors printed via utils.printError. Because the file does not offer language selection or indicate that the skill is intentionally Chinese-only for a justified regional context, it violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

SQP-3 covers language or locale policy violations across all file types. This README presents all user-facing instructions exclusively in Chinese and does not indicate that other languages are supported or that Chinese is a deliberate, documented regional constraint with user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The documentation frames the skill as a public-data Kuaishou analysis tool and explicitly says it does not involve obtaining user privacy data. However, L34 requires users to provision a GUAIKEI_API_TOKEN from an external vendor site, which indicates reliance on a third-party backend beyond merely reading Kuaishou public pages. This is a semantic expansion of behavior not reflected in the high-level safety/value framing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese, and there is no indication that users may choose another language or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

该技能描述聚焦于快手视频、博主和评论的数据分析能力,没有说明需要访问本地环境凭证。虽然调用外部数据接口本身对该场景是合理的,但直接从运行环境读取 GUAIKEI_API_TOKEN 属于额外的凭证访问能力,未在用途说明中体现。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest explains Kuaishou market-insight operations but does not mention credential handling or dependency on external service secrets. Reading process.env.GUAIKEI_API_TOKEN introduces secret access capability that is not user-visible and is not justified by the stated analysis scope alone.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file presents descriptions, help text, and status messages only in Chinese, with no option to select another language. That is a natural-language policy concern because it imposes a locale/language choice on all users rather than offering opt-in or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The manifest describes analytics-oriented Kuaishou data retrieval features, but does not mention credential handling or dependency on environment-secret access. While network access for the search itself is expected, reading secrets from process.env is an extra capability that is not stated in the declared purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.