Back to skill

Security audit

GUAIKEI快手社媒数据复盘

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Kuaishou public-data API client that uses a configured third-party token and saves results locally for analysis.

Install only if you are comfortable sending provided keywords, Kuaishou URLs or IDs, request parameters, and your GUAIKEI_API_TOKEN to www.guaikei.com. Review or delete the local logs directory if saved search, post, or comment results should not be retained, and use collected public social-media data only within applicable platform, privacy, and organizational rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向快手社媒数据采集与分析的技能,但提供的代码片段仅是本地日志写入辅助模块。它操作的是本地文件系统(创建 logs 目录并写文件),没有任何网络请求、快手接口调用、数据抓取、评论分析、作品搜索或统计分析逻辑。虽然日志模块可能作为某个更大系统的辅助组件存在,但就该代码片段本身而言,其行为与声明的核心用途明显不一致,因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a feature-rich Kuaishou data collection and analysis skill. However, the supplied code chunk is only a utility module for terminal output formatting and logging. While utility code can support a larger system, this chunk by itself does not implement or evidence any of the claimed core capabilities. Therefore, the supplied code does not accurately represent the declared purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file consistently presents the skill description, trigger guidance, execution rules, and support information only in Chinese. This effectively forces a specific language for use and interpretation without documenting user choice or a justified locale restriction, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation explicitly supports scraping public creator works and comment data at scale, but provides no guidance on privacy, consent, retention, or platform terms. In a social-media analysis skill, that omission materially increases the risk of misuse for unauthorized profiling, bulk data collection, or policy-violating surveillance workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The code reads process.env.GUAIKEI_API_TOKEN and then calls remote comment APIs with the token, URL, and limit. This involves sensitive credential access and network transmission, but this file does not clearly warn the user that an environment token will be used and that request data will be sent to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI persists fetched comment data to a local JSON file automatically after successful execution, without any consent prompt, opt-in flag, or indication of storage location/retention. In this skill’s context, comment data and associated metadata may be sensitive or regulated, so silent local persistence increases the risk of unintended disclosure on shared systems, later exfiltration, or improper retention.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI writes full results to a local JSON file without prior notice, creating silent data retention. In a social-media analysis skill, fetched posts and associated metadata may be sensitive in operational contexts, and undisclosed logging can leak data to other local users, backups, or later processes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes capabilities for searching videos, fetching public creator works, and analyzing video comments/data, but does not indicate any need to handle local secrets or credentials. At L113 the code pulls GUAIKEI_API_TOKEN from the environment, which introduces credential access behavior beyond the user-visible scope of a simple analytics/search skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The calls to search.createSearchTask and search.getSearchTask send user-provided query data over the network, which falls under network/HTTP operations that transmit user data. Although the command's purpose is search, this file does not clearly disclose that entered keywords and filters are sent to an external service; the only nearby notice is that an API token must be configured.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script writes fetched search results to a local JSON file without any apparent consent, retention control, or sensitivity checks. Even if the data is 'public' platform data, local persistence can create unintended data retention, exposure to other local users/processes, and accumulation of potentially sensitive analysis inputs or outputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Search results are silently written to disk after execution, which violates user expectations for a search CLI that primarily appears to print JSON to stdout. This can leak queried content or derived results to local storage where other users, backup systems, or monitoring tools may access them.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code returns multiple natural-language messages such as "请求失败", "响应解析失败", and "GUAIKEI_API_TOKEN 无效, 请检查环境变量" directly to users. Because the skill forces a specific language in user-visible strings without opt-in or justification, it conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The package description is written entirely in Chinese and does not indicate that the skill is region- or language-specific, nor does it offer users a choice of language. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

A natural-language policy issue exists when a skill effectively forces a specific language without opt-in or justification. This file presents all instructions and parameter explanations only in Chinese, with no note that the skill is intended for a Chinese-speaking audience or any alternative language option.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The script reads an API token from an environment variable, which means it accesses credentials not mentioned in the stated skill behavior. This is common operationally, but without clear disclosure it can surprise users and expands the skill's access to authenticated services, increasing the blast radius if the skill or its dependencies are misused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

Reading a secret from process.env without explicit user-facing disclosure is a transparency and trust issue for a skill that appears to perform data retrieval. In the context of an agent skill, undocumented credential use can cause operators to grant more trust and access than intended, even if the code does not directly exfiltrate the token in this file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The CLI persists fetched creator-work results to a local JSON file after completing the request, but this behavior is not disclosed in the command help or obvious user-facing flow. Even if the data is nominally public, local persistence increases data-retention and privacy risk, especially on shared systems or when output contains more metadata than the operator expects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI descriptions, help text, and runtime messages are written in Chinese only, which can constitute a language/locale policy issue when no opt-in or locale selection is provided. The file does not indicate that this is a region-specific tool or provide an alternative language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This utility's natural-language interface is entirely Chinese, including comments, thrown errors, and help text. The file does not offer a language choice or document that it is intentionally limited to a Chinese-only context, which matches the policy category for language or locale constraints without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code uses Chinese-only user-facing error messages and success text, such as the strings on lines 7, 11, 35, and 37. Under the policy for natural-language violations, forcing a specific language without user opt-in is a reportable issue unless the locale restriction is explicitly documented and justified, which is not shown in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The thrown error string is hard-coded in Chinese (重试${maxAttempts}次后失败). This creates a language/locale policy issue because the skill emits a specific language regardless of user preference, and there is no indication of opt-in or justified region-specific scope in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file contains user-facing text entirely in Chinese, including the module description and printed banner. The provided policy requires flagging language or locale constraints when a skill appears to force a specific language without offering a user choice or documenting the constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits all validation errors in Chinese-only strings, which imposes a specific language on users without any visible opt-in or documented locale restriction. The policy applies to all file types, and these user-facing literals indicate a natural-language locale constraint embedded in code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.