Back to skill

Security audit

TikTok账号拆解

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, read-only TikTok public-data tool, but users should understand it sends queries and an API token to guaikei.com and saves result logs locally.

Install only if you are comfortable sending your GUAIKEI_API_TOKEN and TikTok search terms, profile URLs, video IDs, or comment requests to www.guaikei.com. Review local temp logs before sharing the machine or committing files, because successful runs save full JSON results that may include public usernames, nicknames, comments, and engagement metrics.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Repeated description-behavior mismatch findings indicate the skill's documented purpose materially diverges from its implementation. Even without obviously malicious code, this creates a trust-boundary problem: reviewers cannot rely on the manifest to understand what will execute, what data will be accessed, or whether external requests are truly necessary. Such ambiguity is a real security issue for agent ecosystems because policy, routing, and user consent are often based on manifest text.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Repeated description-behavior mismatch findings indicate the skill's documented purpose materially diverges from its implementation. Even without obviously malicious code, this creates a trust-boundary problem: reviewers cannot rely on the manifest to understand what will execute, what data will be accessed, or whether external requests are truly necessary. Such ambiguity is a real security issue for agent ecosystems because policy, routing, and user consent are often based on manifest text.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Repeated description-behavior mismatch findings indicate the skill's documented purpose materially diverges from its implementation. Even without obviously malicious code, this creates a trust-boundary problem: reviewers cannot rely on the manifest to understand what will execute, what data will be accessed, or whether external requests are truly necessary. Such ambiguity is a real security issue for agent ecosystems because policy, routing, and user consent are often based on manifest text.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions throughout, including the top-level title/description and many property descriptions. Because the file does not document that the skill is China-specific or offer any language choice, it creates a locale/language policy concern under the rule for forced language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The title and property descriptions are presented entirely in Chinese, which imposes a specific language on users and integrators. Under the policy, language constraints should either be optional/opt-in or clearly justified as region-specific, but this schema provides no such explanation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description contains many broad natural-language trigger phrases such as competitor analysis, account teardown, style replication, and data scraping requests. This can cause the skill to be invoked for loosely related prompts without clear user intent, increasing the chance of over-collection of third-party TikTok data or activation in contexts where the user did not explicitly request this capability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The description is written entirely in Chinese and frames outputs in that language, which may push the skill toward responding in Chinese regardless of the user's language preference. This can create unsafe or misleading automation behavior by overriding user expectations and reducing transparency about what data is being collected or returned.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/options.md (reported line 14)May include surrounding context.

node scripts/tiktok/search-cli.js --keyword <关键词> [--sort <排序>] [--time <时间>] [--limit <数量>]

text

| 参数        | 缩写 | 作用       | 可选值                                                                                      | 必填 | 默认 |
| ----------- | :--: | ---------- | ------------------------------------------------------------------------------------------- | :--: | :--: |
| `--keyword` | `-k` | 搜索关键词 | 2–100 字符;不可含 `< > " ' &`,不可含 http 链接                                            |  是  |  —   |
| `--sort`    | `-s` | 排序方式   | `0` 相关度 / `1` 最多点赞                                                                   |  否  | `0`  |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example output specifies message as 人类可读说明, and the entire document is written as mandatory operational guidance in Chinese with no indication that users may choose another language or locale. This can violate language/locale policy when a skill implicitly requires a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The functions send a token plus user-supplied URL and limit values to remote API endpoints via requestApi, which is a network operation involving potentially sensitive data. In this file there is no confirmation prompt, logging, comment, or docstring disclosing that this data is transmitted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI writes the full comment extraction output to a local JSON file automatically, without any notice, consent, or option to disable persistence. Because the tool is designed to collect structured TikTok comment data including commenter and interaction metadata, this creates a privacy and data-retention risk: sensitive scraped data may remain on disk, be accessible to other local users/processes, or be unintentionally committed, shared, or exfiltrated later.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI writes the full task output to a local JSON file, which may contain scraped account metadata, engagement data, and potentially comment content. Persisting collected data to disk without clear opt-in, destination control, or retention safeguards increases the risk of accidental disclosure on shared systems or through later exfiltration of local files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file contains natural-language comments, help text, and error messages entirely in Chinese, including the generated help output and runtime exceptions. Because the skill does not provide user opt-in for language selection or document that it is intentionally limited to a Chinese-speaking context, it may violate a language/locale policy requiring neutrality or user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code emits all user-facing status and error messages in Chinese, such as the validation errors on L19 and L23. For a general utility file, hard-coding a single language without offering user choice or documenting a justified locale restriction is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file contains multiple user-visible messages and API method documentation entirely in Chinese, such as error messages and log labels, with no indication that the skill is China-specific or that users can choose their preferred language. This creates a locale policy concern because the skill appears to force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code emits user-visible warning and info strings only in Chinese (警告..., 已使用配置的私有TOKEN). The policy for natural-language violations applies to all file types, and forcing a specific language without user opt-in or documented justification is in scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language comments and error messages exclusively in Chinese, including all user-visible validation feedback. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present in this file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest and surrounding documentation consistently describe this skill as "tiktok-account-teardown", but the output contract example says metadata.skill_name is "tiktok-creator-videos". This is a direct documentation contradiction that could mislead downstream agents about which tool actually produced the output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title and description are presented only in Chinese, which creates a language/locale constraint in natural-language content. The file does not indicate that the skill is region-specific or provide any user opt-in or alternative language, so this appears to violate the language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON schema is a manifest/config-style file, so SQP-3 applies. The title and descriptions consistently force a single language presentation in Chinese, and the file does not indicate that the skill is region-specific or that users may opt into another language, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language strings in the schema title and field descriptions are entirely in Chinese, which imposes a specific language on users without any opt-in or alternative locale. The policy allows locale constraints only when documented and justified, but this file provides no such justification or language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions throughout, such as the title and field descriptions, with no indication that the skill is region-specific or that users can opt into this locale. Under the language/locale policy rule, forcing a specific language without user choice or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

L113-L116 的输出信封示例把 skill_name 写成了 tiktok-creator-videos,而当前文档和清单描述的是 tiktok-account-teardown,且能力范围还包含搜索与评论抓取,不只是作者视频。这属于文档声明与实际技能身份/用途的直接矛盾,容易误导调用方对返回结果来源的判断。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The string literals "创建任务" and "查询任务" appear to define user-visible operation text in a single language. There is no indication in this file that users can opt into this locale or that the skill is intentionally limited to a Chinese-language context.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16