Back to skill

Security audit

TikTok社媒搜索与分析

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent read-only TikTok data lookup skill, with disclosed third-party API use and local result logging that users should understand before installing.

Before installing, confirm you are comfortable sending your API token and TikTok queries, profile URLs, video IDs, or comment targets to www.guaikei.com. Also account for the fact that successful runs save fetched public results, including usernames and comment text, under the system temp directory for later review; delete or manage those logs if your workflow has retention limits.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill that advertises structured TikTok analytics but reportedly only performs auxiliary terminal output is materially misleading. This weakens trust boundaries and can be abused as cover for non-obvious behavior, since users may authorize execution based on a false business purpose rather than the real code path.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill that advertises structured TikTok analytics but reportedly only performs auxiliary terminal output is materially misleading. This weakens trust boundaries and can be abused as cover for non-obvious behavior, since users may authorize execution based on a false business purpose rather than the real code path.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill that advertises structured TikTok analytics but reportedly only performs auxiliary terminal output is materially misleading. This weakens trust boundaries and can be abused as cover for non-obvious behavior, since users may authorize execution based on a false business purpose rather than the real code path.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and the rest of the markdown content consistently require Chinese comprehension, but the file does not state that the skill is Chinese-only or give users a language/locale option. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README forces a specific language/locale for all instructions and user-facing examples, and nowhere offers an alternative language or asks the user to opt in. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/options.md (reported line 14)May include surrounding context.

node scripts/tiktok/search-cli.js --keyword <关键词> [--sort <排序>] [--time <时间>] [--limit <数量>]

text

| 参数        | 缩写 | 作用       | 可选值                                                                                      | 必填 | 默认 |
| ----------- | :--: | ---------- | ------------------------------------------------------------------------------------------- | :--: | :--: |
| `--keyword` | `-k` | 搜索关键词 | 2–100 字符;不可含 `< > " ' &`,不可含 http 链接                                            |  是  |  —   |
| `--sort`    | `-s` | 排序方式   | `0` 相关度 / `1` 最多点赞                                                                   |  否  | `0`  |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation explicitly supports collection of public TikTok profile, post, and comment data including user identifiers and interaction metrics, but provides no privacy, retention, or acceptable-use guidance. In an agent context, this increases the chance of bulk collection, profiling, or downstream misuse of personal data without operator awareness or policy controls.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI writes full fetched comment results to a local file, creating persistent storage of potentially sensitive or regulated user-generated content without any visible consent, retention control, or path restrictions. Even though the data is public TikTok content, local persistence increases exposure through unintended disclosure, over-retention, or collection beyond the skill's declared read-oriented behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI writes the full fetched TikTok results to a local file via log.taskWrite after returning them to stdout. This creates an additional undisclosed persistence channel for potentially sensitive collected data, increasing retention and exposure risk if the host filesystem is shared, backed up, or later inspected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The program silently writes fetched results to a local JSON file without any user-facing warning in this flow. Because the skill is described as returning structured JSON, this hidden persistence can surprise users and create privacy, compliance, or data handling issues beyond the expected transient execution behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code presents user-facing descriptions, help output, status messages, and errors exclusively in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly justified, which is not evident in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JavaScript file contains natural-language strings exclusively in Chinese, including help text and error messages shown to end users. Under the policy, forcing a specific language without user opt-in or justification is a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code emits user-facing error strings in Chinese (for example, the filename and content validation errors) and later also prints success/failure messages in Chinese. For a general utility file, forcing a specific language without user opt-in matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language comments and user-visible error strings exclusively in Chinese, such as the validation messages printed to users. Because the file does not offer any language selection or indicate that the skill is intentionally limited to Chinese-speaking users, it creates a locale-policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest and surrounding documentation consistently describe this skill as "tiktok-social-media-search", but the JSON example in the output contract shows skill_name as tiktok-creator-videos. This is an active documentation inconsistency that can mislead integrators about what tool produced the output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and field descriptions are written entirely in Chinese, which imposes a specific language on users of the skill metadata. The file does not indicate that this is a region-specific tool or provide any opt-in or alternative locale, so it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JSON schema includes natural-language title and description fields that force a specific language/locale for human-readable content. The file does not state that the schema is intended only for Chinese-speaking users or offer any language/locale choice, which can violate language-policy expectations under the natural-language policy rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The title and property descriptions are entirely in Chinese, which can force a specific language experience on users or maintainers interacting with the schema. The file does not indicate that the skill is intentionally region-specific or provide any multilingual alternative, so this appears to be a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema contains user-facing natural-language fields such as title and description entirely in Chinese. Because the file does not indicate that the skill is China-specific or offer an alternative language, it effectively enforces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest-format JSON schema contains user-facing titles and descriptions entirely in Chinese, such as the title and field descriptions. Under the policy rule, forcing a specific language without opt-in or a documented region-specific justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON schema contains user-facing title and description fields only in Chinese, including the schema title and property descriptions. That imposes a specific language/locale without any visible opt-in or justification, which matches the natural-language policy violation criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example output envelope documents skill_name as tiktok-creator-videos, while the manifest identifies this skill as tiktok-social-media-search. This is an active documentation contradiction about the skill's identity and can mislead integrators about which capability set the output belongs to.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file states that network errors, timeouts, task creation, querying, and automatic retries occur, which means the skill contacts external services and may repeatedly send request data. The markdown explains behavior but does not provide a user-facing warning about external network activity or its implications for privacy, rate limits, or remote-service interaction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code sends a token plus user-provided search parameters (keyword, sort, time, limit) to remote API endpoints via requestApi, but the file contains no comment, log, prompt, or other disclosure indicating that user input and authentication context are transmitted over the network. For code files, outbound network operations that transmit user or system data should have some visible disclosure unless already clearly documented elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16