Back to skill

Security audit

XHS Title Copywriter

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Xiaohongshu title-generation skill, but its trigger instructions are overly broad while it uses an API key, sends queries to an external service, and writes local report files.

Review before installing if you do not want ordinary creative prompts sent to RedFox. Use a scoped, revocable REDFOX_API_KEY, avoid entering sensitive topics or private business plans unless you intend them to be queried externally, and check where generated Markdown report files will be written.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (16)

Tainted flow: 'headers' from os.getenv (line 47, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/fetch_xhs_trends.py (reported line 61)May include surrounding context.

python
if debug:
                print(f"\n=== DEBUG: 第 {attempt + 1} 次尝试 ===", file=sys.stderr)

            response = requests.get(url, params=params, headers=headers, timeout=30)

            if debug:
                print(f"状态码: {response.status_code}", file=sys.stderr)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest presents the skill as a title-generation tool, but the behavior includes external data collection, API-key-based authentication, local file generation, and returning external links for further analysis. This mismatch can mislead users and orchestrators into granting or invoking broader capabilities than expected, increasing the chance of unintended data egress or over-privileged execution.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill states that any user input should be converted into a Xiaohongshu title workflow, creating an extremely broad trigger condition. In agent environments, this can cause unintended invocation on unrelated or sensitive prompts, potentially sending unexpected content to external services or producing irrelevant actions without clear user intent.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: xiaohongshu-title
description: 基于用户输入的任何信息生成小红书爆款标题的专业工具。无论用户输入什么,最终目标都是生成小红书爆款标题。
dependency:
  python:
  system:
---

# 小红书标题生成

## 1. 简介

基于用户输入的任何信息生成小红书爆款标题的专业工具 -- 通过查询小红书平台真实爆款数据,分析爆款标题的共同特征,结合用户输入的核心主题,自动生成 10 个高匹配度的小红书爆款标题,每个标题附带匹配指数、参考爆款和详细推荐理由。

**适用对象**�

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The usage guidance repeats the rule that regardless of what the user enters, the skill should proceed toward title generation. Repeating this ambiguous trigger increases the likelihood that the skill overrides user intent and activates external query/file behaviors in contexts where it should not run.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation materially differs from the declared skill purpose: instead of only generating Xiaohongshu titles from user input, it performs authenticated external trend-data collection and reporting. This capability mismatch is dangerous because it expands the trust boundary and data exposure surface beyond what users and reviewers would reasonably expect from a title-generation skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill’s invocation guidance is broad enough that ordinary user requests about products, topics, or trends could activate the skill even when the user did not explicitly ask for Xiaohongshu title generation. Overly broad triggering increases the chance of unintended routing, prompt hijacking surface, and misuse of external API-backed functionality without clear user intent.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.en.md (reported line 51)May include surrounding context.

md
### Quick-Reference Phrases

| Intent                  | Example                                                                                            | What You Get                                                                |
| ----------------------- | -------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------- |
| Title for a single item | "Write some viral Xiaohongshu titles for a sunscreen — key selling point: lightweight, non-greasy" | Aligns with viral samples by keyword, analyzes then outputs 10 candidates   |
| Regular track updates   | "Outfit track — want to post about fall/winter coats, give me a title set"                         | Extracts same-track patterns to iterate your title library                  |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README says users can 'directly use natural language' and '无需记忆固定命令', but it does not define clear trigger phrases, boundaries, or exclusion conditions. For a markdown skill description, this is an ambiguous invocation description that could overlap with ordinary requests and cause unintended activation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example '看看最近全站什么标题火,帮我改编几条' is broad and resembles ordinary brainstorming language rather than a narrowly scoped command. Without additional constraints, it may match common requests beyond the intended skill context.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares no explicit tool restrictions while its instructions require access to environment variables, outbound network calls, and file creation. In an agent framework, this widens the effective privilege boundary and can let an otherwise simple content-generation skill invoke sensitive capabilities unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

All user-facing instructions and required output format are fixed in Chinese, and the skill does not mention allowing the user to choose another language. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script loads an API credential and uses it to query an external service, even though the stated skill description suggests a narrow local content-generation function. In this context, undisclosed authenticated network access is risky because it can surprise operators, enable unintended data transfer, and conceal broader capabilities inside a seemingly simple skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

该脚本在请求头中固定设置 Accept-Language: zh-CN,zh;q=0.9,属于自然语言/区域设置的强制指定。文件中没有提供用户选择语言或解释该限制为何必要,因此符合语言/locale policy violation。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script defaults to writing results to a local Markdown file for one output mode, which exceeds the minimal expectations of a title-generation skill. Unexpected file creation can leak potentially sensitive query contents to disk, create persistence artifacts, and violate least-surprise or sandbox assumptions in agent environments.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Several scenario prompts are phrased as general content-help requests like '帮我写小红书标题' or '帮我改几条能发的' without specifying activation boundaries. In aggregate, these examples reinforce a vague trigger model instead of a clearly delimited invocation contract.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.