Back to skill

Security audit

快手高赞视频检索

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Kuaishou public-data lookup tool that uses a third-party API token and saves fetched results locally.

Install only if you are comfortable sending Kuaishou search terms, profile/video identifiers, and your GUAIKEI_API_TOKEN to guaikei.com. Treat saved logs as retained research data, especially when collecting comments, and delete or protect the logs directory if the results should not persist locally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

该代码片段的主要行为是调用 /api/kuaishou/search/keyword 和 /api/kuaishou/search/info 两个接口,围绕“关键词搜索视频”创建与查询任务,且支持 sort、time、duration、limit 等筛选参数,这与声明中的第一项能力基本一致。但声明还明确声称支持“达人作品抓取”和“视频评论分析”两大能力,而在提供的代码中完全没有对应主页链接、视频链接、作品列表、评论内容或互动数据的处理逻辑。因此,就此代码片段而言,声明范围大于实际实现,属于描述与行为不完全一致。未发现额外的未声明敏感能力;问题在于过度宣称功能。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码内容仅为 scripts/utils/args.js,一个通用 CLI 参数解析与帮助文本生成模块。它负责读取命令行参数、校验必填项与数值类型、处理 boolean/default/alias/位置参数,并生成帮助信息。代码中没有任何网络请求、快手相关接口调用、视频/评论/达人数据处理、链接解析或趋势分析逻辑。因此,该代码块的实际行为与声明的快手高赞视频搜索/抓取/评论分析用途存在明显不匹配,属于 materially different primary purpose。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是快手视频搜索/抓取/评论分析能力,但给出的代码片段实际仅实现了本地日志写入功能,没有体现任何快手数据获取、关键词搜索、主页作品抓取或评论分析逻辑。虽然日志模块可能是辅助实现细节,但当前代码访问的是本地文件系统并执行写文件操作,这与声明的核心功能完全不对应。依据标准,这属于实际行为与声明目的存在明显差异。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not clearly warn users that retrieved public video metadata, comments, and analysis outputs will be persisted to local files. This creates a real data-handling risk because users may assume results are transient, while the tool silently leaves potentially sensitive research data, URLs, and comment content on disk where they may be exposed to other local users, backups, or accidental commits.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill documentation is written in Chinese, including headings, parameter descriptions, and usage examples, with no indication that another language is supported or that the skill is intentionally limited to Chinese-speaking users. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code performs an HTTP POST using a user-provided URL and authentication token, which transmits potentially sensitive data to an external API. While retry errors are logged, there is no visible user disclosure, confirmation prompt, or explanatory comment in this file about the transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

This function makes an HTTP GET request that includes the supplied URL and token, transmitting request metadata to the service. The file contains retry logging but no user-facing warning or documentation indicating that these values are sent over the network.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI writes the full fetched comment results to a local JSON file after already printing them to stdout. Comment data can contain personal data, usernames, or sensitive user-generated content, and persisting it to disk increases exposure through unintended retention, broader local access, backups, or later exfiltration. In this skill context, comment harvesting is expected, but undisclosed local storage makes the privacy risk more significant.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script saves fetched comment data to a local JSON file without any explicit warning, consent, or opt-in in this script. Silent persistence of scraped social-media comments can create privacy, compliance, and data-handling issues, especially if operators assume the tool only streams results and does not retain them locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The code retrieves GUAIKEI_API_TOKEN and then calls post.createPostTask and post.getPostTask, which indicate outbound API usage with user-supplied profile data. Although success messages are printed, there is no explicit user warning that the provided URL and token-authenticated request data will be sent to an external service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI writes fetched creator-post results to a local JSON file after completing the request, but this persistence is not evident from the stated skill description or from a clear user-facing warning in this file. Silent local retention can expose scraped content, metadata, and queried profile identifiers to other local users, backups, or later unintended processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The tool writes full results to a local JSON file without an explicit user-facing warning in this code path. Even if the fetched data is public, silent storage creates privacy and data-governance risk because queries and retrieved content may persist on disk longer than the user expects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script writes full search results to a local JSON file whose name includes user-supplied keyword data, without explicit consent or a clear disclosure at execution time. This can create unintended local data retention and leak searched topics or collected content to other local users, backup systems, or shared workspaces, especially in multi-user or automated environments.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes capabilities for searching Kuaishou videos, fetching creator works, and analyzing video comments. This helper instead persists caller-provided content to files under a local logs directory, which is outside the stated user-facing scope and constitutes additional write behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits user-facing error messages in Chinese, and later also prints a success message in Chinese. For a general-purpose utility file, forcing a specific language without offering user opt-in or documenting a locale-specific scope is a natural-language policy violation under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The success and failure messages shown to users are hardcoded in Chinese, with no indication that the skill is region-specific or that users can select another language. This can violate organizational language/locale policy when the skill is not explicitly scoped to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code constructs and sends outbound HTTPS POST requests containing serialized data and a TOKEN header, which may transmit user or system data to an external service. There is no confirmation prompt, logging, or inline warning in this file disclosing that data and credentials are being sent over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code builds outbound HTTPS GET requests that include a TOKEN header and query parameters, but the file provides no user-visible disclosure that credentials and request metadata are sent to a remote host. For safety review purposes, network transmission of tokens should be accompanied by some warning or documentation unless clearly disclosed elsewhere.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language description is entirely in Chinese and presents the skill's behavior and interface in a single fixed language. There is no indication that users can opt into another language or that the locale restriction is required for a clearly documented region-specific compliance reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The natural-language content of the skill forces a specific language presentation without offering alternatives or stating that the skill is intended only for a Chinese-speaking audience. Under the language/locale policy, this is a potential policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The stated purpose focuses on searching videos, fetching creator works, and analyzing comments. Reading process.env.GUAIKEI_API_TOKEN introduces access to host environment configuration, which is an implementation capability not justified by the user-facing purpose as written.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

All visible help text, parameter descriptions, and runtime messages are presented in Chinese, with no indication that users can select another language or locale. This can violate language/locale policy where tools must not force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest presents the skill as a video search and analysis tool, but does not mention credential handling or dependency on environment-based secrets. Accessing process.env.GUAIKEI_API_TOKEN introduces secret-reading behavior that is not evident from the stated purpose alone.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest focuses on searching videos, fetching creator works, and analyzing comments. This file additionally depends on a credential sourced from process.env, which is an implementation capability not mentioned in the stated skill purpose and expands the skill's access to host environment data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.