Back to skill

Security audit

快手作品搜索

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a disclosed Kuaishou public-data search and analysis skill that calls a third-party API and saves results locally, with no evidence of hidden posting or destructive behavior.

Install only if you are comfortable sending Kuaishou keywords, profile/video URLs, request limits, and the GUAIKEI_API_TOKEN to guaikei.com. Expect returned public video, profile, and comment data to be saved locally in logs; clean those files when they are no longer needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (48)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is about searching Kuaishou works/videos and filtering/searching their metadata. However, the supplied code only creates and queries comment-related tasks using a Kuaishou URL and a limit. There is no evidence of keyword-based search, work discovery, ranking by likes, newest-post retrieval, duration filtering, or returning the declared work metadata fields. This is a material purpose mismatch, not just an implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description presents a user-facing KuaiShou作品搜索 tool centered on entering keywords and filtering/searching across works. The supplied code instead provides two helper functions: one to create a backend task from a KuaiShou post URL and another to query that task's result, with only url, sort, and limit parameters visible. This suggests a narrower URL-based post retrieval workflow rather than keyword search across KuaiShou content. While sort and limit loosely align with some ranking/list behavior, the main declared capability—searching by keyword with multiple content filters and displaying rich metadata—is not supported by this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的核心能力是“搜索快手作品”,输入应为关键词,输出应为作品列表及相关作品数据,并支持多种作品排序/筛选条件。而代码的输入是视频URL或视频ID,不接受关键词;其调用的是 comment 接口来创建和查询评论任务,结果也是评论数据而非作品搜索结果。因此该代码的主要用途与声明严重不符。附带的本地日志写入虽属实现细节,但在整体上更进一步表明其行为是评论抓取流程,而不是作品搜索。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says this skill searches KuaiShou works by keyword and supports multiple content-level filters and metrics for discovering hot content. The code instead is a command-line tool for retrieving posts from a specific KuaiShou profile or user ID. Its inputs are --url/USER_ID, --sort, and --limit; there is no keyword parameter and no logic for filtering by publish time, video duration, or similar dimensions. While 'latest' and 'most popular' overlap partially with the description, the overall primary purpose is materially different: user-profile post retrieval rather than general keyword-based work search.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is a KuaiShou content search tool for retrieving and filtering real-time KuaiShou works data. The supplied code instead only implements a reusable command-line argument parser and help-text builder. It does not query KuaiShou, process search keywords in a domain-specific way, fetch or display work metadata, or perform any of the promised filtering and result-link behaviors. This is a material purpose mismatch, not merely a supporting detail, because the provided code chunk is generic infrastructure unrelated to the declared primary functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向快手作品搜索与数据查询的技能,应体现搜索、筛选、获取作品元数据等行为。但给出的代码仅实现了本地日志文件写入功能,没有任何与快手、搜索、作品数据抓取、筛选、链接跳转或内容查询相关的逻辑。虽然日志记录可能是辅助功能,但当前提供的代码片段本身的实际用途与声明的核心目的明显不一致,并且涉及未声明的本地文件系统访问能力。因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向快手作品检索与数据查询的技能,应当包含网络请求、搜索参数处理、结果解析或至少与快手作品数据相关的逻辑。但给出的代码仅通过 Node.js 的 fs/path 读取本地 package.json 并返回技能包名,属于本地元数据读取辅助函数。该行为与宣称的核心用途明显不一致,也未展现任何与快手搜索相关的实现。因此应判定为描述与实际代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description claims a full Kuaishou作品搜索工具 with search and analytics capabilities. However, the supplied code only contains utility functions for printing a banner and log messages to stderr. While such logging helpers could support a larger application, this chunk by itself does not implement or evidence the declared core functionality. Therefore, the code behavior shown is materially different from the declared primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose centers on searching Kuaishou works and returning content data with multiple ranking/filter dimensions. The actual code does not perform any search, network access, data retrieval, or metadata handling. It is limited to helper-style URL normalization and classification for Kuaishou video/profile links and IDs, plus generating a filename-like string from a URL. That is a materially different primary purpose from the declared search/data-query tool, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The package manifest describes a search/data-query skill, but the scripts section exposes additional post and comment entry points that enable content-modifying actions. This mismatch increases the risk of deceptive capability expansion, where a reviewer or user expects read-only behavior but the package can also perform write actions against an external platform.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

