Back to skill

Security audit

xiaohongshu-search

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Xiaohongshu research helper, but it asks users to expose an authenticated Chrome session through remote debugging without enough scoping or safety guidance.

Install only if you are comfortable running browser automation against Xiaohongshu. Use a dedicated temporary Chrome profile with no unrelated accounts, tabs, saved passwords, or extensions; keep the debugging port local; close the browser after use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:11
Finding

Overprivileged Access to an Authenticated Chrome Browser

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 11–15
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: Medium

Complete Code Snippet:

markdown
## Prerequisites

The browser tool requires Chrome to run with remote debugging enabled:

`chrome.exe --remote-debugging-port=9222`

Technical Analysis

The skill instructs the user to enable Chrome's remote-debugging interface on TCP port 9222 and subsequently relies on an already authenticated browser. This interface provides broad browser control rather than access restricted to Xiaohongshu. A client capable of connecting to the debugging endpoint may enumerate browser targets, inspect pages, navigate tabs, and execute JavaScript in page contexts.

Consequently, the browser authority granted by this configuration exceeds the minimum privilege required to search public posts. The exposure is especially significant when the same Chrome profile contains unrelated authenticated services or sensitive open tabs.

The documentation does not specify a dedicated browser profile, explicit loopback binding, endpoint access controls, process isolation, or shutdown procedures. Exploitation requires an attacker-controlled process or another party to be able to connect to the debugging endpoint; the reviewed file does not itself implement such exploitation.

Attack Path

  1. The user launches an authenticated Chrome instance with --remote-debugging-port=9222.
  2. The browser exposes its debugging endpoint to clients that can reach the configured listener.
  3. An attacker-controlled local process—or a remote party if network exposure permits—connects to the endpoint.
  4. The attacker enumerates available browser targets, including tabs unrelated to Xiaohongshu.
  5. The attacker inspects or manipulates authenticated pages and may execute JavaScript within accessible page contexts.
  6. Data visible to those sessions can be r ...[truncated 642 chars]
Remediation
View remediation

Remediation Suggestions

  • Use a dedicated, temporary Chrome profile that contains no unrelated authenticated sessions, stored credentials, extensions, or browsing data.
  • Bind the debugging listener explicitly to the loopback interface and prevent access from other hosts with host firewall rules.
  • Run the isolated browser under a low-privilege operating-system account or sandbox.
  • Do not reuse a personal or general-purpose browser instance for skill execution.
  • Close the debugging-enabled browser immediately after the task and remove its temporary profile.
  • Prefer a domain-scoped API or isolated browser automation environment with an allowlist limited to xiaohongshu.com.
  • Add startup validation that rejects non-loopback debugging endpoints and warns when unrelated tabs or profiles are present.
  • Document that debugging ports must never be exposed on public or shared network interfaces.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs use of a Chrome instance started with remote debugging and states it operates through an already logged-in browser, but it does not warn users that actions and reads occur in their authenticated session. This is dangerous because the skill can access session-scoped content and potentially expose account data, personalized results, or other browser-accessible information beyond what a user may expect from a simple public-content search tool.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.