Back to skill

Security audit

TikTok数据智能助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent TikTok public-data API wrapper, but users should understand it sends requests to guaikei.com and saves result logs locally.

Install only if you are comfortable sending your API token plus TikTok keywords, profile URLs, video IDs, and related request metadata to www.guaikei.com. Treat returned public profile/comment data as personal data where applicable, follow TikTok and privacy rules, and delete temporary JSON logs when you no longer need them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (27)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a TikTok data collection tool with three concrete data-access capabilities. However, the provided code chunk only contains generic command-line argument parsing and help text generation utilities. This is a supporting utility component and, by itself, does not perform any TikTok-specific logic, network access, scraping, searching, content retrieval, or comment extraction. Because the actual behavior of the supplied code chunk is materially different from the declared primary purpose, this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill requires access to the sensitive environment variable GUAIKEI_API_TOKEN but does not declare an explicit tool scope such as permissions or allowed-tools. In agent environments, undeclared capability boundaries make it harder to enforce least privilege and increase the risk that the skill can access environment data without clear policy controls or auditing.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly states that each run automatically writes logs and that the location is exposed via stderr. Because the skill processes user-supplied keywords, URLs, IDs, and potentially retrieved comment data, automatic retention can create a secondary data store of sensitive research activity and scraped content, increasing privacy, compliance, and data leakage risk if logs are accessible to other users or processes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON schema includes human-readable title and description strings entirely in Chinese, such as the schema title and many property descriptions. Because SQP-3 applies to all file types and covers language/locale policy violations, this is a policy issue when no user choice or explicit region-specific justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and property descriptions are presented only in Chinese, which imposes a specific language on users through natural-language metadata. The file does not indicate that this is a China-specific or Chinese-only skill, nor does it provide any opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill description, examples, and user-facing instructions are written exclusively in Chinese, including the invocation examples at L083-L085, with no indication that other languages are supported or that the Chinese-only scope is intentional. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/options.md (reported line 14)May include surrounding context.

node scripts/tiktok/search-cli.js --keyword <关键词> [--sort <排序>] [--time <时间>] [--limit <数量>]

text

| 参数        | 缩写 | 作用       | 可选值                                                                                      | 必填 | 默认 |
| ----------- | :--: | ---------- | ------------------------------------------------------------------------------------------- | :--: | :--: |
| `--keyword` | `-k` | 搜索关键词 | 2–100 字符;不可含 `< > " ' &`,不可含 http 链接                                            |  是  |  —   |
| `--sort`    | `-s` | 排序方式   | `0` 相关度 / `1` 最多点赞                                                                   |  否  | `0`  |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document explicitly enumerates collection of account-linked fields such as author_uid, author_sec_uid, author_signature, author_url, and engagement metadata without any privacy notice, use limitation, retention guidance, or legal/compliance warning. In a data-harvesting skill, this normalization of bulk collection of identifiers increases the risk of privacy misuse, profiling, and downstream unauthorized processing of personal data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The comment retrieval section documents collection of comment text plus user identifiers like user_uid, user_nickname, and user_sec_uid, again without any user-facing privacy disclosure or handling constraints. Because comments can contain personal opinions and account identifiers, bulk extraction materially raises risks of deanonymization, surveillance, and non-consensual profiling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file's user-facing descriptions, help examples, status messages, and error messages are all presented in Chinese, with no option to select another language or indication that the skill is intentionally limited to a Chinese-speaking audience. This creates a natural-language locale policy issue because the skill enforces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code reads an API token from the environment and then sends the normalized TikTok URL and query parameters to remote API methods. While the skill's purpose is to fetch TikTok posts, this file does not include any confirmation prompt or user-facing disclosure that the provided URL and associated request data will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI writes the full search output, including user-supplied query terms and returned TikTok data, to a local JSON file by default. In a data-research skill that processes potentially sensitive research targets, this creates an unnecessary persistence risk: other local users, backup systems, or later processes may access retained data without the operator realizing it is being stored.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code constructs outbound HTTPS requests that include a TOKEN header and JSON request data, which may transmit user or system data to a remote service. There is no confirmation prompt, user-facing notice, or explicit disclosure in this file about the network transmission or use of authentication credentials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JavaScript file contains user-facing validation and error messages entirely in Chinese, such as the comments and utils.printError strings on L11, L15, L19, L23, L53, L59, and L64. Under the policy criteria, forcing a specific language without user opt-in can be a natural-language policy violation unless the skill is clearly documented as region- or locale-specific, which is not evident in this file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation presents this file as the manifest and usage guide for the "tiktok-data-research" skill, but the sample output metadata names a different skill, "tiktok-creator-videos". This is an active documentation contradiction that could mislead downstream agents or operators about which skill produced the output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest-style JSON schema contains user-facing title and description fields only in Chinese, which can impose a specific language on users without any opt-in or documented locale restriction. The policy specifically calls for flagging language or locale constraints when they are forced and not justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON schema contains natural-language title and description fields exclusively in Chinese, which can impose a language requirement on users or downstream tooling without explicit opt-in. The policy allows locale constraints when they are documented and justified, but this file does not indicate that the schema is intentionally limited to Chinese-speaking users or a China-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The title and property descriptions are written entirely in Chinese, which imposes a specific language in the skill's user-facing schema metadata. There is no indication that the skill is China-specific or that users can choose another language, so this appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The schema title and description are written only in Chinese, which can impose a specific language/locale on users or downstream tooling without any opt-in or documented regional limitation. Under the policy, locale-specific language is acceptable only when the constraint is justified or the user is offered a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language description is entirely in Chinese and presents the skill as a general TikTok data assistant, with no indication that Chinese is optional or that the skill is intentionally limited to Chinese-speaking users. Under the policy, a fixed language without user opt-in or documented justification is a locale/language policy issue.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

文档上下文明确说明这是 tiktok-data-research 技能的参数说明,但统一输出示例中的 metadata.skill_name 被写成了 tiktok-creator-videos。这会让使用者误解该文件对应的实际技能身份,属于文档意图与对象不一致。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

Help text and runtime messages in this file are consistently presented in Chinese, and there is no indication of user opt-in or selectable locale. This can violate language/locale policy when a skill forces a specific language for all users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing error and help strings entirely in Chinese, including parser errors and generated help output. That forces a specific language for all users without opt-in or justification, which matches the natural-language locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Several natural-language strings returned to users or shown in logs are fixed in Chinese, such as error messages and retry notices. This enforces a specific language/locale without any visible user choice or documented locale constraint in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file contains natural-language comments and a thrown error message in Chinese, indicating a fixed language choice rather than offering locale flexibility. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless clearly justified as region-specific, which is not shown here.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16