Back to skill

Security audit

xiaohongshu-matrix-manager

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Xiaohongshu API helper, but it directs agents to send API keys and publishable account content over plaintext HTTP and lacks clear confirmation safeguards for public posting.

Review this skill carefully before installing. Only use it with a scoped API key, do not put keys in URLs, avoid sending secrets or unpublished content over HTTP, and require a manual confirmation of the exact account and content before any publish request. If the service cannot be used over HTTPS, avoid authenticated or publishing operations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
references/api.md:5
Finding

API Credentials and Account Data Transmitted Over Plaintext HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include very broad terms like '小红书', 'xhs', 'API 调用', and '笔记搜索', which can match ordinary conversation and invoke a capability that performs external API actions. In this skill, that overlap is more dangerous because the skill can query accounts and publish content, increasing the chance of unintended activation and data transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow explicitly instructs use of an exec tool to perform Python requests against a third-party API that can publish notes and manage accounts, but it provides no warning about external side effects, credential handling, or user-consent requirements. This is dangerous because it can lead to silent transmission of user data or unauthorized modification of external accounts and content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document instructs users to send API credentials and data to an external service over plain HTTP, and it does so without any warning about credential exposure, data transmission, or transport security. Because the API key may be placed in headers or query parameters, this increases the risk of interception, leakage in logs, and inadvertent disclosure during use.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This example performs an external network request containing an API key and user-supplied search content to a third-party domain. In this skill, the risk is heightened because the documented base URL uses HTTP rather than HTTPS, so credentials and request data could be exposed in transit or via intermediary logging.

Content

Scanner excerpt · references/api.md (reported line 86)May include surrounding context.

url = "http://redapi.cn/api/external-api/search" headers = {"X-API-Key": "YOUR_API_KEY", "Content-Type": "application/json"} data = {"keyword": "美食推荐", "page": 1, "page_size": 20, "sort": "MOST_POPULAR"} response = requests.post(url, headers=headers, json=data)

text

**响应示例**:

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This request transmits note identifiers and an xsec_token to an external service, again using an insecure HTTP base URL according to the document. Tokens and metadata sent over plaintext transport can be intercepted, replayed, or leaked, especially in automated agent environments.

Content

Scanner excerpt · references/api.md (reported line 129)May include surrounding context.

url = "http://redapi.cn/api/external-api/note-detail" headers = {"X-API-Key": "YOUR_API_KEY", "Content-Type": "application/json"} data = {"note_id": "67685c7f000000001e00f5b9", "xsec_token": ""} response = requests.post(url, headers=headers, json=data)

text

**响应示例**:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The publish endpoint can create or schedule posts on an external account, but the documentation does not clearly warn that using it performs real account actions with externally visible effects. In an agent skill context, omission of that warning increases the chance of unintended posting, abuse of connected accounts, or user surprise about irreversible side effects.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

This example sends content and account identifiers to an external endpoint that can publish on behalf of a user account, creating both data exfiltration and real-world action risk. In context, this is more dangerous than a read-only call because misuse or silent invocation could lead to unauthorized posting, reputational harm, or account abuse, especially since the documentation uses insecure HTTP.

Content

Scanner excerpt · references/api.md (reported line 179)May include surrounding context.

"image_urls": ["https://example.com/image1.jpg", "https://example.com/image2.jpg"], "topics": ["美食", "家常菜"] } response = requests.post(url, headers=headers, json=data)

text

**响应示例**:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

All natural-language instructions and invocation text in the skill are presented only in Chinese, with no indication that users may interact in another language or that the language restriction is intentional and required. Under the stated policy, a skill should not implicitly force a specific language without opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The natural-language content of the skill file is fully Chinese and does not indicate that users can choose another language or that the documentation is intentionally limited to a Chinese-only audience. The stated policy calls for flagging language or locale restrictions when a specific language is effectively forced without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.