A posting command similarly exceeds the expected read-only scope of a search/data tool and creates a hidden write capability. In the context of a social-media-related skill, this could be used to publish unauthorized content, support spam campaigns, or create account-reputation and policy risks for the operator.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

A commenting command is not justified by the stated purpose of searching and viewing Kuaishou works, and it introduces an unexpected ability to perform external side effects. If invoked by mistake or abuse, it could post unauthorized comments, spam content, or act on behalf of a user without clear consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a tool that searches KuaiShou works by keyword and supports filters like likes, publish time, and duration. This file instead requires a creator profile URL or user ID, creates a 'post task', and retrieves works for that specific profile, with only sort and limit options, which is a materially different capability from general keyword search.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description includes multiple broad trigger phrases such as generic Kuaishou search and hot-content terms, which may cause the skill to activate in situations broader than intended. Because the package also exposes unexpected posting and commenting scripts, accidental activation becomes more dangerous by increasing the chance that users interact with a skill whose true capabilities are not well-scoped.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README markets broader capabilities such as competitor monitoring, trend prediction, KOL screening, and comment analysis, which materially exceed the manifest’s narrower '作品搜索' description. This creates a scope-transparency problem: users and reviewers may authorize or install the skill for simple search while the skill is positioned to support more extensive data collection and monitoring workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatically writing collected outputs to disk without a clear warning is risky because search results, profile data, comment content, and URLs may accumulate locally outside the user’s awareness. Even if the source data is public, silent retention expands exposure through shared machines, backups, endpoint monitoring, and accidental redistribution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all user-facing instructions and parameter descriptions in Chinese only. Under the policy rule, forcing a specific language without user opt-in or a documented justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes this skill as a 快手作品搜索工具 for searching works by keyword and filtering/sorting search results. However, this file documents separate commands for fetching a creator's published works and retrieving comments for a video, which are materially broader capabilities than keyword search alone.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file implements creation and polling of comment-collection tasks for a specific Kuaishou URL, which exceeds the declared skill scope of searching and viewing Kuaishou works. Scope mismatch is dangerous because users and reviewers may authorize a seemingly narrow search tool while the code can access or facilitate collection of additional content types, increasing privacy and trust risks. In this context, the hidden capability makes the skill more suspicious because comment scraping is not necessary for the advertised functionality.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is described as a Kuaishou search/works metadata tool, but this CLI creates and retrieves comment tasks, expanding into collection of user-generated comment content. That scope expansion matters because comments may contain personal or sensitive data and users invoking a search tool would not reasonably expect comment harvesting behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI persists retrieved comments to a local JSON file without any explicit warning, opt-in, retention control, or sanitization. Because comment content can include personal data, handles, links, or abusive text, silent local storage increases privacy risk and may leave sensitive data behind on shared systems or agent hosts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code accesses process.env.GUAIKEI_API_TOKEN to obtain a token, introducing credential handling behavior not mentioned in the manifest. For a user-facing 'search KuaiShou works' skill, hidden dependence on environment-stored secrets is an additional capability outside the stated purpose unless explicitly declared.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes the full retrieved results to a local JSON file after successful execution, which can unnecessarily persist potentially sensitive usage data, creator information, and query context on disk. Because this storage happens automatically and without any visible consent or retention controls at the write site, it increases the risk of local data exposure on shared systems or in collected logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The tool silently writes collected results to a local JSON file without an explicit warning or consent prompt at the point of write. This can surprise users and create privacy or operational risk if the output contains sensitive business data, scraped content, or identifiable creator metadata on multi-user or monitored environments.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:15