Back to skill

Security audit

快手运营助手

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Kuaishou analytics purpose, but it automatically saves large social-media result sets locally and includes unsafe token troubleshooting guidance.

Install only if you are comfortable sending Kuaishou search terms, target URLs, and your GUAIKEI_API_TOKEN to the GuaiKei API. Avoid running the documented echo command for the token; use a presence check instead. Treat the generated logs/ files as retained datasets that may include comments, author data, profile/video identifiers, and your research targets, and delete or protect them on shared machines or CI systems.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:271
Finding

Documentation Recommends Printing the API Token to Standard Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 271
Vulnerability Type: Credential disclosure through insecure diagnostic guidance
Risk Level: Low

Evidence

markdown
> Self-check: This is usually because `GUAIKEI_API_TOKEN` did not pass validation (see Q1). Before running, use `echo $GUAIKEI_API_TOKEN` to confirm that the variable has been injected.

Technical Analysis

The troubleshooting instructions recommend printing the complete GUAIKEI_API_TOKEN value to standard output. Terminal output is frequently retained in shell transcripts, CI/CD job logs, remote-support recordings, agent execution histories, and centralized logging systems.

Although the application code does not print the token itself, following the documented diagnostic procedure can disclose the credential to users or systems that can read captured output. The token is subsequently used as the TOKEN authentication header for www.guaikei.com, so disclosure could enable unauthorized use of the associated API account.

Attack Path

  1. A user encounters token validation or authentication failure.
  2. The user follows the documented troubleshooting instruction and runs echo $GUAIKEI_API_TOKEN.
  3. The full token appears in terminal output.
  4. A CI log collector, support-session participant, terminal recorder, or another party with access to execution history obtains the token.
  5. The party sends requests to the GuaiKei API using the disclosed value in the TOKEN header.
  6. The token remains usable until it expires or is revoked.

Impact Assessment

Successful exploitation does not grant local operating-system privileges. It grants the external API permissions associated with the compromised token. Depending on server-side authorization and quotas, an attacker could consume API credits, retrieve data available to the account, trigger rate limits, or cause charges and service disruption. The scope is limited to th ...[truncated 45 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the instruction to print the token value.

  • Recommend presence-only checks that do not disclose the secret, for example:

    sh
    test -n "$GUAIKEI_API_TOKEN" && echo "GUAIKEI_API_TOKEN is configured" || echo "GUAIKEI_API_TOKEN is missing"
    
  • If format diagnostics are necessary, perform them inside the application and report only whether validation succeeded.

  • Do not display even partial token values unless a carefully reviewed masked identifier is operationally necessary.

  • Add guidance to rotate the token immediately if it has been printed into a persistent or shared log.

  • Ensure CI/CD systems register the variable as a secret and apply output masking.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/utils/log.js:23
Finding

Automatically Persisted API Results Use Default File Permissions and Have No Retention Controls

Content
View full analysis

Vulnerability Details

File Location: scripts/utils/log.js, lines 23-34
Vulnerability Type: Plaintext storage of collected data with environment-dependent permissions
Risk Level: Medium

Evidence

javascript
const outputFilename = path.join(
  path.dirname(__filename),
  "..",
  "..",
  "logs",
  safeFilename,
);

try {
  await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true });
  await fs.promises.writeFile(outputFilename, content);

Successful CLI operations pass the complete output, including returned results, to this helper. For example, scripts/kuaishou/comment-cli.js lines 161-166 contain:

javascript
url = validator.url2Name(url);
await log.taskWrite(
  `${startTime}_${url}_comment.json`,
  JSON.stringify(finalOutput, null, 2),
);

Technical Analysis

Search results, profile data, and comment records are automatically written as plaintext JSON under the project-level logs directory. The writeFile call does not specify a restrictive file mode, so Node.js uses the platform default creation mode, generally 0666 filtered by the process umask. The directory is likewise created without an explicit restrictive mode.

Consequently, confidentiality depends on the caller's umask and the permissions of the project directory. In shared workspaces, containers with mounted project directories, permissively configured CI runners, or multi-user systems, other principals may be able to read the stored records. No retention, cleanup, opt-out, encryption, or data-minimization control is implemented.

Filename sanitization prevents straightforward path traversal, so this finding is not an arbitrary-file-write issue. The risk arises from automatic plaintext retention and insufficiently explicit access controls.

Attack Path

  1. A user invokes a search, profile, or comment command.
  2. The skill retrieves records from the external API and constructs ...[truncated 1370 chars]
Remediation
View remediation

Remediation Suggestions

  • Make result persistence opt-in rather than automatic, such as through an explicit --output or --save option.

  • Create the log directory with owner-only permissions and create files with mode 0600:

    javascript
    await fs.promises.mkdir(path.dirname(outputFilename), {
      recursive: true,
      mode: 0o700,
    });
    await fs.promises.writeFile(outputFilename, content, {
      mode: 0o600,
      flag: "wx",
    });
    
  • Verify existing directory permissions because mkdir mode does not correct an already existing permissive directory.

  • Store logs in a user-specific application data directory rather than inside a potentially shared project tree.

  • Provide configurable retention and secure cleanup, including limits by age, count, or total size.

  • Allow callers to redact query parameters and unnecessary response fields before persistence.

  • Exclude logs/ from version control, package publication, CI artifacts, backups, and shared-workspace synchronization by default.

  • Document that saved result files may contain account-related or personal data, even when sourced from public pages.

