Back to skill

Security audit

快手社媒搜索与分析

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Kuaishou public-data lookup tool that uses a declared API token and saves results locally, with no evidence of hidden execution, account control, or exfiltration beyond the disclosed third-party API use.

Install only if you are comfortable sending Kuaishou search terms, video/profile URLs, and your GUAIKEI_API_TOKEN to guaikei.com. Also expect fetched public results, including comments and usernames returned by the API, to be saved under the skill's logs directory after each run.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

代码内容仅包含 scripts/utils/args.js,一个通用参数解析模块:读取 flag 后的值、校验数字类型、处理布尔参数、默认值、重复参数、位置参数、未知选项,并生成帮助文本。它没有任何网络请求、快手平台访问、视频/评论数据处理、达人主页抓取、搜索排序或互动趋势分析逻辑。因此,实际行为与声明的核心功能明显不符。这不是单纯的底层支持细节,因为当前提供的代码块本身只体现了 CLI 工具能力,而未体现任何所声明的快手社媒检索能力。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向快手公开内容检索与分析的技能,核心能力应围绕网络搜索、内容抓取、数据分析等。但提供的代码片段实际只是一个本地日志写入模块,使用 fs/path 在本地文件系统创建目录并写入文件,不包含任何快手相关请求、搜索、作品抓取、评论分析或社媒数据处理逻辑。虽然日志功能可能是辅助实现细节,但当前代码片段本身的行为与声明能力完全不相符,且体现了未在声明中提及的本地文件写入能力,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest description says to use the skill whenever a user wants to check public performance for brands, topics, events, or content on Kuaishou, but it does not define specific trigger phrases, boundaries, or negative examples. In a manifest file, this broad natural-language invocation guidance can cause unintended activation because many common research requests could match it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README forces a specific language/locale for all users through its natural-language instructions and descriptions. Under the policy, language constraints should either offer user choice or be clearly documented as a justified region-specific limitation, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese, and there is no note that the skill is China/Chinese-only or that users may choose another language. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI persists the full fetched comment dataset to a local JSON file after returning results, which expands data exposure beyond the skill's stated behavior of returning public Kuaishou comment data. Even if the source data is public, comments can contain usernames, text, and interaction metadata that may be unintentionally retained on disk, leaked to other local users/processes, or collected later without the operator realizing persistence occurred.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI writes full search output to a local JSON file named with the queried keyword and parameters, creating persistent storage of user queries and retrieved content. This can leak sensitive research topics, search terms, or collected data to other local users, backups, or downstream tooling, especially because persistence is not essential to the stated real-time search behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The program silently persists search results and embeds the keyword in the filename without a user-facing warning or consent. Even if the content is public social media data, the user’s search intent and collected dataset may be sensitive, and unexpected local storage increases privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a skill for searching and analyzing public Kuaishou content, which is a read-oriented data retrieval task. This utility creates directories and writes caller-controlled content to local files under a logs directory, which is a local persistence capability not needed by or declared in the stated purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code returns multiple natural-language error messages such as "请求失败", "响应解析失败", and "GUAIKEI_API_TOKEN 无效, 请检查环境变量" only in Chinese. Because the file does not provide any language selection, fallback, or documented region-specific justification, it violates the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits user-visible warning and informational text only in Chinese ("警告: 你的 GUAIKEI_API_TOKEN 未正确配置" and "已使用配置的私有TOKEN"). Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The heading presents the skill documentation in Chinese only, and the file does not indicate that users may choose another language or that the locale restriction is intentional. This can conflict with a language/locale policy requiring user choice or explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The retry log string at L19 is written only in Chinese, and similar user-facing text appears elsewhere in the file. This can violate language/locale policy when the skill does not provide user opt-in or clearly document that it is intended only for a Chinese-language context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The thrown error message at L38 is natural-language text in Chinese only. Without an explicit locale restriction or user language choice, this is a natural-language policy concern rather than a code defect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The retry log string at L45 is user-visible natural-language text in Chinese only. The file provides no indication that users can opt into this language or that the skill is limited to a Chinese-language setting.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The manifest presents the skill as a Kuaishou public-content search and comment-analysis tool, but does not mention dependence on external service credentials. While authentication may be operationally necessary, reading a secret from the environment is an additional capability not justified by the user-facing purpose alone.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI silently writes fetched comment data to a local JSON file without requiring explicit user consent or prominently warning about persistence. This can surprise users who expect a transient command result, and it increases the chance of local data accumulation, privacy issues, or accidental disclosure through backups, shared machines, or later file collection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code persists the full task output to disk via log.taskWrite, which is a file write operation covered by the warning requirement for code files. Although the script logs progress and prints the fetched URL, there is no visible disclosure here that results will be saved locally under an autogenerated filename.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest describes a skill for searching public Kuaishou content, creator posts, and comments. In this file, the code explicitly accesses process.env.GUAIKEI_API_TOKEN to obtain credentials, which is an operational capability beyond the stated end-user purpose and not mentioned in the manifest text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JavaScript file contains natural-language strings intended for end users entirely in Chinese, beginning with the file description and continuing throughout errors and help output. Because the skill does not offer a language/locale option or document that it is intentionally region-specific, it may violate language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code emits user-facing status and error messages only in Chinese, such as the validation errors on these lines. That imposes a specific language on all users without any opt-in or documented region-specific justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The thrown error string 重试${maxAttempts}次后失败 is hard-coded in Chinese, which imposes a specific language in user-visible output. The file does not offer a language choice or document a justified locale restriction, so this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JavaScript file contains natural-language strings and comments in Chinese, including the banner text shown to users. Because the skill does not provide any opt-in or alternative locale handling, it may violate a language/locale policy requiring user choice or explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JavaScript file contains multiple user-facing error strings in Chinese, such as at L05, L10, L14, L18, L23, L50, L54, L59, and L64. Because the skill does not provide any user opt-in, locale selection, or justification that it is intended only for a Chinese-speaking region, it may violate the language/locale policy for natural-language behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.