Back to skill

Security audit

快手机会研究

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Kuaishou public-data research tool that uses a disclosed third-party API and saves results locally, with no evidence of hidden execution, credential theft, or destructive behavior.

Before installing, confirm you are comfortable sending Kuaishou keywords, profile/video links, and your GUAIKEI_API_TOKEN to guaikei.com. Treat the generated logs as retained research data and delete or protect them if they contain sensitive business targets or comment datasets.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill is presented as a Kuaishou research tool, but the reported behavior includes local filesystem writes, directory creation, and saving arbitrary string content. Undeclared file-writing behavior is dangerous because it expands the skill's effective capability beyond user expectations and can enable sensitive data persistence, log injection, or unintended overwriting of local artifacts. In an agent setting, hidden stateful writes also make review and containment harder.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a Kuaishou research tool, but the reported behavior includes local filesystem writes, directory creation, and saving arbitrary string content. Undeclared file-writing behavior is dangerous because it expands the skill's effective capability beyond user expectations and can enable sensitive data persistence, log injection, or unintended overwriting of local artifacts. In an agent setting, hidden stateful writes also make review and containment harder.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a Kuaishou research tool, but the reported behavior includes local filesystem writes, directory creation, and saving arbitrary string content. Undeclared file-writing behavior is dangerous because it expands the skill's effective capability beyond user expectations and can enable sensitive data persistence, log injection, or unintended overwriting of local artifacts. In an agent setting, hidden stateful writes also make review and containment harder.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a Kuaishou research tool, but the reported behavior includes local filesystem writes, directory creation, and saving arbitrary string content. Undeclared file-writing behavior is dangerous because it expands the skill's effective capability beyond user expectations and can enable sensitive data persistence, log injection, or unintended overwriting of local artifacts. In an agent setting, hidden stateful writes also make review and containment harder.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description is broad enough to trigger on generic requests about 快手 topics, growth, or user pain points rather than a narrowly scoped research task. Over-broad activation can cause the skill to be invoked unexpectedly, exposing scraping or data-collection capabilities in contexts where the user did not explicitly request them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Automatically saving collected data and user-supplied links/keywords to local files can create unintended data exposure on shared machines, developer workstations, or synced directories. Even if the source data is public, the aggregation itself and the user's research targets may be sensitive, and the README does not clearly warn users about this persistence behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code persists the full output, including the requested URL and retrieved comments, to a timestamped file via log.taskWrite. While the script reports task progress, it does not clearly disclose that data will be saved to disk, which matters because comment content and request details may be sensitive or unexpected to persist locally.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest and CLI help text state that the capability accepts either a 快手博主主页URL or a USER_ID, but the implementation validates input only with isProfileUrl() and exits on failure. This creates a direct description-behavior mismatch because one of the advertised input modes is not actually supported here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI saves fetched task results to a local file without any explicit warning or consent flow in this file, which can surprise users and create privacy and data-handling risks. Because the skill gathers public creator/content data and may include metadata users do not expect to persist, undisclosed local storage makes the behavior more dangerous in this context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a read-oriented research skill for analyzing Kuaishou search results, creator content, and comments. This helper function persists arbitrary caller-provided content to local disk under a chosen filename, which is not one of the declared user-facing capabilities and is not obviously necessary to perform the stated research tasks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple user-visible error strings are hardcoded in Chinese, such as 请求失败 and token validation messages. This imposes a specific language on users without offering a language/locale choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This utility sends JSON payloads over HTTPS and includes a TOKEN header, which means user or system data and credentials may be transmitted to an external service. In this file there is no confirmation prompt, user-facing log, or explanatory comment/docstring warning about that behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

All user-facing documentation in this skill file is presented in Chinese, and there is no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest frames the skill as a research tool for querying and analyzing Kuaishou data, with three core capabilities around search, creator posts, and comment analysis. The README adds persistent local result archival in logs/, which is a behavior beyond the user-facing description of returning structured data, even though it is related to the workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The changelog content and title are entirely in Chinese, which may imply a fixed language/locale for the skill documentation. The policy requires avoiding forced language constraints unless the skill offers language choice or clearly documents a justified locale-specific scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all user-facing instructions, parameter descriptions, and examples exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale policy issue when no alternative language option or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code contains user-visible retry and error messages in Chinese only, such as the retry notices and format-error text. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the skill is clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script writes fetched creator/work results to a local JSON file by default, which can retain potentially sensitive scraped data longer than the user expects. In a research/scraping skill context, silent persistence increases exposure to unauthorized local access, accidental sharing, or over-retention of collected platform data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code persists the full search output to disk via log.taskWrite(...), which is a file-write operation affecting user data handling. Although the script logs progress and mentions the API token in help text, it does not disclose that results will be saved locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains user-facing natural-language strings in Chinese, beginning with the module description and continuing throughout the parser's errors and help output. Because the skill does not provide any user opt-in or configurable locale selection, it can violate language/locale policy for users expecting another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits user-facing status and error strings only in Chinese, such as the validation errors on these lines. The file provides no opt-in, fallback, or documentation that the skill is intentionally Chinese-only, which conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The success and failure messages shown to users are also hardcoded in Chinese only. Because the file does not offer localization choices or justify a Chinese-only scope, this is a natural-language policy issue under the locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The thrown error string 重试${maxAttempts}次后失败 forces a specific language in a user-visible message. This is a natural-language locale policy issue because the file provides no option for user language selection and no documented justification for Chinese-only output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file contains user-facing Chinese text in the module comment and banner output, suggesting the skill presents itself in a fixed language. Under the policy rules, forcing a specific language without offering user choice or documenting a justified locale constraint is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.