Back to skill

Security audit

TikTok数据分析与市场调研

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed TikTok public-data research tool that uses a third-party API token and saves fetched results locally, with no evidence of hidden execution, privilege escalation, or destructive behavior.

Install only if you are comfortable sending your GUAIKEI_API_TOKEN and TikTok search terms, profile URLs, or video IDs to www.guaikei.com. Treat exported comments and user identifiers as public personal data: limit retention, avoid unnecessary sharing, and delete temp logs when they are no longer needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (34)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码内容仅实现了一个通用 JavaScript CLI 参数解析器,包括读取参数值、识别短长选项、处理默认值/必填项、生成帮助文本和报错提示。它没有体现任何与 TikTok 相关的数据访问、视频/评论/达人查询、市场分析、舆情监控或爆款挖掘逻辑。该代码块的主要用途与声明的技能描述明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description is entirely written in Chinese and presents the invocation and usage conditions only in that language, which can amount to a language/locale constraint without explicit user opt-in. The file does not state that users may interact in other languages or choose their preferred language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description defines very broad trigger phrases for common TikTok-related research and analysis tasks, which can cause the skill to activate in many contexts beyond a narrowly intended scope. Over-broad activation increases the chance of unintended invocation, unnecessary access to external data collection capabilities, and accidental routing of user requests into scraping/monitoring behavior they did not explicitly request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire README, including the example natural-language invocations, is written only in Chinese and frames usage as direct Chinese prompts to the AI. Under the stated policy, forcing a specific language without an explicit user choice or opt-in is a natural-language policy violation unless the locale constraint is clearly justified, which is not documented here.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/options.md (reported line 14)May include surrounding context.

node scripts/tiktok/search-cli.js --keyword <关键词> [--sort <排序>] [--time <时间>] [--limit <数量>]

text

| 参数        | 缩写 | 作用       | 可选值                                                                                      | 必填 | 默认 |
| ----------- | :--: | ---------- | ------------------------------------------------------------------------------------------- | :--: | :--: |
| `--keyword` | `-k` | 搜索关键词 | 2–100 字符;不可含 `< > " ' &`,不可含 http 链接                                            |  是  |  —   |
| `--sort`    | `-s` | 排序方式   | `0` 相关度 / `1` 最多点赞                                                                   |  否  | `0`  |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill is explicitly designed to collect TikTok comments and creator/user identifiers (user_uid, user_sec_uid, nicknames, signatures, author URLs) but the documentation provides no privacy, data-minimization, retention, or lawful-use guidance. In a data collection skill, that omission increases the risk of misuse, over-collection, and non-compliant handling of personal data, especially when users may treat the skill as approved for unrestricted scraping and analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script performs token-authenticated remote requests and later writes returned data locally without clearly warning the user that data is being transmitted to a third-party service and persisted on disk. In a research/data-analysis skill, this increases privacy and compliance risk because users may supply URLs or IDs tied to monitored accounts or sensitive investigations without realizing the storage and transfer implications.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI writes the full fetched comment dataset to a local JSON file after completing the request. Comment data can contain personal data, usernames, sentiment, and potentially sensitive content, so persisting it by default creates an unnecessary data retention surface beyond the expected query/analysis behavior of the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script reads a sensitive environment variable (GUAIKEI_API_TOKEN) and uses it together with the target URL in createPostTask and getPostTask, which are network/API operations. Although network access is inherent to fetching remote TikTok data, this file does not explicitly warn users that their input and token are being sent to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The CLI persists fetched TikTok results to a local JSON file automatically, and those results may contain sensitive or regulated data such as comments, profile details, or research outputs. In a shared workstation, CI runner, or multi-user environment, silent persistence increases the risk of unintended data retention, local disclosure, and compliance/privacy issues because users may assume the tool is only printing transient output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI persists the full search output to a local JSON file, and the filename also embeds the user-supplied keyword. For a research tool that may process sensitive market research terms or proprietary investigation topics, this creates an information disclosure risk through unintended local retention, exposure to other local users/processes, backups, or shared workspaces.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill emits hard-coded Chinese messages such as validation errors and success/failure notices, which imposes a specific language on users. Under the policy, locale-specific behavior should either be optional or clearly documented as intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code returns multiple user-visible error messages in Chinese, such as at L037, and similar strings continue throughout the file. Because the file does not offer language selection or document that the skill is intentionally Chinese-only, it violates the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest declares the skill name as "tiktok-research" at L002, but the documented JSON output example says metadata.skill_name is tiktok-creator-videos. This is an active documentation contradiction that can mislead callers about which skill produced the data and how to validate responses.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The title and description fields, including parameter descriptions, are entirely in Chinese. Because this file is a general JSON schema rather than a clearly region-specific compliance tool, forcing a single language without opt-in can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The schema title and field descriptions are written entirely in Chinese, which imposes a specific language/locale in natural-language metadata without any indication of user opt-in or region-specific justification. This matches the policy category for language or locale constraints that are not optional or documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This manifest-style JSON file contains all human-readable title and description fields in Chinese only, including the skill title and parameter descriptions. Because no locale choice, multilingual option, or region-specific justification is provided in the file, it may violate a language/locale policy requiring user opt-in or documented scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema contains natural-language titles and descriptions entirely in Chinese, including the top-level title/description and many property descriptions. Because the file provides no indication that the skill is region-specific or that users can opt into this locale, it may violate language/locale policy requiring choice or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This is a manifest-format file, so natural-language policy issues apply. The title and field descriptions force a single language/locale for user-facing schema documentation, but the file does not state that the skill is intentionally Chinese-only or region-specific, which can violate language-choice expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON schema contains title and description fields in Chinese throughout, including user-facing metadata such as the schema title and field descriptions. Because the file does not indicate that the skill is region-specific or provide any opt-in for language/locale, it may violate a language/locale policy requiring user choice or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The natural-language description is entirely in Chinese and does not indicate that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. This can violate language or locale policy when a skill appears to impose a language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

SQP-3 适用于所有文件。标题及全文均以中文固定描述该技能的使用方式,但未声明这是面向中文用户的区域性技能,也未提供其他语言或用户选择,可能构成语言/locale 强制约束。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

该文件是当前技能的参数说明,但统一输出示例中的 metadata.skill_name 被写成了 tiktok-creator-videos,而清单中的技能名是 tiktok-research。这会让调用方误解该技能实际提供的能力边界和输出归属,属于文档与实际技能意图不一致。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command description, help text, and runtime messages are written in Chinese, which imposes a specific language on users without any opt-in or locale-selection mechanism. This is a natural-language policy concern because the skill does not offer an alternative language or document that it is intentionally region-specific.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16