Back to skill

Security audit

小红书评论采集

Security checks for vulnerabilities and agentic risk

Overview

This skill appears purpose-built for Xiaohongshu comment collection, but it uses an insecure default HTTP backend that can expose login tokens and collected data in transit.

Review this carefully before installing. Use it only if you are comfortable sending Xiaohongshu links, account tokens, and exported comment data to the stated backend service. Avoid the default HTTP endpoint on untrusted networks; prefer a verified HTTPS base URL if the provider supports it, and treat the saved config token like a password.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
src/config.js:17
Finding

Bearer Tokens and Authentication Responses Transmitted over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: src/config.js:17-20, with credential transmission in src/client.js:50-74 and cli.js:386-393
Vulnerability Type: Plaintext transmission of authentication credentials
Risk Level: High

Vulnerable Code

src/config.js:17-20 configures a public plaintext HTTP endpoint as the default:

javascript
const DEFAULT_BASE_URL = 'http://st.aidata366.com';

src/client.js:50-74 warns about HTTP but proceeds to transmit the bearer token:

javascript
if (!_httpWarned && this.token && this.baseUrl.startsWith('http://')) {
  _httpWarned = true;
  process.stderr.write('[warn] 当前服务地址为明文 http,token 会明文传输,建议确认网络安全或切换 https\n');
}

res = await fetch(this.baseUrl + '/api/v1' + apiPath, {
  method,
  headers: {
    ...(body ? { 'Content-Type': 'application/json' } : {}),
    ...(this.token ? { Authorization: `Bearer ${this.token}` } : {}),
    ...headers,
  },
  body: body ? JSON.stringify(body) : undefined,
  signal: ctrl.signal,
});

cli.js:386-393 also sends the bearer token over the configured endpoint when downloading an export:

javascript
const dlCtrl = new AbortController();
const dlTimer = setTimeout(() => dlCtrl.abort(), DOWNLOAD_TIMEOUT_MS);
let buf;
try {
  const res = await fetch(`${cfg.baseUrl}/api/v1/platform/exports/${encodeURIComponent(info.export_id)}/file`,
    { headers: { Authorization: `Bearer ${cfg.token}` }, signal: dlCtrl.signal });

Technical Analysis

The default base URL uses unencrypted HTTP for a remote public service. Authenticated API methods attach a reusable bearer token to the Authorization header, while session-check responses can return the token through the same unencrypted channel.

HTTP provides neither transport confidentiality nor server authentication. An attacker able to observe or modify traffic between the host running the Skill and the configured service can read bearer credentials, alter API responses, or substitute exported content.

The warning w ...[truncated 2061 chars]

Remediation
View remediation

Remediation Suggestions

  1. Deploy a correctly configured HTTPS endpoint and change DEFAULT_BASE_URL to an https:// URL.
  2. Reject authenticated requests to non-HTTPS remote destinations. If HTTP support is required for development, restrict it to loopback addresses such as 127.0.0.1, ::1, and localhost.
  3. Apply the same HTTPS enforcement to login, registration-session checks, authenticated API calls, and export downloads.
  4. Do not rely on a standard-error warning as the security control. Fail closed before transmitting access tokens or receiving authentication credentials over HTTP.
  5. Remove the process-wide NODE_TLS_REJECT_UNAUTHORIZED=0 mechanism where possible. If private certificate authorities are required, configure an explicit trusted CA instead of disabling certificate validation globally.
  6. After deploying HTTPS enforcement, revoke or rotate tokens that may previously have traversed untrusted plaintext networks.
  7. Add automated tests verifying that bearer-authenticated requests and authentication-session checks reject remote http:// base URLs.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs use of a plaintext HTTP service endpoint while storing and transmitting authentication tokens, and even warns that tokens will traverse the public network in cleartext. This enables interception or modification by any network attacker on path, leading to account compromise, unauthorized scraping actions, quota theft, and exposure of collected comment data.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill exposes meaningful capabilities—shell, network, and environment access—yet declares no explicit tool scope or permissions boundary. That makes it easier for an agent runtime to grant broader access than necessary and increases the risk of unintended command execution, network exfiltration, or misuse of local secrets during normal operation or prompt-influenced flows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to activate this skill for general discussion of comments, opinion monitoring, or exports, which can cause over-invocation of a networked scraping tool in contexts where the user did not clearly request data collection. In practice, that raises the chance of unnecessary external data transmission, accidental point consumption, and collection of personal information such as nicknames and IP location without strong intent confirmation.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
97% confidence
Finding

The function explicitly disables TLS certificate verification process-wide by setting NODE_TLS_REJECT_UNAUTHORIZED='0'. This makes all subsequent HTTPS requests in the process vulnerable to man-in-the-middle interception, allowing attackers to steal bearer tokens, alter API responses, or redirect task/export operations. In this skill, the client handles authenticated API calls and potentially sensitive scraped/exported user data, which increases the severity.

Content

Scanner excerpt · src/client.js (reported line 17)May include surrounding context.

js
/** 忽略 HTTPS 证书校验 (服务端自签/域名不匹配证书时由 insecure 配置开启)。进程级。 */
function allowInsecureTls() {
  process.env.NODE_TLS_REJECT_UNAUTHORIZED = '0';
}

/** 业务错误: code 为后端错误码 (1001/1002/3001/...) */

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s natural-language documentation is written in Chinese only, with no indication that the skill offers a language choice or is intentionally limited to a Chinese-speaking or region-specific audience. Under the language/locale policy, forcing a specific language without user opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file's natural-language comments and emitted messages are entirely in Chinese, including operational guidance such as login and retry instructions. The policy forbids forcing a specific language without user opt-in, and there is no indication here that the skill offers a locale choice or that the Chinese-only behavior is justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The workflow tells agents to directly submit user-provided links and rely on automatic conversion, with little gating around consent, privacy review, billing awareness, or whether the request actually requires scraping. That can lead to premature external requests, accidental triggering of linked skills, and processing of user-supplied URLs before the agent has validated appropriateness and user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction says the agent must send the registration guidance to the user verbatim, and the provided guidance is only in Chinese. This imposes a language choice on user-facing communication without opt-in or alternatives, which is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file’s natural-language interface and instructions are entirely in Chinese, including the top-level description, usage text, and user-facing prompts. There is no indication that the user can select another language or that the Chinese-only constraint is a documented locale-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The package description is written entirely in Chinese and presents the skill as a Chinese-language CLI without any indication that other languages are supported or that the locale restriction is intentional. Under the policy, language or locale constraints should be opt-in or clearly justified when they limit user interaction.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.insecure_tls_verification

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
cli.js:235

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
src/client.js:17