Back to skill

Security audit

快手数据分析与市场调研

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently performs disclosed Kuaishou public-data research using a third-party API, with local result logging that users should manage carefully.

Install only if you are comfortable sending Kuaishou keywords, URLs, requested limits, and your GUAIKEI API token to the guaikei.com service. Treat saved logs as retained research data, especially when they contain public comments or creator metadata, and delete or protect them according to your privacy and platform-compliance needs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码片段仅实现了一个通用参数解析模块(parseArgs、readValueAfterFlag、buildHelp),其功能是处理命令行输入并生成帮助信息。这与声明的业务能力——快手视频搜索、达人作品抓取、评论分析和市场研究——没有直接对应关系。虽然这类工具代码可能作为更大系统的辅助组件存在,但就当前提供的代码片段本身而言,实际行为并未体现声明中的核心能力,因此描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Yes, this code chunk does not match the declared purpose. The description claims substantive KuaiShou analytics capabilities, but the supplied code only contains auxiliary logging/CLI display functions. While support utilities themselves are not problematic, this chunk alone does not perform any of the declared core behaviors. Therefore the code's actual behavior is materially different from the declared primary purpose for this supplied chunk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is entirely in Chinese and presents the skill's invocation and usage policy only in that language, with no indication that users may choose another language or locale. This can violate language/locale policy expectations when the surrounding agent environment may serve multilingual users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The operational guidance, trigger rules, examples, and support instructions are all written in Chinese, and the file does not explicitly offer a language choice or state that the skill is intentionally limited to Chinese-speaking users. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description is broad enough to activate on generic mentions of KuaiShou, market research, product selection, or trend analysis without clearly constraining when the skill should run. In an agent environment, over-broad activation can cause inappropriate tool invocation, unnecessary data access, or the model routing user requests into this skill when the user did not explicitly ask for it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description is written entirely in Chinese and implies Chinese-language behavior without indicating locale scope or fallback behavior. In a multilingual agent setting, this can cause mismatched language responses, user confusion, or unintended routing for users who mention KuaiShou in another language and do not expect Chinese-only handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not warn users that scraped video metadata, comments, or other public-content extracts may be retained locally. In a data-scraping and comment-analysis skill, silent persistence increases the risk of unnecessary collection, leakage, or over-retention of potentially sensitive or regulated content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation explicitly instructs users to collect Kuaishou post and comment data, including bulk retrieval up to 10,000 records, but provides no privacy, consent, retention, or platform-terms guidance. In a skill focused on market research and comment analysis, this omission can encourage indiscriminate scraping and downstream misuse of user-generated content or personal data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code persists the full task output to disk via log.taskWrite, creating a JSON file that includes request details and returned results. Although writing logs may be part of the tool's implementation, there is no visible disclosure at the write site or earlier in this file that execution will save data locally, which can affect user data handling expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file presents descriptions, help text, errors, and status messages only in Chinese, with no option to select another language or locale. That is a natural-language policy concern because the skill imposes a specific language rather than offering user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI writes the full search request and returned results to a local JSON file, which creates persistent storage of potentially sensitive research queries and data outside the user-visible primary output path. In a skill described as search/analysis functionality, undisclosed local persistence increases data exposure risk through accidental retention, later access by other local users/processes, or collection by other tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Search results are silently written to a local file without any user-facing warning in this file, so users may reasonably believe the tool is only printing results to stdout. That lack of transparency undermines informed consent and can expose sensitive keywords, market research, or returned content to unintended local disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Multiple error strings in this file are hard-coded in Chinese, which enforces a specific language for user-visible messages. There is no indication that the user can choose the language or that the locale restriction is documented as intentional and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code constructs and sends an outbound HTTPS POST request including a TOKEN header and JSON payload, which can transmit user or system data to a remote service. In this file there is no confirmation prompt, logging, or explanatory comment/docstring disclosing that this network transmission occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This function performs an outbound HTTPS GET request and includes the TOKEN header, transmitting credentials and query parameters to an external endpoint. The file does not provide any visible warning, prompt, or explanatory comment describing this network behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

SQP-3 covers natural-language policy violations across all file types, including language or locale restrictions without opt-in. The README is entirely in Chinese and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience for compliance reasons.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

All user-facing instructions in this file are presented only in Chinese, with no indication that the language is optional or that the skill is intentionally limited to Chinese-speaking users. This can violate a language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This code sends a token plus the provided URL and limit to an API endpoint via postJson, which is a data-transmitting network operation. The file contains retry logging for failures, but no confirmation prompt, warning, or explanatory comment/docstring disclosing that user-provided data and authentication material are sent to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This code performs an outbound POST request using a user-supplied URL and authentication token, which is a safety-relevant operation because it transmits user or system data to an external API. While retry errors are logged, there is no confirmation prompt, warning comment, or user-facing disclosure in this file describing that the URL and token will be sent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This function sends the provided URL, sort, limit, and token in an outbound request to retrieve task information. The operation is visible in code, but there is no confirmation prompt, explanatory comment, or other user disclosure in this file that these values are transmitted to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This code sends search parameters and an authentication token via HTTP requests in both createSearchTask and getSearchTask. While retry errors are logged, the file provides no confirmation prompt, comment, or user-facing notice that network transmission of user-provided search terms and token-backed requests will occur.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The manifest describes analytical capabilities over KuaiShou data, but does not mention use of external API credentials. Although authentication may be an implementation detail, accessing process environment for a secret is a capability beyond the explicitly stated user-facing scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The CLI writes the full fetched comment results to a local JSON file without any user-facing disclosure in the described skill behavior. Comment data can contain personal information, usernames, or sensitive business research output, so silent persistence increases privacy and data-handling risk, especially on shared machines or multi-user environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI's descriptions, help examples, errors, and status messages are all presented in Chinese, which imposes a language choice on users. Under the policy, forcing a specific language without opt-in or justification is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.