Back to skill

Security audit

XiaoHongShu Viral Post Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated Xiaohongshu post-generation purpose, but it needs Review because its billing call can be redirected to an arbitrary endpoint while carrying a payment credential and part of the user topic.

Install only if you trust the publisher with OpenAI and SkillPay credentials and are comfortable sending topics to OpenAI, Datamuse, and SkillPay. Before use, require SKILLPAY_ENDPOINT to be removed or strictly allowlisted to the official HTTPS SkillPay endpoint, and prefer pinned dependencies with a lockfile.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
run.js:16
Finding

Configurable Billing Endpoint Can Disclose the SkillPay Credential

Content
View full analysis

Vulnerability Details

File Location: run.js, lines 16–32
Vulnerability Type: Unvalidated credential-bearing HTTP destination
Risk Level: High

Vulnerable Code

js
const endpoint = process.env.SKILLPAY_ENDPOINT || "https://api.skillpay.me/v1/charges";

const payload = {
  skillId: SKILLPAY_ID,
  amount: PRICE_USDT,
  currency: "USDT",
  unit: "call",
  input: {
    topic: String(input.topic || "").slice(0, 120)
  },
  timestamp: new Date().toISOString()
};

await axios.post(endpoint, payload, {
  headers: {
    Authorization: `Bearer ${skillPayKey}`,
    "Content-Type": "application/json"
  },
  timeout: 10000
});

Technical Analysis

The undocumented SKILLPAY_ENDPOINT environment variable completely controls the destination of a request carrying the SKILLPAY_KEY bearer credential. The implementation does not enforce HTTPS, validate the destination hostname against an allowlist, restrict ports, or otherwise ensure that the credential is sent only to the legitimate SkillPay API.

Anyone able to influence the Skill's environment can set the endpoint to an attacker-controlled server. When the Skill runs, Axios sends both the bearer credential and the billing payload—including up to 120 characters of the user's topic—to that server. An internal URL could also cause the runtime to issue a credential-bearing request to an internal HTTP service.

Attack Path

  1. An attacker obtains the ability to configure or influence the Skill's environment.
  2. The attacker sets SKILLPAY_ENDPOINT to an attacker-controlled URL, such as https://attacker.example/collect, or to an internal HTTP endpoint.
  3. A user invokes the Skill with a valid topic.
  4. chargeSkillPay() reads the malicious endpoint without validating its scheme or hostname.
  5. Axios sends Authorization: Bearer <SKILLPAY_KEY> and the topic-bearing billing payload to the selected destination.
  6. The attacker captures the credential and may attempt unauthorized actions ...[truncated 646 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove SKILLPAY_ENDPOINT configurability from production builds and use a fixed trusted endpoint:

    js
    const endpoint = "https://api.skillpay.me/v1/charges";
    
  2. If endpoint configurability is operationally necessary, parse the URL and require an exact approved HTTPS origin:

    js
    const endpoint = new URL(
      process.env.SKILLPAY_ENDPOINT || "https://api.skillpay.me/v1/charges"
    );
    
    if (
      endpoint.protocol !== "https:" ||
      endpoint.hostname !== "api.skillpay.me" ||
      endpoint.port
    ) {
      throw new Error("Invalid SkillPay endpoint");
    }
    
  3. Prefer an exact origin-and-path allowlist rather than suffix matching, which may accept attacker-controlled domains.

  4. Prevent credentials from being forwarded across redirects. Disable redirects for this request or validate every redirect destination before forwarding the Authorization header.

  5. Restrict access to deployment environment variables using least-privilege configuration controls, and monitor changes to billing-related settings.

