Back to skill

Security audit

快手选题分析

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Kuaishou public-data research skill that uses a disclosed third-party API and local result logs, with some privacy and robustness caveats.

Install this only if you are comfortable sending Kuaishou search terms, profile/video URLs, and token-authenticated requests to guaikei.com, and with returned JSON data being saved locally in logs. Avoid sensitive campaign or client research terms unless your organization approves that external API use and local retention.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/utils/request.js:14
Finding

Unbounded HTTP Response Buffering Enables Memory Exhaustion

Content
View full analysis
(body += chunk)); ``` ### Technical Analysis The shared HTTP client accumulates every response chunk in an in-memory string without enforcing a maximum response size. JSON parsing occurs only after the complete response has been received. All search, post, and comment API operations use this request function. A compromised, malicious, malfunctioning, or unexpectedly verbose API endpoint could therefore return an excessively large response and cause uncontrolled memory consumption. The configured request timeout limits request duration but does not reliably limit the total response size received within that interval. Because response parsing and certain response failures are retryable, repeated attempts may reproduce the resource exhaustion unless oversized-response errors are explicitly marked as non-retryable. ### Attack Path 1. A user or Agent invokes a search, post, or comment command. 2. The Skill sends an HTTPS request containing the relevant parameters to the fixed API host, `www.guaikei.com`. 3. The API endpoint, or infrastructure serving it, returns an excessively large response body or continuously sends data within the timeout window. 4. The `data` handler repeatedly appends incoming chunks to `body`. 5. Process memory usage grows without an application-level bound. 6. The Node.js process experiences severe memory pressure or terminates with an out-of-memory error. 7. If the failure is considered retryable, subsequent attempts may repeat the memory consumption. ### Impact Assessment This vulnerability does not grant additional operating-system privileges, arbitrary code execution, or access to unrelated credentials. Its primary impact is availability: - Termination of ...[truncated 524 chars]
Remediation
View remediation
{ receivedBytes += Buffer.byteLength(chunk, "utf8"); if (receivedBytes > MAX_RESPONSE_BYTES) { const err = new Error("API response exceeds the permitted size"); err.code = "ERR_RESPONSE_TOO_LARGE"; err.nonRetryable = true; req.destroy(err); return; } body += chunk; }); ``` ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill claims to perform Kuaishou research but instead reads a local package.json, that is an undocumented local file access behavior. Even though reading package.json is low sensitivity by itself, deceptive undeclared file reads violate least surprise and can become dangerous if the same pattern is used to access other local files or if users run the skill in sensitive workspaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill claims to perform Kuaishou research but instead reads a local package.json, that is an undocumented local file access behavior. Even though reading package.json is low sensitivity by itself, deceptive undeclared file reads violate least surprise and can become dangerous if the same pattern is used to access other local files or if users run the skill in sensitive workspaces.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest and instructions are entirely written in Chinese and all example prompts, warnings, and operational guidance assume Chinese-language interaction. There is no statement that the skill supports other languages, offers language choice, or is intentionally restricted to Chinese for a documented regional-compliance reason.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description is very broad and can match generic content-planning or research requests without clearly scoping when the skill should or should not activate. This increases the chance of over-invocation, causing the agent to route ordinary planning tasks into a data-collection/social-platform analysis skill unnecessarily, which can expose users to unintended scraping, platform-specific actions, or irrelevant data processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README instructs users to obtain and configure a third-party API token and use commands that submit keywords, profile URLs, and video URLs, but it does not clearly disclose that these inputs and any returned public-platform data are likely sent to an external service. This creates a transparency and data-handling risk: users may unknowingly expose research targets, campaign interests, monitored accounts, and retrieved dataset contents to the vendor or intermediary service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code persists the full command output, including the requested URL and fetched comment results, to disk via log.taskWrite. Although the script logs progress messages, there is no user-facing disclosure here that results will be saved locally, no confirmation prompt, and no inline comment/docstring warning about this file write.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code reads a credential from the GUAIKEI_API_TOKEN environment variable and then uses it to create and query a remote task, but the file does not provide a user-facing warning that an external API call using credentials will occur. While there is console output about progress, it does not disclose the credential use or external transmission aspect of the operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script persists the final output to a local file via log.taskWrite, which is a file-write operation affecting user/system data. This file includes request metadata and results, but the code gives no explicit warning in help text or nearby user-facing output that a local artifact will be created.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes the full search output to a local JSON file after completing a search, even though its documented purpose is search/retrieval. Search results and request metadata may contain sensitive research terms, operational context, or creator-analysis data, and silently persisting them expands the data exposure surface on disk beyond user expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script stores search results to a local JSON log file without any explicit warning, consent, or confirmation at runtime. In a content-research skill, queries and returned data may reveal business strategy, campaign planning, or user interests, so silent retention can create privacy, confidentiality, and compliance risks if the host machine or workspace is shared.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code's comments, error messages, and generated help output are all written in Chinese, including strings that will be shown directly to end users such as parameter errors and usage text. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code contains user-facing status and error strings in Chinese, which enforces a specific language for users interacting with the skill. The file does not indicate any user opt-in, language selection, or documented region-specific justification, which matches the policy-violation criteria for language or locale constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The success and failure messages shown to the user are hard-coded in Chinese, again imposing a specific language choice. Because no alternate locale handling or documented justification is present in this file, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Multiple error messages are hard-coded in Chinese, which imposes a specific language on users regardless of preference. The file does not offer language selection or document that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This JavaScript file contains multiple user-facing error strings exclusively in Chinese, which imposes a specific language on users. The provided policy flags language or locale constraints when they are forced without opt-in or documented justification, and no such choice or justification appears in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The only natural-language description in the manifest is written in Chinese and centers the skill around a Chinese platform, but it does not state whether users may interact in other languages or whether the language restriction is intentional. This can violate language/locale policy if the skill effectively enforces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

Natural-language policy violations include forcing a specific language without user opt-in. This README presents all instructions and warnings only in Chinese and does not indicate that the skill is intentionally region-specific or offer an alternative language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The heading prominently presents the skill in Chinese ("快手选题分析") and does not indicate that users can choose another language or that the Chinese-language constraint is intentional and required. Under the policy, forcing a specific language or locale without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents the skill instructions in Chinese only, which can amount to a language/locale policy issue when no user choice or opt-in is offered. The policy specifically calls for flagging content that forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code sends a user-provided URL to remote API endpoints and includes an authentication token, which qualifies as network transmission of user or system data. While retry errors are logged, there is no confirmation prompt, user-facing notice, or explanatory comment/docstring in this file disclosing that these values are sent over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The code reads process.env.GUAIKEI_API_TOKEN to authenticate API requests, which is access to sensitive credential material. In this file there is no explicit disclosure, comment, or help text informing the user that the skill depends on and reads a credential from the environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The code reads process.env.GUAIKEI_API_TOKEN to authenticate API requests. Although the help text says the variable must be configured, it does not clearly warn users that the skill will consume a sensitive credential to perform external requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code performs outbound HTTPS GET and POST requests, including sending request parameters, JSON payloads, and a TOKEN header. There is no confirmation prompt, user-facing log, or explanatory comment/docstring in this file disclosing that user or system data may be transmitted to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The functions require a token and place it into the outbound request header, which is a sensitive credential-handling operation. This file does not include any user-visible warning, logging, or inline documentation explaining that a credential is being used and transmitted.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:15