Back to skill

Security audit

TikTok达人发现与洞察

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed read-only TikTok data helper that sends requested TikTok queries to its provider and saves returned results locally for later review.

Before installing, be comfortable sharing your GUAIKEI_API_TOKEN and requested TikTok keywords, URLs, or IDs with www.guaikei.com, and remember that returned public TikTok data, including comments and usernames, is saved as JSON in the system temp directory. Review or clear those logs if you work on a shared machine or handle regulated research data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (36)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A description-behavior mismatch is dangerous because it breaks the trust boundary that agents and reviewers rely on when deciding whether to invoke a skill. If the packaged implementation does not actually perform the documented TikTok read-only retrieval flow, users may unknowingly execute unrelated logic, which can conceal unauthorized actions, data exfiltration, or other unexpected behavior behind a benign-looking manifest.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This JSON schema contains user-facing title and description fields only in Chinese, which effectively forces a specific language for users consuming the schema. The file does not indicate that the skill is region-specific or provide any opt-in or alternative locale, matching the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON schema contains user-facing natural-language titles and descriptions entirely in Chinese, such as the schema title and multiple property descriptions. Because the file does not indicate that the skill is region-specific or provide an opt-in language choice, it may violate a language/locale policy that requires not forcing a specific language on users.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README includes very broad natural-language invocation examples such as asking the AI to search TikTok or analyze a creator, but it does not define activation boundaries, confirmation requirements, or exclusion conditions. In an agent setting, this can cause unintended tool execution during ordinary conversation, leading to unnecessary external requests, token consumption, and retrieval of third-party data the user did not explicitly mean to collect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation states that every run automatically writes logs to disk, but this retention behavior is not prominently disclosed near the onboarding and usage examples where users decide to run the skill. Because the tool fetches comments, creator data, and structured results, silent persistence can create privacy, compliance, and data-handling risks, especially on shared systems or in enterprise environments.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/options.md (reported line 14)May include surrounding context.

node scripts/tiktok/search-cli.js --keyword <关键词> [--sort <排序>] [--time <时间>] [--limit <数量>]

text

| 参数        | 缩写 | 作用       | 可选值                                                                                      | 必填 | 默认 |
| ----------- | :--: | ---------- | ------------------------------------------------------------------------------------------- | :--: | :--: |
| `--keyword` | `-k` | 搜索关键词 | 2–100 字符;不可含 `< > " ' &`,不可含 http 链接                                            |  是  |  —   |
| `--sort`    | `-s` | 排序方式   | `0` 相关度 / `1` 最多点赞                                                                   |  否  | `0`  |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation explicitly supports collecting TikTok comments, post metadata, and user identifiers such as user_uid, user_sec_uid, author_uid, and profile links, but provides no privacy, retention, consent, or permitted-use guidance. In a data-collection skill, that omission increases the risk of misuse, over-collection, noncompliant processing, and downstream privacy violations, especially when comments and user identifiers are exported as structured JSON at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The program writes full comment results to a local JSON file without a clear warning or consent mechanism before persistence. Because this skill is specifically designed to collect public comments, commenter identities, interaction metrics, and related metadata at scale, silent storage meaningfully increases privacy, compliance, and unintended data exposure risks beyond transient CLI output.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI persists full fetched post results to a local JSON file after displaying them, which creates an additional data sink beyond the user-requested stdout output. In this skill context, the results can include creator metadata and potentially comment or engagement-related data, so writing them to disk increases the risk of unintended retention, later disclosure, and misuse on shared hosts or agent environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

Search results are persisted to disk without an explicit user-facing warning or consent, which can expose potentially sensitive research activity, collected profile data, or comment data to other local users, backups, or endpoint monitoring tools. In the context of a TikTok discovery skill that may process large-scale creator intelligence, silent retention increases privacy and operational data-leak risk even if no remote exfiltration occurs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file’s natural-language interface is consistently Chinese-only, including comments, error messages, and generated help text. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Multiple user-visible error and log messages are hard-coded in Chinese, such as request failures, timeout messages, and retry logs. This imposes a specific language/locale without any visible choice or opt-in, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits user-facing warning and info text only in Chinese via string literals. That can violate language/locale policy because the skill forces a specific language without any visible user opt-in or justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language comments and user-facing error messages exclusively in Chinese, such as the validation errors printed to users. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest defines this skill as tiktok-kol-discovery, but the documented output example says metadata.skill_name is tiktok-creator-videos. This is an active documentation contradiction that can mislead agents relying on the declared output contract to verify which skill actually ran.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The title and description are written only in Chinese, which imposes a specific language in user-facing schema metadata. The file does not indicate that Chinese is optional, user-selected, or required for a region-specific purpose, so this appears to violate the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema contains human-readable title and description fields exclusively in Chinese, which imposes a specific language on downstream users or developers. The file does not indicate that Chinese is optional, configurable, or justified as a region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The title and property descriptions are written entirely in Chinese, and there is no surrounding text indicating that the skill is China-specific or that users can choose another language. This can conflict with a language/locale policy that requires user choice or explicit justification for locale constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This JSON schema is a manifest-type file, so vague-trigger review applies. The natural-language description says the skill fetches TikTok creator works and accepts either a homepage URL or SEC_UID, but it does not provide clearer scope constraints, examples, or exclusions for what qualifies as valid input, which can make invocation boundaries less explicit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON schema uses Chinese-only natural-language title and description text, which can impose a specific language/locale on downstream users or tools consuming the skill metadata. The file does not document that the skill is region-specific or offer any language choice, so it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The package description is entirely in Chinese, which indicates the skill is presented in a fixed language without offering any user choice or opt-in for locale. The policy specifically flags language or locale constraints when they are imposed without explicit user selection or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The documentation is entirely written in Chinese and the example output specifies a human-readable message field without indicating that language can be selected by the user. Under SQP-3, forcing a specific language without user opt-in can be a natural-language policy violation when no language choice or justification is documented.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

L115 在“统一输出信封”的示例中将 skill_name 写为 tiktok-creator-videos,而当前技能清单名称是 tiktok-kol-discovery。这会让文档对技能身份的说明与实际声明产生直接矛盾,属于文档意图与实际对象不一致。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This code sends user-supplied data (url, limit) and an auth token to remote API endpoints via requestApi, but the file contains no confirmation prompt, user-facing log/print, or explanatory comment/docstring disclosing that network transmission occurs. For a code-file review under SQP-2, that absence of visible disclosure is a qualifying missing-warning issue.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16