Back to skill

Security audit

TikTok定向舆情监测助手

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed, read-only TikTok data retrieval helper, with the main caveat that it sends queries to Guaikei and automatically saves returned public data locally.

Install only if you are comfortable sending TikTok keywords, target URLs or IDs, and your Guaikei API token to www.guaikei.com. Review and clean the temp-directory logs if queries, targets, comments, or usernames are sensitive for your organization.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (43)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad TikTok舆情监测助手 with multiple data-collection modes and analytical/reporting functions. However, this code chunk implements only one narrow sub-function: a command-line tool for retrieving comments for a given TikTok video URL/ID. It validates arguments, creates/polls a comment task, outputs structured JSON, and logs results. There is no evidence in this chunk of keyword-based search, blogger/video list retrieval, competitive monitoring, or any opinion-analysis/report-generation logic. While the comment-grabbing portion is consistent with one declared capability, the actual code does not match the overall declared purpose if this chunk is meant to represent the skill's behavior, because it omits most of the advertised core functionality and analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code does not implement any TikTok-specific behavior, network access, scraping, data collection, JSON output for TikTok entities, or public-opinion analysis. It only provides reusable command-line argument parsing and help-text generation. This is a materially different primary purpose from the declared TikTok monitoring assistant, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a full TikTok data collection and analysis tool. The supplied code chunk does not implement any of those capabilities. Instead, it performs a small utility function: reading local package metadata from package.json via filesystem access and returning the skill/package name with a fallback. This is materially different from the declared primary purpose. While utility code can be supporting infrastructure, based on this chunk alone the behavior shown is unrelated to the described TikTok monitoring functions, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly states that each run is automatically logged and elsewhere indicates logs may include user query terms or target TikTok URLs/IDs. Even if limited to public TikTok targets, retained logs can expose sensitive research topics, investigations, customer names, or monitoring targets to other local users, backup systems, or support staff, creating unnecessary data retention risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema is a manifest-like file, so natural-language content in titles and descriptions should not force a language unless the skill clearly documents that locale constraint. Lines L004-L005 present the schema title and description only in Chinese, and the same pattern continues across field descriptions, with no user opt-in or justification for a Chinese-only locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file presents all user-facing instructions, examples, warnings, and operational guidance exclusively in Chinese. Under the policy rule for language or locale constraints, this can be a violation when a skill effectively forces a specific language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/options.md (reported line 14)May include surrounding context.

node scripts/tiktok/search-cli.js --keyword <关键词> [--sort <排序>] [--time <时间>] [--limit <数量>]

text

| 参数        | 缩写 | 作用       | 可选值                                                                                      | 必填 | 默认 |
| ----------- | :--: | ---------- | ------------------------------------------------------------------------------------------- | :--: | :--: |
| `--keyword` | `-k` | 搜索关键词 | 2–100 字符;不可含 `< > " ' &`,不可含 http 链接                                            |  是  |  —   |
| `--sort`    | `-s` | 排序方式   | `0` 相关度 / `1` 最多点赞                                                                   |  否  | `0`  |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly describes collecting profile and comment data including identifiers such as author_uid, author_sec_uid, user_uid, nicknames, signatures, URLs, and interaction data, but does not clearly warn that these are privacy-sensitive fields or define handling limits. In a sentiment-monitoring context, this increases the risk of unnecessary collection, downstream retention, or misuse of personal data scraped from public profiles and comments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The functions send a user-provided TikTok URL and an authentication token to remote API endpoints via requestApi. In this file, there is no confirmation prompt, warning comment, or user-facing disclosure indicating that external network transmission of potentially sensitive data will occur.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI persists fetched TikTok comment data to a local JSON file after already printing the results, creating undisclosed data retention beyond the expected 'return structured JSON' behavior. Comments and metadata may contain personal or sensitive content, and silent local storage increases privacy, compliance, and accidental exposure risk on shared systems or agent runtimes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code writes full comment results to a local file without explicit user consent or a visible warning, which is a security/privacy issue in a sentiment-monitoring tool handling third-party user content. In agent or multi-user environments, these files can persist longer than intended and be accessed by other processes or users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Descriptions, examples, and runtime messages are presented only in Chinese, which enforces a specific language for users regardless of preference. The file does not indicate that this is a region-specific tool or provide any opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI writes fetched TikTok results to a local JSON file automatically after successful execution, but this persistence is not clearly disclosed in the user-facing behavior. Stored result sets may contain comments, usernames, links, and engagement metadata, creating unintended local data retention and possible exposure to other local users, backups, or later tooling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The script reads an API token from the environment and uses it to access an external backend, but the described skill metadata does not clearly disclose this external service dependency. This is primarily a transparency and trust-boundary issue: operators may unknowingly send user queries and retrieved data to a third-party service, which can affect privacy, data handling, and credential governance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script persists full search output to a local log file without explicit user notice or consent. Because TikTok search results can contain links, author identifiers, comments, and other potentially sensitive monitoring data, silent retention increases the risk of unintended disclosure, over-retention, or later compromise of stored data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code contains hard-coded Chinese user-facing strings for validation errors, and additional Chinese output appears later in the file. Under the policy, forcing a specific language without offering a user choice or documenting a justified locale restriction is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The success and failure messages shown to users are hard-coded in Chinese, which enforces a specific language in normal operation. The file does not indicate any user opt-in, language negotiation, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code returns multiple hard-coded Chinese messages such as "请求失败", "响应解析失败", and "GUAIKEI_API_TOKEN 无效, 请检查环境变量". Because the file provides no user opt-in, locale selection, or documented China-specific scope, it appears to enforce a specific language in violation of the language/locale policy.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

L217-L219 的示例元数据显示 skill_name 为 tiktok-creator-videos,但本文件清单 L002 明确该技能名是 tiktok-sentiment-monitor。这会让调用方误以为输出来自另一个技能,属于文档对实际技能身份的主动性误导,而不是单纯信息缺失。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The title and property descriptions are written only in Chinese, which imposes a specific language on users. This can violate language/locale policy when no user opt-in or justification for the locale restriction is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This JSON schema includes multiple human-readable titles and descriptions only in Chinese, such as the title and field descriptions. Because the file provides no user opt-in, alternative locale, or justification that the skill is China-specific, it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON schema contains user-facing natural-language strings such as the title and parameter descriptions entirely in Chinese. Because the file does not indicate that the skill is region-specific or provide any user language/locale choice, it can violate language/locale policy by implicitly forcing one language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON schema contains human-readable title and description fields entirely in Chinese, which can force a specific language experience for users or integrators who do not read that locale. The file does not provide an alternative language, opt-in mechanism, or justification for a Chinese-only constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON schema contains natural-language titles and descriptions exclusively in Chinese, including the top-level title/description and most property descriptions. Because the file does not indicate that the skill is China-specific or provide an opt-in language choice, it may violate a language/locale policy requiring neutral or user-selectable language.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16