Back to skill

Security audit

TikTok竞品洞察分析

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed, read-only TikTok data lookup skill that uses a configured API token and saves fetched results locally for later review.

Before installing, confirm you are comfortable sending your GUAIKEI_API_TOKEN and TikTok queries or target URLs to www.guaikei.com. Treat saved temp-directory logs as retained datasets: delete them when no longer needed and avoid sharing outputs containing usernames, stable IDs, or comments unless you have a compliant basis to do so.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (32)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a full TikTok competitor intelligence and data collection tool with three specific business capabilities. However, the supplied code chunk only implements a reusable command-line argument parser and help-text generator. This is not merely a supporting detail if evaluated in isolation: the code itself does not perform any of the declared TikTok-related behaviors, access TikTok resources, or implement search/scraping/analysis functions. Therefore, the code chunk's actual behavior does not accurately represent the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description is about TikTok data collection and competitor-analysis features: keyword search, fetching creators' public works, and scraping video comments. The supplied code chunk does none of those things. It defines a helper function that validates filename/content inputs, sanitizes the filename, creates a directory in the OS temp path, and writes content to a local file. Local logging can be a supporting detail in a larger system, but this chunk's actual behavior is solely filesystem logging, which is not represented in the declared capabilities and is unrelated to the described end-user functionality. Therefore this chunk does not accurately match the declared purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/options.md (reported line 14)May include surrounding context.

node scripts/tiktok/search-cli.js --keyword <关键词> [--sort <排序>] [--time <时间>] [--limit <数量>]

text

| 参数        | 缩写 | 作用       | 可选值                                                                                      | 必填 | 默认 |
| ----------- | :--: | ---------- | ------------------------------------------------------------------------------------------- | :--: | :--: |
| `--keyword` | `-k` | 搜索关键词 | 2–100 字符;不可含 `< > " ' &`,不可含 http 链接                                            |  是  |  —   |
| `--sort`    | `-s` | 排序方式   | `0` 相关度 / `1` 最多点赞                                                                   |  否  | `0`  |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The documentation explicitly supports bulk collection of public profile, post, and comment data, including user identifiers and engagement metadata, but provides no privacy, consent, retention, or acceptable-use guidance. In a competitive-intelligence scraping context, this increases the risk of misuse, over-collection, or noncompliant handling of personal data, especially when comments and user IDs are exported as structured JSON at scale.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI persists full fetched comment results to a local JSON file without any explicit disclosure or consent flow, which creates an unintended data-retention channel. Since comment data may include usernames, profile links, interaction metrics, and other scraped content, this increases privacy, compliance, and accidental exposure risk on shared systems or in downstream backups.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The program silently saves fetched comment data to a local JSON file, despite presenting itself primarily as a retrieval/output tool. This can surprise users and cause scraped comment datasets to remain on disk where other local users, processes, backup systems, or logs may later access them.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The warning and info strings shown to users are written only in Chinese, and the file provides no user opt-in, language selection, or documented locale justification. This can violate a language/locale policy requiring neutral defaults or explicit user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JavaScript file contains natural-language comments and user-visible error messages entirely in Chinese, such as the validation errors printed at L11, L15, L19, L23, L53, L59, and L64. Under the policy, forcing a specific language without user opt-in or clear region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file defines the skill as tiktok-insight at L002, but the documented output contract shows metadata.skill_name as tiktok-creator-videos. This is an active documentation contradiction that can mislead integrators about which tool produced the output.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description at L003 scopes the skill to keyword search, creator-post retrieval, and video-comment retrieval with structured JSON output. However, the documentation later states that each run automatically writes a log file and specifies storage behavior, which is an additional behavior beyond the three declared user-facing capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest/config file contains human-facing title and description text only in Chinese, which imposes a specific language/locale without any opt-in or indication that the skill is intentionally region-specific. Under the policy rules, locale-specific language is only acceptable when the constraint is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The user-facing property descriptions for required CLI inputs are only in Chinese, which can force a specific language experience for users or integrators. The file does not state that the tool is China-specific or otherwise justify the locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON schema contains titles and descriptions exclusively in Chinese, such as the schema title and field descriptions. Because the file does not offer an alternative language or explain that the schema is intentionally limited to a Chinese-speaking context, it may violate the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions throughout, including the top-level title/description and nearly all property descriptions. Because SQP-3 applies to all file types, this is a locale-policy concern when no language choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON schema contains user-facing title and description fields exclusively in Chinese, including parameter descriptions and usage text. Because the file does not offer a language choice or explain that the skill is intentionally region- or locale-specific, it creates a natural-language locale constraint without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON schema contains user-facing title and description strings exclusively in Chinese, including field descriptions that consumers of the skill may rely on. Under the stated policy, forcing a specific language without opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description is written entirely in Chinese and provides no indication that other languages are supported. For a general-purpose skill package, this can constitute a language-policy issue because it implicitly fixes the skill's user-facing description to a specific language without opt-in or documented locale scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

L113-L116 的统一输出示例将 metadata.skill_name 写为 "tiktok-creator-videos",而当前清单上下文中的技能名称是 "tiktok-insight"。这不是单纯信息缺失,而是文档中明确声明了一个不同的技能标识,可能误导调用方对实际技能身份和用途的理解。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The stated purpose focuses on TikTok comment acquisition and analysis outputs. This file also depends on reading a credential from process.env, which is an operational capability beyond the manifest's described analytical functions and is not explicitly disclosed there.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code presents command descriptions and output messages in Chinese only, such as the flag descriptions and later status messages. That can violate a language/locale policy when a skill is not explicitly documented as Chinese-only and does not offer user opt-in or locale selection.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest focuses on TikTok competitive-insight functions such as searching keywords, listing posts, and fetching comments. This file additionally depends on process.env.GUAIKEI_API_TOKEN for authentication, which is an operational capability not disclosed in the stated purpose and could matter for trust and deployment expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes capabilities around keyword search, post retrieval, and comment extraction with structured JSON output. In addition to returning JSON, this command persists the full result set to a local file via log.taskWrite, which is additional behavior not stated in the skill description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code embeds user-facing flag descriptions, help text, and notices entirely in Chinese, which effectively forces a specific language for interaction. The file does not offer any locale selection or opt-in mechanism, so it may violate a language/locale policy requiring user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains comments, error messages, and help text entirely in Chinese, including thrown errors and CLI help output. That enforces a specific language for users without any visible opt-in or locale selection, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16