Back to skill

Security audit

Xiaohongshu MCP Installer

Security checks for vulnerabilities and agentic risk

Overview

This skill is an installer for a Xiaohongshu MCP service, but it makes persistent system changes, runs unverified downloaded code, and handles login cookies in ways users should review carefully before installing.

Install only if you intentionally want a persistent Xiaohongshu MCP service and are comfortable reviewing the installer first. Prefer a pinned, verified release; avoid the cookie import path unless you understand that browser cookies can act like account credentials; and check or modify the service setup so it runs as an unprivileged user and does not kill unrelated processes or edit unrelated cron entries.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/install.sh:125
Finding

Root systemd service executes a user-writable binary

Content
View full analysis
/tmp/xhs-mcp.service << SERVICEEOF [Unit] Description=Xiaohongshu MCP Service After=network.target [Service] WorkingDirectory=${INSTALL_DIR} ExecStart=${INSTALL_DIR}/xhs-mcp-bin server --port ${PORT} Restart=always RestartSec=5 [Install] WantedBy=multi-user.target SERVICEEOF sudo mv /tmp/xhs-mcp.service /etc/systemd/system/xhs-mcp.service sudo systemctl daemon-reload sudo systemctl enable xhs-mcp sudo systemctl start xhs-mcp ``` A corresponding unsafe example also appears in `SKILL.md:137-156`, where the service runs a binary from `/root/xiaohongshu-mcp` without an explicit `User=` directive. ### Technical Analysis The generated systemd unit does not specify `User=` or `Group=`, so systemd runs the service as root. In the executable installer, `INSTALL_DIR` is derived from the invoking user's `$HOME`: ```bash HOME_DIR="$HOME" INSTALL_DIR="$HOME_DIR/xiaohongshu-mcp" ``` The downloaded executable remains in that user-controlled directory. If an unprivileged user can replace or modify `xhs-mcp-bin`, the next systemd restart or system reboot causes systemd to execute the replacement with root privileges. This violates least privilege. The MCP server does not require root privileges merely to listen on port 18060, which is an unprivileged port. ### Attack Path 1. A user runs the installer and authorizes its `sudo` operations. 2. The installer registers `/etc/systemd/system/xhs-mcp.service`. 3. The unit points `ExecStart` to `${HOME}/xiaohongshu-mcp/xhs-mcp-bin`. 4. The service runs as root because no `User=` directive is present. 5. The user, malware running as that user, or another principal with write access replaces `xhs-mcp-bin`. 6. The attacker triggers `systemctl restart xhs-mcp ...[truncated 542 chars]
Remediation
View remediation

T06 · System Persistence

Error
Location
scripts/install.sh:94
Finding

Automatic installation of redundant persistent services and scheduled tasks

Content
View full analysis
"$PLIST" << PLISTEOF Labelcom.openclaw.xhs-mcp ProgramArguments ${INSTALL_DIR}/xhs-mcp-bin server --port ${PORT} WorkingDirectory${INSTALL_DIR} RunAtLoad KeepAlive StandardOutPath${INSTALL_DIR}/mcp.log StandardErrorPath${INSTALL_DIR}/mcp.log PLISTEOF launchctl unload "$PLIST" 2>/dev/null || true launchctl load "$PLIST" ``` ```bash cat > "$INSTALL_DIR/watchdog.sh" << 'WATCHDOG' #!/bin/bash PORT=18060 LOG="$HOME/xiaohongshu-mcp/watchdog.log" if ! curl -s --max-time 3 http://localhost:$PORT/health > /dev/null 2>&1; then echo "$(date '+%Y-%m-%d %H:%M:%S') 重启服务..." >> "$LOG" lsof -ti :$PORT | xargs kill -9 2>/dev/null sleep 2 cd "$HOME/xiaohongshu-mcp" nohup ./xhs-mcp-bin server --port $PORT >> mcp.log 2>&1 & fi WATCHDOG chmod +x "$INSTALL_DIR/watchdog.sh" if [ "$OS" = "Darwin" ]; then (crontab -l 2>/dev/null | grep -v watchdog; echo "*/5 * * * * $INSTALL_DIR/watchdog.sh") | crontab - fi ``` Equivalent persistence instructions appear in `SKILL.md:96-192`. ### Technical Analysis The installer automatically creates a launchd or systemd startup service. On macOS, it additionally installs a ...[truncated 1729 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install.sh:29
Finding