  6. Rotate the SKILLPAY_KEY immediately if the Skill has ever run with an untrusted endpoint.

  7. Apply outbound network controls so the process can contact only the required public API hosts and cannot reach internal or link-local services.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (17)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 1)May include surrounding context.

md
---
name: xhs-viral-post
description: AI 一键生成小红书爆款笔记(标题、正文、标签、封面提示、发帖策略)。真实种草风,防封号友好。
version: 1.1.0

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
---
name: xhs-viral-post
description: AI 一键生成小红书爆款笔记(标题、正文、标签、封面提示、发帖策略)。真实种草风,防封号友好。
version: 1.1.0

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README presents all user-facing instructions and behavior descriptions exclusively in Chinese, which effectively forces a specific language experience. Under the policy, language constraints should either be optional for the user or clearly documented as a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt is entirely in Chinese and instructs the model to act as a Xiaohongshu blogger, effectively constraining output language and locale behavior. There is no indication that users can opt into this language choice or that the locale restriction is explicitly justified in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code performs a network call that transmits user input (topic and keywords) to an external service. In this file there is no confirmation prompt, logging/print disclosure, or comment/docstring warning users that their input will be sent off-box.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill unconditionally injects several Chinese hashtags into every result set, regardless of the user's language or region. This is a natural-language policy concern because it forces a locale-specific output without offering any user choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill enforces an external billing call before performing its main function and reads a payment credential from the environment, but the file contains no user disclosure, consent flow, or stated need for payment handling. This creates a trust and privacy risk because user input is transmitted to a third-party billing endpoint and execution is blocked unless the charge succeeds.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · run.js (reported line 17)May include surrounding context.

js
throw new Error("Missing SKILLPAY_KEY");
  }

  const endpoint = process.env.SKILLPAY_ENDPOINT || "https://api.skillpay.me/v1/charges";

  const payload = {
    skillId: SKILLPAY_ID,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The network request sends both the user's topic and a bearer authorization token to an external service without any user-facing warning or in-file indication of consent. Even though the destination is HTTPS, transmitting user content and payment credentials to a third party without transparent disclosure can expose sensitive prompts and creates risk if the endpoint is changed or logged.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The hardcoded audience segments and writing hooks are entirely in Chinese, which imposes a specific language/locale on generated strategy content regardless of the user's requested topic or preferences. This is a natural-language policy issue because the file provides no option to choose language and no justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · trending.js (reported line 19)May include surrounding context.

js
}

async function fetchDatamuse(topic) {
  const res = await axios.get("https://api.datamuse.com/words", {
    params: { ml: topic, max: 12 },
    timeout: 5000
  });

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated prompt hard-codes 'Xiaohongshu cover' and defaults the title to 'xiaohongshu viral note', which steers output toward a specific platform/locale style. This is a natural-language policy concern because the skill does not offer any user opt-in or alternative language/locale selection.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This is a manifest file, so vague trigger review applies. The description only says "Xiaohongshu viral post generator with SkillPay billing," which describes capability but does not specify activation conditions, trigger phrases, scope limits, or exclusion conditions, making invocation criteria ambiguous if this metadata is used for routing.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

Using a caret range for axios allows newer minor/patch releases to be installed without explicit review, which can introduce breaking or vulnerable code through the dependency supply chain. In a skill that likely performs network requests and billing-related actions, silently drifting dependencies increase the risk of exploitable behavior or operational compromise.

Content

Scanner excerpt · package.json (reported line 9)May include surrounding context.

json
"license": "MIT",
  "type": "commonjs",
  "dependencies": {
    "axios": "^1.8.2",
    "openai": "^4.86.1"
  }
}

Unverifiable Dependency: axios has 16 known advisory(ies) (CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The manifest references axios with an unpinned version despite known advisories affecting some axios releases, so the actual installed package may be vulnerable and cannot be verified from this file. Given axios is commonly used for outbound HTTP requests, exploitable issues such as SSRF, credential leakage, or response tampering could materially affect a network-enabled skill.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

Using a caret range for the openai package permits automatic adoption of future compatible-version releases that may change behavior or introduce vulnerabilities before they are reviewed. Because this skill appears to generate content and may interact with paid APIs, dependency drift can affect both security and billing integrity.

Content

Scanner excerpt · package.json (reported line 10)May include surrounding context.

json
"type": "commonjs",
  "dependencies": {
    "axios": "^1.8.2",
    "openai": "^4.86.1"
  }
}

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
run.js:12