Back to skill

Security audit

TikTok作品批量下载

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed TikTok public-data API wrapper with local JSON logging and no hidden execution or persistence behavior found.

Install only if you are comfortable sending TikTok search terms, target URLs or IDs, and your GUAIKEI_API_TOKEN to www.guaikei.com. Review the temporary JSON logs if the machine is shared, and treat returned comments/user identifiers as public personal data that may require retention, consent, or terms-of-service review before reuse.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (36)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

这段代码的行为只覆盖已声明能力中的一部分:‘博主作品获取’。它通过 URL/sec_uid 获取账号作品列表,并支持最新/最热排序与数量限制,这与声明的第二项能力基本一致。但声明中还强调了关键词搜索、评论抓取、下载链接解析和批量下载到本地,而代码中没有任何对应实现迹象;输入参数也仅有 url、sort、limit,没有关键词、时间筛选、视频链接/作品ID、评论相关参数或下载路径等。故整体描述明显宽于该代码块实际能力,属于描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码内容仅为 scripts/utils/args.js,一个通用参数解析与帮助文本生成模块。它处理命令行参数、校验参数值、生成 help 文本,并返回解析结果。代码中没有出现 TikTok 相关 API、网页抓取、HTTP 请求、链接解析、JSON 数据抓取、评论提取或文件下载逻辑。因此,实际行为与声明的核心用途明显不符,属于重大描述-行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是面向 TikTok 的搜索、作品抓取、评论抓取和下载能力;而这段代码实际只实现了日志落盘功能,与 TikTok 数据搜索、抓取、解析、下载或评论获取没有直接关系。虽然日志记录可被视为辅助实现细节,但这里提供的代码片段本身的实际行为完全是本地文件写入,且涉及文件系统访问这一声明中未体现的能力。因此,就“该代码片段是否准确体现声明用途”而言,存在明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises substantial TikTok scraping/downloading functionality, including search, creator post retrieval, and comment collection. The supplied code chunk does none of that. It is only a utility that reads the local package metadata (package.json) to determine the skill's name and caches the result. This is not a supporting detail clearly tied to the claimed capabilities in this isolated chunk; instead, the actual behavior shown is materially different from the declared primary purpose, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares access to an environment variable (GUAIKEI_API_TOKEN) but does not declare an explicit tool scope such as permissions or allowed-tools. That creates ambiguity about what runtime capabilities the skill is expected to use and weakens least-privilege review, making it easier for a skill to gain or later expand sensitive access without clear policy boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The title and property descriptions are presented only in Chinese, which imposes a specific language on users without offering a language choice or explaining that the skill is region- or locale-specific. This matches the policy concern for language or locale constraints that are not explicitly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The package description advertises very broad capabilities and usage scenarios without clear trigger boundaries or limiting conditions. In an agent environment, this can cause over-activation or invocation in contexts involving scraping, bulk collection, and downloading of third-party content or comments, increasing the chance of privacy, policy, or unauthorized data-handling abuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example trigger phrases are generic natural-language requests such as searching TikTok, reviewing an account, or analyzing comments. In an agent environment, these broad phrases can cause the skill to activate for ordinary user requests without an explicit opt-in, leading to unintended third-party API calls, external data disclosure, and unexpected billing.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/options.md (reported line 14)May include surrounding context.

node scripts/tiktok/search-cli.js --keyword <关键词> [--sort <排序>] [--time <时间>] [--limit <数量>]

text

| 参数        | 缩写 | 作用       | 可选值                                                                                      | 必填 | 默认 |
| ----------- | :--: | ---------- | ------------------------------------------------------------------------------------------- | :--: | :--: |
| `--keyword` | `-k` | 搜索关键词 | 2–100 字符;不可含 `< > " ' &`,不可含 http 链接                                            |  是  |  —   |
| `--sort`    | `-s` | 排序方式   | `0` 相关度 / `1` 最多点赞                                                                   |  否  | `0`  |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation explicitly supports large-scale collection of TikTok posts, comments, and persistent author identifiers such as author_uid, author_sec_uid, user_uid, and interaction metadata, but provides no privacy, retention, consent, or permitted-use guidance. In a scraping/downloader skill, that omission increases the chance of improper surveillance, profiling, or non-compliant handling of personal data at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script persists the full output to disk via log.taskWrite, which may include scraped account data and request metadata. Although the code logs progress messages, it does not clearly disclose beforehand that results will be saved to a file, nor does it ask for confirmation or provide an opt-out in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's descriptions, help text, and status/error messages are all hard-coded in Chinese, with no apparent option to select another language or locale. This creates a natural-language policy issue when users are not given language choice or explicit opt-in to a fixed locale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI writes full search output to a local JSON file using a filename derived from the user keyword, without any opt-in, masking, or warning. In this skill context, results may include potentially sensitive research topics, account data, or comment datasets, so silent local persistence can create privacy and data-handling risks, especially on shared systems or when logs are later collected or synced.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains multiple user-facing error and help strings in Chinese, such as parameter errors and usage text. The skill does not offer a language/locale choice or indicate that it is intentionally limited to a Chinese-speaking context, which creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits multiple natural-language strings such as "请求失败", "响应解析失败", and "GUAIKEI_API_TOKEN 无效, 请检查环境变量" directly in Chinese. Because the file does not provide any user opt-in, localization mechanism, or documentation that the skill is intentionally Chinese-only, it appears to enforce a specific language/locale in violation of the language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code emits warning and info messages only in Chinese ("警告..." and "已使用配置的私有TOKEN"). The policy disallows forcing a specific language without user opt-in, and this file provides no indication that the skill is region-specific or that users can choose another locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits all user-facing validation and error messages in Chinese, which imposes a specific language on users without any opt-in or fallback. Under the language/locale policy, hard-coding a single language is a natural-language policy concern unless the locale constraint is explicitly offered as a choice or clearly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON manifest-like schema uses Chinese-only natural-language descriptions in the title and description fields. Because the file does not state that the skill is intended only for Chinese-speaking users or offer any language choice, it creates an ambiguous trigger/usage surface for broader environments and lacks clear scope constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON schema includes titles and descriptions only in Chinese, such as the title and field descriptions on multiple lines. That can constitute a language/locale policy issue because it forces a specific language for consumers of the skill artifact without any visible user choice or documented locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The title and property descriptions are written entirely in Chinese, which creates a language-specific constraint in the skill's natural-language interface metadata. Under the policy, locale or language restrictions should either offer user choice or be explicitly justified as region-specific, neither of which is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema contains natural-language titles and descriptions exclusively in Chinese, such as the title on L004 and multiple property descriptions throughout the file. Because the policy forbids forcing a specific language without user opt-in or documented justification, this constitutes a locale/language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This manifest file contains user-facing title and description fields only in Chinese, which can amount to a language/locale policy issue if the skill is expected to operate in a general environment. There is no accompanying indication that the skill is China/Chinese-language specific or that users can opt into this locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON schema contains natural-language titles and descriptions exclusively in Chinese, including the top-level title/description and many property descriptions. Because the file does not document that the skill is China/Chinese-specific or offer a language choice, it may violate a language/locale policy that requires user opt-in or justified locale constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The user-facing description is entirely in Chinese, which can imply a fixed language/locale expectation without user opt-in. The file does not indicate that the skill is intentionally region-specific or that alternative language support is available.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The schema specifies the message field as '人类可读说明' and the entire operational documentation is written as if Chinese is the required interface language, with no opt-in or alternative locale described. This can be a natural-language policy issue when a skill imposes a specific language without user choice or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16