Back to skill

Security audit

快手定向舆情监测助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a public Kuaishou data lookup tool that uses a disclosed third-party API and local result logging, with no evidence of hidden, destructive, or deceptive behavior.

Install only if you are comfortable sending Kuaishou keywords, profile URLs, video URLs, and request metadata to Guaikei using your GUAIKEI_API_TOKEN. Review or delete the generated logs directory when results include sensitive monitoring targets, competitor research, or collected comments.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向快手平台的数据采集与舆情分析技能,核心应包含对快手作品、达人主页、评论等资源的访问与分析逻辑。但提供的代码仅是 scripts/utils/args.js,一个通用 CLI 参数解析器,负责读取命令行参数、校验参数类型、处理帮助文本和生成 usage 信息。这类代码最多只是其他脚本的辅助基础设施,不构成所声明的三大核心能力,也没有显示出任何访问快手、抓取内容、分析评论或生成报告的行为。因此,基于当前代码片段,描述与实际行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README states that all task results are automatically saved to a local logs/ directory, but it does not warn users that the collected data may include sensitive business intelligence, user-generated comments, or monitoring targets. In the context of sentiment monitoring and competitor tracking, silent persistence increases the risk of unintended retention, local disclosure, and secondary misuse of scraped datasets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code sends the user-supplied target URL together with an API token to an external service to create and query a comment collection task, but the CLI flow shown here does not explicitly disclose that third-party transmission occurs. In a sentiment-monitoring skill that processes potentially sensitive investigative targets, undisclosed outbound transfer can create privacy, confidentiality, and compliance issues even if the transport is otherwise intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI persists fetched comment data to a local JSON file automatically after success, and this file may contain sensitive or regulated content such as usernames, comment text, interaction data, or other scraped public data. Silent local retention increases privacy, compliance, and data handling risk because users may not realize data is being stored on disk, where it can later be exposed through shared workstations, backups, or other local compromise.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes fetching Kuaishou works, comments, and generating sentiment/public-opinion analysis, but it does not mention local file persistence. Here the CLI writes the full output to disk via log.taskWrite, which is a material behavior beyond simple retrieval/output and could retain scraped data unexpectedly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI writes the full search output, including user-provided keywords and returned results, to a local JSON file by default. For a sentiment-monitoring tool, those queries and results may contain sensitive investigative topics, reputation-monitoring targets, or collected public data that should not be silently persisted, especially on shared systems or CI/agent environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends request parameters and JSON payloads over HTTPS and includes a TOKEN header, but there is no confirmation prompt, user-facing log, or explanatory comment/docstring warning that user or system data may be transmitted to an external service. Because network transmission and credential use are safety-relevant operations, the lack of disclosure meets the missing-warning criterion for code files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file's natural-language comments and user-facing warning/info strings are exclusively in Chinese, including operational messages shown to the user. Under the policy, forcing a specific language without user opt-in or a documented justification is a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits all validation error messages exclusively in Chinese, with no indication that users can choose another language or locale. That creates a natural-language policy issue because the skill forces a specific language in user-facing output rather than offering opt-in or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language instructions and usage guidance are entirely in Chinese, which can amount to forcing a specific language without user opt-in. The file does not state that the skill is China-specific or offer an alternative language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

Line L1 presents the skill documentation entirely in Chinese and names the skill in Chinese without any indication that language selection is optional or that the skill is intentionally region-specific. This can conflict with language/locale policy expectations when no user opt-in or justification is provided in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

该 markdown 文档从标题到参数说明、示例注释全部仅使用中文,未见提供其他语言选项、用户语言偏好说明,或对仅限中文的合理约束说明。根据语言/地区策略,这可能构成未经用户选择即强制特定语言的自然语言策略问题。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The function posts data to a remote API using both a user-provided URL and an authentication token, which is a safety-relevant network operation. In this file there is retry/error logging, but no confirmation prompt, warning message, or explanatory comment disclosing that this data will be sent externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This request transmits the provided URL and token to an external endpoint to retrieve comment task information. Although the operation fits the module's purpose, the file itself contains no user-facing warning, confirmation, or explanatory comment indicating that user data is being sent over the network.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest describes Kuaishou public-data retrieval and analysis capabilities, but this entrypoint also depends on a separate API credential from the environment. While network access is expected for this skill, credential harvesting from environment variables is not clearly justified by the stated end-user purpose in the manifest for a simple content-fetch CLI.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code persists the final output to disk via log.taskWrite, which is a file-write operation covered by the missing-warning rule for code files. While the script logs progress and prints results to stdout, it does not clearly disclose before writing that a local file named from the target profile will be created.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Search results are saved to a local JSON file without any explicit warning in this file, which can create an unexpected data retention channel. Even if the data is not secret by design, silent persistence increases exposure to other local users, backups, log collectors, or later unintended reuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

This JavaScript file contains natural-language comments and user-facing CLI messages entirely in Chinese, including thrown errors and help output. Because the file does not offer any language or locale choice, it enforces a specific language without user opt-in, which matches the policy-violation criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill emits user-facing status and error messages in Chinese only, such as the validation errors on these lines. This creates a language/locale policy issue because the file does not offer a language choice or document that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Multiple thrown error messages are written only in Chinese, such as '请求失败' and '请求超时', with no indication that the user can choose or opt into that locale. This can violate language/locale policy when a skill forces a specific language in user-visible output without user choice or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The thrown error string 重试${maxAttempts}次后失败 is hard-coded in Chinese. For a general utility module, this imposes a specific language on downstream users without offering a locale choice or documenting that the skill is intentionally Chinese-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The call to toLocaleString() emits timestamps using the system's default locale, while the surrounding user-facing text is hard-coded in Chinese. This creates an implicit locale choice without offering user opt-in or documenting a justified locale constraint, which falls under language/locale policy concerns.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.