  • Consider encryption at rest when records must be retained in shared or centrally managed environments.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码片段并未体现任何快手/Kuaishou 数据分析、关键词搜索、作品获取、评论抓取或社媒数据访问能力。它只是一个与具体业务无关的基础工具模块,用于解析命令行参数和生成帮助信息。虽然这类工具可能作为整个技能的支持性实现存在,但就当前提供的代码片段本身而言,其实际行为与声明的业务功能明显不一致,缺少任何与快手平台、数据获取、内容分析或互动指标相关的逻辑。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向快手社媒数据分析的技能,核心能力应涉及获取、分析或查询快手相关内容。而实际代码仅实现了一个辅助函数:定位 package.json,读取其内容,并返回其中的 name 字段。这属于与声明目标无关的本地元数据读取/内部工具逻辑。虽然这可能是技能内部的辅助实现,但就该代码片段本身而言,其实际行为与声明用途没有对应关系,也体现了未声明的本地文件访问能力,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file’s user-facing instructions, triggers, examples, and support guidance are all presented in Chinese with no indication that users may choose another language. This can constitute a language/locale policy violation when the skill effectively forces a specific language without explicit user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but does not warn that those results may contain sensitive operational data such as searched keywords, target profile/video URLs, comment content, or derived analysis outputs. On shared machines, CI runners, or improperly secured workspaces, these logs can be retained, copied, or exposed unintentionally, creating a privacy and data-handling risk even if the source data is public.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The function sends a user-provided URL and authentication token to an external API via postJson, which is a data-transmitting network operation. While retry errors are logged, there is no confirmation prompt, user-facing disclosure of the outbound transmission, or explanatory comment/docstring in this file describing that this data is sent to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This function performs a network request using getJson and includes the supplied URL and token in the request parameters, which may expose user or system data to a remote service. The file contains retry logging but no user-facing notice, confirmation, or inline documentation warning that this outbound request occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script persists retrieved comment data to a local JSON file without any explicit consent or warning in this file, which can create unintended retention of potentially sensitive or regulated user-generated content. In a social-media analysis skill, silent storage increases privacy and data-handling risk because users may expect transient processing rather than durable local copies.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The argument description and examples say the command accepts a creator homepage URL or a USER_ID, but the implementation validates the input only with isProfileUrl and exits on failure. This creates a semantic mismatch between the advertised interface and actual behavior for a core claimed use case.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The flag description and usage examples explicitly document USER_ID input, while lines 79-83 reject anything that does not satisfy isProfileUrl. This is an active contradiction between the file's own documentation and the implemented validation logic.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The code reads process.env.GUAIKEI_API_TOKEN and then uses it in calls to post.createPostTask and post.getPostTask, which are network-oriented by naming and context. Although the script logs URLs and progress, it does not explicitly warn users that credentials are being used and request data is being transmitted to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script persists fetched results to a local JSON file automatically, without explicit notice, consent, or retention controls. Because the tool handles social-media analysis data, this can create unintended local data exposure on shared systems, developer workstations, CI runners, or agent environments where output files may be collected, synced, or readable by other users/processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI writes the full search output to a local JSON file automatically, including the searched keyword and returned results, without obtaining consent or clearly warning the user. In a data-analysis skill, those results may contain sensitive research terms, creator data, or content metadata that can persist on disk and be exposed to other local users, backups, or later compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code sends request payloads and a TOKEN header over HTTPS via postJson and getJson, which can transmit user or system data to a remote service. In this file there is no confirmation prompt, user-facing log/print, or explanatory comment/docstring warning that network transmission and credential use will occur.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file contains user-facing natural-language strings entirely in Chinese, including the warning and informational output. Because the skill does not offer user opt-in for language selection or document that it is intentionally limited to Chinese-speaking users, it can violate a language/locale policy requiring user choice or justified locale constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits all validation errors in Chinese across multiple user-facing print statements, which forces a specific language on users without any visible opt-in or locale selection. That matches the policy-violation category for language/locale constraints because the file provides no indication that the skill is explicitly China-region-specific or that users can choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The description and keywords are entirely in Chinese, which can act as a language constraint in user-facing skill metadata. There is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking/regional context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. The file forces a single language for all instructions and warnings, with no opt-in, alternative locale, or justification that the skill is intended only for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file title and content are entirely in Chinese, and there is no indication that the skill offers users a language choice or that the locale restriction is intentional for a region-specific audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file’s user-facing instructions and parameter descriptions are exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill description focuses on social-media data analysis and retrieval functions, but this file additionally pulls an API token from the process environment. While likely needed for backend access, credential access is not stated in the manifest and is a capability users may not expect from a purely analytics-oriented skill description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes Kuaishou analytics, video details, work data, comments retrieval, and content analysis, which implies fetching and returning platform data. This CLI also persists the full result to a local JSON file via log.taskWrite, a side effect not reflected in the skill description and beyond simple retrieval/output behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes Kuaishou data analysis and retrieval functions such as keyword search, creator works, and comments. This file additionally depends on a credential sourced from process.env, which is an operational capability not mentioned in the stated purpose and is not directly user-facing analysis behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The code reads process.env.GUAIKEI_API_TOKEN, which is access to sensitive credential material. The help text tells the user to configure the variable, but it does not clearly warn that the skill will read and use that credential to make authenticated requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file contains natural-language comments and all user-facing CLI messages in Chinese, including errors and help output. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation because no alternative locale or language selection is offered.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:15