Back to skill

Security audit

快手热门视频检索

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Kuaishou public-data lookup tool that sends requested keywords or URLs to a third-party API and saves returned JSON results locally.

Install only if you are comfortable sending Kuaishou search terms, profile URLs, video URLs, and your GUAIKEI API token to guaikei.com. Review or clean the generated `logs/` directory if the queried targets or returned comments are sensitive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (32)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a multi-capability Kuaishou trend-analysis/search tool centered on keyword hot-video search, creator works extraction, and comment analysis. The supplied code chunk does not implement those advertised capabilities. Instead, it defines two functions that submit and query a backend task for a Kuaishou post URL, with optional sort and limit parameters. There is no evidence of keyword search, homepage crawling, comment analysis, publish-time or duration filtering, or broad hot-content retrieval. Because the actual behavior in this chunk is materially narrower and different from the declared purpose, this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description describes a feature-rich Kuaishou data tool focused on searching hot videos, scraping creator works, and analyzing video comments. However, the supplied code chunk only contains a reusable command-line argument parser (parseArgs, readValueAfterFlag, buildHelp). This is infrastructure code for handling CLI options and help text, not code that accesses Kuaishou, fetches real-time data, processes videos, or analyzes comments. While utility code can support a larger skill, this chunk by itself does not match the declared functional behavior and instead serves a different, generic purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is about Kuaishou data retrieval and analysis features: searching hot videos, fetching creator works, and analyzing comments. The supplied code does none of those things. Instead, it validates inputs, sanitizes filenames, creates directories, and writes content to local files in a logs folder. While logging can be a supporting implementation detail in a larger system, this chunk's actual behavior is purely a filesystem logging utility and does not implement or directly relate to the declared end-user capabilities. Therefore, for this code chunk considered on its own, the description does not accurately represent what it actually does.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The package metadata describes a search/scrape/analyze skill with three read-oriented capabilities, but the scripts section exposes an additional post operation not disclosed in the description. Hidden or undocumented write/publish functionality increases the risk of unexpected side effects, abuse of authenticated sessions, or repurposing the skill to perform actions users did not consent to.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

A post command is inconsistent with the stated purpose of a video search and comment-analysis tool, making it an unjustified capability escalation. In agent environments, an unexpected posting path can be triggered intentionally or accidentally to publish content, spam, or perform account actions under the user's identity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to obtain a third-party token and use commands that submit keywords, profile URLs, and video URLs, but it does not clearly warn that those inputs are transmitted to an external service. This creates a transparency and privacy risk because users may unknowingly send sensitive research targets, monitoring subjects, or internal investigation terms to the vendor API.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The CLI writes the full comment-analysis output, including retrieved comment content and metadata, to a local JSON file without any explicit user consent or clear disclosure in the skill description. Persisting externally sourced social-media data can create unintended local data retention, exposure to other local users/processes, and compliance/privacy issues if operators assume the tool is read-only.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool silently persists retrieved comment data to disk after successful execution, which can surprise users and expand the exposure window for potentially sensitive or regulated data. Because this is a comment-analysis skill, the saved file may contain large volumes of user-generated content and engagement metadata that operators did not expect to retain locally.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI writes the full retrieved results to a local JSON file, which can include scraped profile data, comments, and other potentially sensitive or regulated content. Persisting this data without clear disclosure, minimization, retention controls, or opt-in behavior increases the risk of unintended local data exposure, especially on shared systems or environments where log directories are collected or synchronized.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The CLI writes the full search output to a local file whose name includes user-controlled keyword data, without any explicit opt-in, warning, or control in this script. Because the results may contain sensitive research terms, scraped content, or account-related metadata, this creates an unintended local data persistence/privacy risk, especially on shared systems or CI/agent environments where workspace artifacts may be exposed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file contains user-facing natural-language strings in Chinese, beginning with the file-level description and continuing throughout errors and help output. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple thrown errors, warnings, and generated help text are emitted exclusively in Chinese across the parser implementation. Because these are user-visible strings and the file does not provide a language choice or clearly justified locale limitation, this conflicts with the language/locale policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code builds and sends outbound HTTPS POST requests containing a TOKEN header and JSON payload, but there is no confirmation prompt, user-facing log, or explanatory comment disclosing that user or system data will be transmitted to a remote service. For this code file, that makes the network transmission a safety-relevant operation lacking visible disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This helper sends outbound HTTPS GET requests with a TOKEN header and serialized query parameters, but the code provides no prompt, log, print, or local documentation warning that data is being sent off-host. That matches the missing user warning criterion for network calls in code files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The entire skill documentation is presented in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language audience for compliance or regional reasons. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file presents the skill changelog entirely in Chinese, and there is no natural-language indication that the skill is intended only for a Chinese-speaking audience or that users can choose another language. Under the language/locale policy, forcing a specific language without opt-in or documented justification can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all usage instructions and parameter descriptions exclusively in Chinese. Under the policy rule for language or locale constraints, forcing a single language without user opt-in or justification can be considered a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code sends the supplied URL to a remote API via postJson and authenticates with a token, but the file contains no comment, docstring, or user-facing message disclosing that user data is transmitted over the network. Under the code-file warning criteria, network calls that transmit user or system data should have some visible disclosure unless clearly covered elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The getCommentTask function performs a network request that includes the provided URL and token, but this file offers no confirmation, comment, or user-visible notice about that data transmission. Because network operations involving user or system data are safety-relevant, some disclosure is expected in code or accompanying markdown.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The retry/error messages are hard-coded in Chinese, which is a natural-language locale constraint visible in code. Under the policy, forcing a specific language without user opt-in or a clearly documented region-specific justification is a violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The thrown error message is hard-coded in Chinese and does not indicate any user choice of language or documented locale restriction. This creates the same language-policy issue as other user-facing strings in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This string is another fixed-language message that appears to be shown to users or operators. The policy requires either user opt-in for the locale or clear documentation that the skill is intentionally region/language specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The command descriptions, examples, and runtime messages are presented only in Chinese, which forces a specific language/locale on all users. There is no indication in this file that the user can select a language or that the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The manifest presents the skill as a Kuaishou video search/comment analysis tool, but does not mention dependency on external credentials or secret handling. Reading process.env.GUAIKEI_API_TOKEN adds a credential-access capability that is not part of the stated purpose itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.