Back to skill

Security audit

TikTok热门视频检索

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed TikTok public-data lookup tool that uses a third-party API token and saves result logs locally, so users should treat the collected social data and token carefully.

Install only if you are comfortable sending your GUAIKEI_API_TOKEN and TikTok query targets to www.guaikei.com. Review and delete temp log files when they contain usernames, comments, or other data you do not want retained locally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

该代码块的实际功能与声明中的第①项“关键词搜索”基本一致:支持关键词、排序、发布时间和数量参数,并返回 JSON 结果。但声明将整个技能描述为一个包含 3 项能力的工具,而本代码块仅展示搜索 CLI 的实现,没有任何与“按主页链接/用户名获取博主作品”或“按视频链接/作品 ID 获取评论”相关的参数、API 调用、处理逻辑或输出字段。因此,就“整个已声明能力集合是否被该代码块准确代表”而言,存在描述与行为不完全一致的情况。未发现额外越权或无关能力;日志写入属于实现细节,不构成额外能力。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a clear description-to-code mismatch. The declared purpose describes a TikTok data collection/search capability with three concrete functions: searching popular videos by keyword, retrieving a creator's public posts, and scraping comments. However, the supplied code chunk only contains a reusable CLI argument parsing utility (parseArgs, readValueAfterFlag, buildHelp). It handles command-line options and help generation, which is merely a supporting utility and does not itself implement any of the declared TikTok-facing behaviors. No network requests, TikTok identifiers, scraping logic, data extraction, sorting/filtering of TikTok results, or JSON output construction for TikTok entities are present in this chunk. Therefore, the actual behavior does not match the declared primary functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This code chunk’s behavior is materially different from the declared end-user purpose. The declared description promises TikTok data retrieval features, but the actual code is a generic log writer using fs/path/os to create directories and write files in a temp folder. While logging could be a supporting utility in a larger system, this supplied chunk itself does not implement any of the stated TikTok-related capabilities. It also accesses the local filesystem, which is not mentioned in the description. Therefore, for this chunk, the description does not accurately represent the actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a TikTok data collection and analysis skill with three core capabilities: keyword hot-video search, creator content retrieval, and comment extraction. The supplied code chunk does none of these. It only accesses the local filesystem to read package.json and returns the package name, using a fallback value if needed. This is a materially different behavior and primary purpose from the declared TikTok scraping/search functionality, so it is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/options.md (reported line 14)May include surrounding context.

node scripts/tiktok/search-cli.js --keyword <关键词> [--sort <排序>] [--time <时间>] [--limit <数量>]

text

| 参数        | 缩写 | 作用       | 可选值                                                                                      | 必填 | 默认 |
| ----------- | :--: | ---------- | ------------------------------------------------------------------------------------------- | :--: | :--: |
| `--keyword` | `-k` | 搜索关键词 | 2–100 字符;不可含 `< > " ' &`,不可含 http 链接                                            |  是  |  —   |
| `--sort`    | `-s` | 排序方式   | `0` 相关度 / `1` 最多点赞                                                                   |  否  | `0`  |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document explicitly supports collection of TikTok author and commenter identifiers such as author_uid, author_sec_uid, user_uid, and user_sec_uid, but provides no user-facing privacy notice, purpose limitation, or handling guidance. In a data-harvesting skill context, this increases the risk of bulk profiling, correlation across datasets, and misuse of personal data even if the data is publicly accessible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code uses a credential from the environment and transmits user-supplied TikTok URLs and request parameters to a remote API without any explicit notice in this file that the operation sends data off-host. In a skill that processes public social-media content this network behavior is functionally expected, but the lack of transparency can still mislead users about where their inputs and retrieved data are being sent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI persists fetched TikTok comment results to a local JSON file even though the described behavior is to return structured JSON output. Comment data can contain personal information or sensitive user-generated content, so silently writing it to disk creates an unnecessary data retention and disclosure risk on shared systems or developer machines.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI writes retrieved comment data to a local file without clearly informing the user, which creates a privacy and data retention risk. Even if the comments are public, the saved JSON may aggregate usernames, interaction data, and metadata in a way that is more sensitive than transient console output.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI writes the full retrieved results to a local JSON log file without the manifest disclosing local persistence. Because the output may include scraped profile, content, and comment data, this creates an unintended data-retention surface on disk that could expose sensitive or regulated data to other local users, backup systems, or later compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code presents all flag descriptions, help text, and runtime messages in Chinese only, which imposes a specific language on users without offering a language selection or documenting a justified locale restriction. The policy explicitly flags language or locale constraints when they are forced without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code emits user-visible error messages in Chinese string literals, and later also prints a Chinese success message. That imposes a specific language on users without any visible choice or documented locale constraint, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The success and failure log messages shown to users are fixed in Chinese, with no indication that the user can opt into that language or that the skill is region-specific. This is a natural-language policy issue because it forces a locale choice in user-facing output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple natural-language strings shown to users or operators, such as error messages and retry logs, are fixed in Chinese. This can violate language/locale policy when the skill does not offer a language choice or document a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code includes user-visible warning and info strings only in Chinese ("警告..." and "已使用配置的私有TOKEN"). The policy for natural-language behavior requires avoiding a forced language/locale unless the skill offers user opt-in or clearly documents a justified regional constraint, which is not present in this file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The output contract example reports skill_name as tiktok-creator-videos while the manifest declares tiktok-videos-search. This identity mismatch can cause downstream agents or validation logic to attribute output to the wrong tool, weakening trust boundaries and enabling confusion or policy-routing errors when multiple skills exist.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions for the command-line parameter schema. Because the file provides no opt-in, alternative locale, or justification that the skill is region- or language-specific, it may violate a language/locale policy requiring user choice or documented constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The title and description strings specify the schema metadata exclusively in Chinese. Because this file does not document that the skill is region-specific or that users can choose their preferred language, it may violate a language/locale policy requiring opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The title and property descriptions are written only in Chinese, which imposes a specific language on users without any visible opt-in or alternative locale. Under the policy, locale or language constraints should be optional or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON schema is a manifest/config-type file, so SQP-3 applies. Multiple natural-language strings such as the title and descriptions require Chinese comprehension, which can violate a language/locale policy when no user opt-in or justification for the locale restriction is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The title and description are written entirely in Chinese, and the schema provides no indication that this skill is China-specific or that users can choose another language. Per the policy, forcing a specific language without opt-in or documented locale justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON schema contains user-facing natural-language titles and descriptions exclusively in Chinese, including the top-level title/description and field descriptions. Under the language/locale policy rule, forcing a specific language without opt-in is a policy concern unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The package description is entirely in Chinese and does not indicate that the skill is Chinese-only, region-specific, or that users can choose another language. Under the language/locale policy, this can be a natural-language policy issue because it implicitly fixes the skill's presentation to one language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The entire skill documentation is presented only in Chinese, including the human-readable message field example, with no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking context. Per SQP-3, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16