Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 99% confidence
- Finding
代码内容仅实现了一个通用 JavaScript CLI 参数解析器,包括读取参数值、识别短长选项、处理默认值/必填项、生成帮助文本和报错提示。它没有体现任何与 TikTok 相关的数据访问、视频/评论/达人查询、市场分析、舆情监控或爆款挖掘逻辑。该代码块的主要用途与声明的技能描述明显不一致,因此应判定为描述与行为不匹配。
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed TikTok public-data research tool that uses a third-party API token and saves fetched results locally, with no evidence of hidden execution, privilege escalation, or destructive behavior.
Install only if you are comfortable sending your GUAIKEI_API_TOKEN and TikTok search terms, profile URLs, or video IDs to www.guaikei.com. Treat exported comments and user identifiers as public personal data: limit retention, avoid unnecessary sharing, and delete temp logs when they are no longer needed.
代码内容仅实现了一个通用 JavaScript CLI 参数解析器,包括读取参数值、识别短长选项、处理默认值/必填项、生成帮助文本和报错提示。它没有体现任何与 TikTok 相关的数据访问、视频/评论/达人查询、市场分析、舆情监控或爆款挖掘逻辑。该代码块的主要用途与声明的技能描述明显不一致,因此应判定为描述与行为不匹配。
Without declared permissions the skill's intent is opaque and cannot be validated.
The manifest description is entirely written in Chinese and presents the invocation and usage conditions only in that language, which can amount to a language/locale constraint without explicit user opt-in. The file does not state that users may interact in other languages or choose their preferred language.
The description defines very broad trigger phrases for common TikTok-related research and analysis tasks, which can cause the skill to activate in many contexts beyond a narrowly intended scope. Over-broad activation increases the chance of unintended invocation, unnecessary access to external data collection capabilities, and accidental routing of user requests into scraping/monitoring behavior they did not explicitly request.
The entire README, including the example natural-language invocations, is written only in Chinese and frames usage as direct Chinese prompts to the AI. Under the stated policy, forcing a specific language without an explicit user choice or opt-in is a natural-language policy violation unless the locale constraint is clearly justified, which is not documented here.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
node scripts/tiktok/search-cli.js --keyword <关键词> [--sort <排序>] [--time <时间>] [--limit <数量>]
| 参数 | 缩写 | 作用 | 可选值 | 必填 | 默认 |
| ----------- | :--: | ---------- | ------------------------------------------------------------------------------------------- | :--: | :--: |
| `--keyword` | `-k` | 搜索关键词 | 2–100 字符;不可含 `< > " ' &`,不可含 http 链接 | 是 | — |
| `--sort` | `-s` | 排序方式 | `0` 相关度 / `1` 最多点赞 | 否 | `0` |
The skill is explicitly designed to collect TikTok comments and creator/user identifiers (user_uid, user_sec_uid, nicknames, signatures, author URLs) but the documentation provides no privacy, data-minimization, retention, or lawful-use guidance. In a data collection skill, that omission increases the risk of misuse, over-collection, and non-compliant handling of personal data, especially when users may treat the skill as approved for unrestricted scraping and analysis.
The script performs token-authenticated remote requests and later writes returned data locally without clearly warning the user that data is being transmitted to a third-party service and persisted on disk. In a research/data-analysis skill, this increases privacy and compliance risk because users may supply URLs or IDs tied to monitored accounts or sensitive investigations without realizing the storage and transfer implications.
The CLI writes the full fetched comment dataset to a local JSON file after completing the request. Comment data can contain personal data, usernames, sentiment, and potentially sensitive content, so persisting it by default creates an unnecessary data retention surface beyond the expected query/analysis behavior of the skill.
The script reads a sensitive environment variable (GUAIKEI_API_TOKEN) and uses it together with the target URL in createPostTask and getPostTask, which are network/API operations. Although network access is inherent to fetching remote TikTok data, this file does not explicitly warn users that their input and token are being sent to an external service.
The CLI persists fetched TikTok results to a local JSON file automatically, and those results may contain sensitive or regulated data such as comments, profile details, or research outputs. In a shared workstation, CI runner, or multi-user environment, silent persistence increases the risk of unintended data retention, local disclosure, and compliance/privacy issues because users may assume the tool is only printing transient output.
The CLI persists the full search output to a local JSON file, and the filename also embeds the user-supplied keyword. For a research tool that may process sensitive market research terms or proprietary investigation topics, this creates an information disclosure risk through unintended local retention, exposure to other local users/processes, backups, or shared workspaces.
The skill emits hard-coded Chinese messages such as validation errors and success/failure notices, which imposes a specific language on users. Under the policy, locale-specific behavior should either be optional or clearly documented as intentionally region-specific.
This code returns multiple user-visible error messages in Chinese, such as at L037, and similar strings continue throughout the file. Because the file does not offer language selection or document that the skill is intentionally Chinese-only, it violates the language/locale policy for natural-language content.
The manifest declares the skill name as "tiktok-research" at L002, but the documented JSON output example says metadata.skill_name is tiktok-creator-videos. This is an active documentation contradiction that can mislead callers about which skill produced the data and how to validate responses.
The title and description fields, including parameter descriptions, are entirely in Chinese. Because this file is a general JSON schema rather than a clearly region-specific compliance tool, forcing a single language without opt-in can violate language/locale policy expectations.
The schema title and field descriptions are written entirely in Chinese, which imposes a specific language/locale in natural-language metadata without any indication of user opt-in or region-specific justification. This matches the policy category for language or locale constraints that are not optional or documented.
This manifest-style JSON file contains all human-readable title and description fields in Chinese only, including the skill title and parameter descriptions. Because no locale choice, multilingual option, or region-specific justification is provided in the file, it may violate a language/locale policy requiring user opt-in or documented scope.
This JSON schema contains natural-language titles and descriptions entirely in Chinese, including the top-level title/description and many property descriptions. Because the file provides no indication that the skill is region-specific or that users can opt into this locale, it may violate language/locale policy requiring choice or justification.
This is a manifest-format file, so natural-language policy issues apply. The title and field descriptions force a single language/locale for user-facing schema documentation, but the file does not state that the skill is intentionally Chinese-only or region-specific, which can violate language-choice expectations.
This JSON schema contains title and description fields in Chinese throughout, including user-facing metadata such as the schema title and field descriptions. Because the file does not indicate that the skill is region-specific or provide any opt-in for language/locale, it may violate a language/locale policy requiring user choice or documented justification.
The natural-language description is entirely in Chinese and does not indicate that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. This can violate language or locale policy when a skill appears to impose a language without user opt-in or documented justification.
SQP-3 适用于所有文件。标题及全文均以中文固定描述该技能的使用方式,但未声明这是面向中文用户的区域性技能,也未提供其他语言或用户选择,可能构成语言/locale 强制约束。
该文件是当前技能的参数说明,但统一输出示例中的 metadata.skill_name 被写成了 tiktok-creator-videos,而清单中的技能名是 tiktok-research。这会让调用方误解该技能实际提供的能力边界和输出归属,属于文档与实际技能意图不一致。
The command description, help text, and runtime messages are written in Chinese, which imposes a specific language on users without any opt-in or locale-selection mechanism. This is a natural-language policy concern because the skill does not offer an alternative language or document that it is intentionally region-specific.
Detected: suspicious.exposed_secret_literal