Mutable remote release artifact is downloaded and executed without integrity verification

Content
View full analysis
/dev/null | head -1 || echo "") if [ -n "$BINARY" ]; then mv "$BINARY" ./xhs-mcp-bin chmod +x ./xhs-mcp-bin else log "❌ 解压失败,未找到二进制文件" ls -la exit 1 fi cd "$INSTALL_DIR" nohup ./xhs-mcp-bin server --port $PORT > mcp.log 2>&1 & MCP_PID=$! ``` The documentation also recommends direct remote script execution at `scripts/install.sh:3`: ```bash bash <(curl -sSL https://raw.githubusercontent.com/xpzouying/xiaohongshu-mcp/main/scripts/install.sh) ``` ### Technical Analysis The installer resolves the mutable `latest` release, downloads an archive, extracts it, grants execute permission, and immediately launches the resulting binary. It performs no SHA-256 comparison, cryptographic signature verification, signer verification, or trusted-version pinning. TLS protects transport but does not establish that the release itself is an approved artifact. Compromise of the upstream repository, maintainer account, release automation, or published assets could replace the effective payload after this Skill has been reviewed. The archive is also extracted without first validating its members. A malicious archive could contain path traversal entries or overwrite files outside the intended installation directory, depending on tar implementation and archive contents. ### Attack Path 1. An attacker compromises the ...[truncated 955 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:263
Finding

Authentication cookies are accepted through process arguments and stored without enforced restrictive permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (68)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description advertises automatic download, background service setup, startup persistence, and service launch, but does not clearly warn users before destructive process kills or persistent system changes occur. Missing up-front warnings and consent are especially dangerous because the skill can modify startup behavior and run with elevated privileges on Linux.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The cookie import section handles highly sensitive authentication material but provides no privacy or security warning about account takeover, session theft, or local retention. Users may paste live session tokens without understanding that these can grant ongoing access to their account.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instructions explicitly ask the user to provide browser Cookie data and then save it locally in a structured file for later use. Collecting and retaining authentication material in this way creates a direct credential-handling pathway that can enable account hijacking, unauthorized reuse, or exfiltration if the host is compromised.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/install.sh (reported line 47)May include surrounding context.

sh
# 解压
log "📂 解压..."
tar xzf ./xhs-mcp.tar.gz
rm ./xhs-mcp.tar.gz

# 找二进制文件
BINARY=$(ls xiaohongshu-mcp-* 2>/dev/null | head -1 || echo "")

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The installer enumerates every process listening on port 18060 and sends SIGKILL without verifying ownership, executable path, or whether the process is actually the intended MCP service. This can terminate unrelated local services, causing denial of service and unsafe interference with other software on the host.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The watchdog repeats the same unsafe logic every five minutes by killing any process bound to the configured port before restarting the MCP binary. Because this runs persistently, it can repeatedly disrupt unrelated applications and reassert control over the port, making the behavior more dangerous than a one-time installer action.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill executes substantial shell actions, including downloads, process control, persistence setup, and privileged service installation, but declares no explicit tool scope or allowed-tools boundary. That mismatch increases the chance of unintended or overly broad execution by an agent runtime and reduces transparency for users and reviewers.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases include broad casual language like '帮我搞个小红书', which could activate the skill in contexts where the user did not intend software installation, downloads, service creation, or persistence changes. For a skill that makes system modifications, broad triggering materially increases the risk of accidental execution.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

Using nohup and background execution creates a detached long-running process that survives the invoking shell session. For a server process this may be functionally intended, but it still introduces persistence-like behavior that should be disclosed and confirmed because it leaves software running in the background.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
sleep 1

# 启动
nohup ./xhs-mcp server --port 18060 > ~/xiaohongshu-mcp/mcp.log 2>&1 &
sleep 3

# 验证

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

2.4 配置开机自启

macOS — launchd plist

bash
XHS_PLIST="$HOME/Library/LaunchAgents/com.openclaw.xhs-mcp.plist"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

2.4 配置开机自启

macOS — launchd plist

bash
XHS_PLIST="$HOME/Library/LaunchAgents/com.openclaw.xhs-mcp.plist"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 310)May include surrounding context.

