T09 · Insecure Skill Coding Practices
- Location
references/api.md:5- Finding
API Credentials and Account Data Transmitted Over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Xiaohongshu API helper, but it directs agents to send API keys and publishable account content over plaintext HTTP and lacks clear confirmation safeguards for public posting.
Review this skill carefully before installing. Only use it with a scoped API key, do not put keys in URLs, avoid sending secrets or unpublished content over HTTP, and require a manual confirmation of the exact account and content before any publish request. If the service cannot be used over HTTPS, avoid authenticated or publishing operations.
references/api.md:5API Credentials and Account Data Transmitted Over Plaintext HTTP
The trigger phrases include very broad terms like '小红书', 'xhs', 'API 调用', and '笔记搜索', which can match ordinary conversation and invoke a capability that performs external API actions. In this skill, that overlap is more dangerous because the skill can query accounts and publish content, increasing the chance of unintended activation and data transmission.
The workflow explicitly instructs use of an exec tool to perform Python requests against a third-party API that can publish notes and manage accounts, but it provides no warning about external side effects, credential handling, or user-consent requirements. This is dangerous because it can lead to silent transmission of user data or unauthorized modification of external accounts and content.
The document instructs users to send API credentials and data to an external service over plain HTTP, and it does so without any warning about credential exposure, data transmission, or transport security. Because the API key may be placed in headers or query parameters, this increases the risk of interception, leakage in logs, and inadvertent disclosure during use.
This example performs an external network request containing an API key and user-supplied search content to a third-party domain. In this skill, the risk is heightened because the documented base URL uses HTTP rather than HTTPS, so credentials and request data could be exposed in transit or via intermediary logging.
url = "http://redapi.cn/api/external-api/search" headers = {"X-API-Key": "YOUR_API_KEY", "Content-Type": "application/json"} data = {"keyword": "美食推荐", "page": 1, "page_size": 20, "sort": "MOST_POPULAR"} response = requests.post(url, headers=headers, json=data)
**响应示例**:
This request transmits note identifiers and an xsec_token to an external service, again using an insecure HTTP base URL according to the document. Tokens and metadata sent over plaintext transport can be intercepted, replayed, or leaked, especially in automated agent environments.
url = "http://redapi.cn/api/external-api/note-detail" headers = {"X-API-Key": "YOUR_API_KEY", "Content-Type": "application/json"} data = {"note_id": "67685c7f000000001e00f5b9", "xsec_token": ""} response = requests.post(url, headers=headers, json=data)
**响应示例**:
The publish endpoint can create or schedule posts on an external account, but the documentation does not clearly warn that using it performs real account actions with externally visible effects. In an agent skill context, omission of that warning increases the chance of unintended posting, abuse of connected accounts, or user surprise about irreversible side effects.
This example sends content and account identifiers to an external endpoint that can publish on behalf of a user account, creating both data exfiltration and real-world action risk. In context, this is more dangerous than a read-only call because misuse or silent invocation could lead to unauthorized posting, reputational harm, or account abuse, especially since the documentation uses insecure HTTP.
"image_urls": ["https://example.com/image1.jpg", "https://example.com/image2.jpg"], "topics": ["美食", "家常菜"] } response = requests.post(url, headers=headers, json=data)
**响应示例**:
All natural-language instructions and invocation text in the skill are presented only in Chinese, with no indication that users may interact in another language or that the language restriction is intentional and required. Under the stated policy, a skill should not implicitly force a specific language without opt-in or clear justification.
The natural-language content of the skill file is fully Chinese and does not indicate that users can choose another language or that the documentation is intentionally limited to a Chinese-only audience. The stated policy calls for flagging language or locale restrictions when a specific language is effectively forced without opt-in.
No suspicious patterns detected.