Back to skill

Security audit

TikTok评论分析与用户洞察

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed read-only TikTok data API wrapper, with the main considerations being third-party API transmission and local result logs.

Install only if you are comfortable sending TikTok search terms or target URLs/IDs and your GUAIKEI_API_TOKEN to www.guaikei.com. Treat downloaded comments, nicknames, and identifiers as personal data, avoid unnecessary sharing, and periodically delete temp logs if the results contain sensitive research topics or user data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (34)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation discloses automatic local log-file writes but the high-level description presents the skill as a simple data-retrieval utility. Undeclared persistence can create privacy and data-handling risk because TikTok URLs, keywords, and retrieved comment data may be stored on disk without the user's informed expectation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation discloses automatic local log-file writes but the high-level description presents the skill as a simple data-retrieval utility. Undeclared persistence can create privacy and data-handling risk because TikTok URLs, keywords, and retrieved comment data may be stored on disk without the user's informed expectation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation discloses automatic local log-file writes but the high-level description presents the skill as a simple data-retrieval utility. Undeclared persistence can create privacy and data-handling risk because TikTok URLs, keywords, and retrieved comment data may be stored on disk without the user's informed expectation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The package description is written entirely in Chinese and describes the skill's behavior in that language, with no indication that users can choose another language or locale. This can violate language/locale policy when a skill implicitly constrains interaction language without explicit opt-in or documented regional limitation.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/options.md (reported line 14)May include surrounding context.

node scripts/tiktok/search-cli.js --keyword <关键词> [--sort <排序>] [--time <时间>] [--limit <数量>]

text

| 参数        | 缩写 | 作用       | 可选值                                                                                      | 必填 | 默认 |
| ----------- | :--: | ---------- | ------------------------------------------------------------------------------------------- | :--: | :--: |
| `--keyword` | `-k` | 搜索关键词 | 2–100 字符;不可含 `< > " ' &`,不可含 http 链接                                            |  是  |  —   |
| `--sort`    | `-s` | 排序方式   | `0` 相关度 / `1` 最多点赞                                                                   |  否  | `0`  |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation explicitly describes collecting commenter and author identifiers such as author_uid, author_sec_uid, user_uid, and user_sec_uid but provides no privacy, retention, consent, or data-handling guidance. In a consumer-insights skill, this increases the risk that integrators will collect, store, or repurpose personal data in ways that violate platform rules, privacy expectations, or internal compliance requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The functions send a user-provided TikTok URL and a token to remote API endpoints via requestApi, which is a network operation involving potentially sensitive data. In this file there is no confirmation prompt, logging, comment, or docstring disclosing that the skill transmits this data externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes the full comment retrieval results to a local JSON file automatically, and those results likely contain user-generated content, commenter identifiers, links, and interaction metadata. In a consumer-insights skill focused on mass collection of TikTok comments, silently persisting this data increases privacy and data-handling risk because sensitive or regulated data may remain on disk longer than intended, be copied to backups, or be accessible to other local users/processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script sends the keyword and search parameters to remote APIs to create and fetch search tasks, but does not provide a clear just-in-time notice that user input will be transmitted off-host. While remote transmission is functionally necessary for this tool, keywords may reveal sensitive business intent, internal investigations, or personal interests, so undisclosed sharing creates a privacy and confidentiality risk. Given this skill is specifically for consumer-insight gathering, operators may search for sensitive product, brand, or complaint topics, increasing the significance of the disclosure gap.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI writes the full structured search output to a local JSON file whose filename includes the user-supplied keyword. Because results may contain user-generated TikTok content, metadata, and potentially sensitive research terms, this creates a privacy and data-retention risk if logs are stored on shared systems or synced to other locations without the user's awareness. In this skill's context, the data being collected is third-party social content and consumer insights, which makes silent persistence more sensitive rather than less.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code's natural-language interface is entirely in Chinese, including errors, help text, usage labels, and warnings. Because the file provides no opt-in, fallback, or documented region-specific justification, it imposes a specific language on users and matches the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits user-facing error messages only in Chinese, and later also prints a success message in Chinese. The file provides no indication that the skill is China-specific or that users can choose their preferred language, which creates a natural-language locale policy violation under the stated rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The success and failure status strings are hard-coded in Chinese, forcing a specific language for runtime interaction. Because no opt-in, fallback, or documented locale limitation is present in this file, this matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code sends request parameters/body data to a remote host and includes a TOKEN header, but the file provides no user-facing disclosure such as a prompt, log, or warning comment about transmitting data or credentials. For code files, network calls that transmit user or system data should have some visible disclosure unless clearly covered elsewhere or obviously inherent to the skill's purpose, which is not established in this file alone.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language comments and user-facing warning/info strings only in Chinese, with no indication that the skill is region-specific or that users can opt into a preferred language. That can violate a language/locale policy when a skill imposes a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains all user-facing validation errors exclusively in Chinese, such as the messages printed at L11, L15, L19, L23, L53, L59, and L64. Under the policy rule for natural-language violations, this is a language/locale constraint with no visible opt-in, fallback, or documentation that the skill is intended only for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file consistently identifies the skill as "tiktok-comment-consumer-insights" in the manifest and title, but the example output hardcodes a different skill name. This is an active documentation contradiction that can mislead integrators about what tool produced the output.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill states that each run automatically writes log files, but this behavior is not prominently declared alongside the advertised data-retrieval features. Because the skill processes potentially sensitive research targets, URLs, search terms, and public-comment datasets, unexpected local persistence increases privacy, compliance, and data-exposure risk on shared systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON schema contains user-facing natural-language fields such as title and description entirely in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON schema contains user-facing natural-language fields such as the title and descriptions exclusively in Chinese. Under the policy, forcing a specific language without opt-in or justification is a natural-language locale violation, and the file does not indicate that the schema is intentionally limited to a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The title and description are written entirely in Chinese, which imposes a specific language on users of this schema. The file does not indicate that the skill is region-specific or that users can opt into another language, so this conflicts with the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON schema contains user-facing natural-language titles and descriptions in Chinese throughout the file. Because the file does not document that the skill is Chinese-only or provide any language/locale opt-in, it may violate the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This manifest/config file contains user-facing natural-language strings exclusively in Chinese, but it does not document that the skill is Chinese-only or offer any language/locale choice. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions throughout, such as the title and field descriptions, with no indication that the skill is region-specific or that users can opt into this locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16