2.4 配置开机自启

macOS — launchd plist

bash
XHS_PLIST="$HOME/Library/LaunchAgents/com.openclaw.xhs-mcp.plist"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 311)May include surrounding context.

2.4 配置开机自启

macOS — launchd plist

bash
XHS_PLIST="$HOME/Library/LaunchAgents/com.openclaw.xhs-mcp.plist"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 317)May include surrounding context.

2.4 配置开机自启

macOS — launchd plist

bash
XHS_PLIST="$HOME/Library/LaunchAgents/com.openclaw.xhs-mcp.plist"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install.sh (reported line 92)May include surrounding context.

sh
### 2.4 配置开机自启

#### macOS — launchd plist

```bash
XHS_PLIST="$HOME/Library/LaunchAgents/com.openclaw.xhs-mcp.plist"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install.sh (reported line 96)May include surrounding context.

sh
### 2.4 配置开机自启

#### macOS — launchd plist

```bash
XHS_PLIST="$HOME/Library/LaunchAgents/com.openclaw.xhs-mcp.plist"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install.sh (reported line 97)May include surrounding context.

sh
### 2.4 配置开机自启

#### macOS — launchd plist

```bash
XHS_PLIST="$HOME/Library/LaunchAgents/com.openclaw.xhs-mcp.plist"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install.sh (reported line 113)May include surrounding context.

sh
### 2.4 配置开机自启

#### macOS — launchd plist

```bash
XHS_PLIST="$HOME/Library/LaunchAgents/com.openclaw.xhs-mcp.plist"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install.sh (reported line 168)May include surrounding context.

sh
### 2.4 配置开机自启

#### macOS — launchd plist

```bash
XHS_PLIST="$HOME/Library/LaunchAgents/com.openclaw.xhs-mcp.plist"

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

Defining the launchd plist path is part of creating a user-level autostart mechanism. While not harmful in isolation, in context it participates in persistent background execution and should be treated as part of the autostart setup.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

macOS — launchd plist

bash
XHS_PLIST="$HOME/Library/LaunchAgents/com.openclaw.xhs-mcp.plist"
mkdir -p "$HOME/Library/LaunchAgents"

cat > "$XHS_PLIST" << 'EOFPLIST'

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

Defining the launchd plist path is part of creating a user-level autostart mechanism. While not harmful in isolation, in context it participates in persistent background execution and should be treated as part of the autostart setup.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

macOS — launchd plist

bash
XHS_PLIST="$HOME/Library/LaunchAgents/com.openclaw.xhs-mcp.plist"
mkdir -p "$HOME/Library/LaunchAgents"

cat > "$XHS_PLIST" << 'EOFPLIST'

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

This line is part of the plist body that defines a launchd autostart entry. In context, it contributes to creating persistent execution of the downloaded binary whenever the user logs in.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
cat > "$XHS_PLIST" << 'EOFPLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

This line is part of the plist body that defines a launchd autostart entry. In context, it contributes to creating persistent execution of the downloaded binary whenever the user logs in.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
cat > "$XHS_PLIST" << 'EOFPLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

This line sits within the launchd plist that defines a persistent agent label, contributing to user-session autostart. The danger is contextual: the skill is not merely running software once, but establishing recurring background execution.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
cat > "$XHS_PLIST" << 'EOFPLIST'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>
    <string>com.openclaw.xhs-mcp</string>

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

Loading the launchd plist activates user-level autostart persistence immediately. This is dangerous in context because the skill performs it automatically after downloading software, without strong prior warning or a distinct opt-in step.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

加载服务

launchctl unload "$XHS_PLIST" 2>/dev/null launchctl load "$XHS_PLIST" echo "✅ launchd 服务已加载"

text

Static analysis

No suspicious patterns detected.