Back to skill

Security audit

小红书长链转短链

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its stated Xiaohongshu short-link purpose, but it sends account tokens over plain HTTP by default, which is a real credential-exposure risk.

Install only if you are comfortable using this paid third-party Xiaohongshu service and storing its bearer token locally. Do not use it on untrusted networks unless you override the backend to a valid HTTPS URL; the default HTTP endpoint can expose your token and submitted links in transit.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
src/config.js:19
Finding

Bearer tokens and task data are transmitted over plaintext HTTP by default

Content
View full analysis

Vulnerability Details

File Location: src/config.js:19-22, with authenticated request sinks at src/client.js:66-72 and cli.js:292-293
Vulnerability Type: Plaintext transmission of credentials and sensitive data
Risk Level: High

Technical Analysis

The built-in service endpoint uses unencrypted HTTP:

js
// Server certificate is not ready, so HTTP remains the default.
const DEFAULT_BASE_URL = 'http://st.aidata366.com';

resolveConfig() uses this endpoint unless it is overridden through command-line options, an environment variable, or the configuration file. Authenticated API requests then attach the reusable bearer token to requests sent to that endpoint:

js
res = await fetch(this.baseUrl + '/api/v1' + apiPath, {
  method,
  headers: {
    ...(body ? { 'Content-Type': 'application/json' } : {}),
    ...(this.token ? { Authorization: `Bearer ${this.token}` } : {}),
    ...headers,
  },
  body: body ? JSON.stringify(body) : undefined,
  signal: ctrl.signal,
});

The export download path independently sends the same credential:

js
const res = await fetch(
  `${cfg.baseUrl}/api/v1/platform/exports/${encodeURIComponent(info.export_id)}/file`,
  {
    headers: { Authorization: `Bearer ${cfg.token}` },
    signal: dlCtrl.signal
  }
);

Although src/client.js emits a warning when a token is sent over HTTP, the warning does not require confirmation or stop the request. Consequently, authenticated commands using the default configuration expose credentials and application data to passive interception and active modification.

This affects commands including submit, query, quota, export, and logout. Registration and login session exchanges also use the configured endpoint.

Attack Path

  1. A user invokes the Skill without overriding its default base URL.
  2. The CLI resolves the endpoint to http://st.aidata366.com.
  3. The user logs ...[truncated 1082 chars]
Remediation
View remediation

Remediation Suggestions

  1. Configure a valid TLS certificate and change DEFAULT_BASE_URL to an https:// endpoint.
  2. Reject plaintext HTTP whenever a bearer token, login-session value, submitted URL, task result, profile response, or export is involved.
  3. Validate the URL with the URL parser and require the https: scheme rather than relying on a prefix check.
  4. If HTTP support is unavoidable for isolated development environments, require an explicit per-invocation opt-in and prohibit sending production credentials through that mode.
  5. Do not treat a stderr warning as an adequate security boundary; fail closed before constructing authenticated requests.
  6. Ensure export downloads apply the same centralized HTTPS enforcement as other API requests.
  7. After migrating to HTTPS, revoke or rotate tokens that may previously have traversed untrusted networks over HTTP.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The documented purpose is a narrowly scoped long-URL-to-short-URL converter, but the described behavior includes broader authentication/session management and generic task submission capabilities. This mismatch is dangerous because agents or reviewers may approve the skill for a limited purpose while it actually exposes more powerful platform actions and account/session handling than advertised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The submitTask method accepts an arbitrary capability parameter and forwards it to a broader platform task API. If an attacker or prompt-injected workflow can influence that parameter, the skill may invoke unrelated backend capabilities contrary to the manifest, resulting in privilege expansion or unauthorized operations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill requires shell, network, and access to local configuration/token storage, but it does not declare any explicit tool scope or permissions boundaries. That makes the runtime trust model ambiguous and can lead to over-privileged execution, especially because the documented workflow includes network calls, token persistence in ~/.xhs-platform/config.json, and CLI invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill metadata and usage guidance are entirely presented in Chinese and describe when the skill should be used, but nowhere offer a language or locale choice to the user. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code embeds its primary description, usage text, and operational prompts entirely in Chinese, and does not offer any locale selection or user opt-in. That creates a natural-language policy issue under the language/locale rule because the skill enforces a specific language for all users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The registration/login instructions shown to users at runtime are hard-coded in Chinese and there is no opt-in or configurable locale. This continues the same language-forcing behavior during actual operation, not just in static help text.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

allowInsecureTls disables TLS certificate verification process-wide by setting NODE_TLS_REJECT_UNAUTHORIZED=0. This allows man-in-the-middle interception or tampering of all subsequent HTTPS requests in the process, including bearer tokens and task data, which is especially risky for a paid networked service.

Content

Scanner excerpt · src/client.js (reported line 17)May include surrounding context.

js
/** 忽略 HTTPS 证书校验 (服务端自签/域名不匹配证书时由 insecure 配置开启)。进程级。 */
function allowInsecureTls() {
  process.env.NODE_TLS_REJECT_UNAUTHORIZED = '0';
}

/** 业务错误: code 为后端错误码 (1001/1002/3001/...) */

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The client exposes generic platform task and export operations that go beyond the skill's declared purpose of converting Xiaohongshu long links to short links. In an agent setting, this scope mismatch can enable unintended backend actions or data access if other capabilities exist server-side and are reachable through the same client.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file’s documented output contract and multiple emitted messages are written only in Chinese, indicating the skill is designed to communicate in a fixed language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The default skill tip and all operational/error messages in this section are hard-coded in Chinese, with no indication that users can choose another language. This creates a locale restriction that is not opt-in and is not justified in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The package description is written entirely in Chinese and names the skill as a Chinese-platform-specific CLI without any indication that users may choose another language or locale. Under the policy for natural-language violations, forcing a specific language without user opt-in should be flagged unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The header documents an output contract for this shared module, but later behavior includes progress reporting and timeout error construction details not reflected in that contract. More importantly, the timeout path constructs new BizError(...) even though no BizError is defined or imported in this file, so the documented error-mapping behavior can diverge from actual runtime behavior if that path is hit.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
src/client.js:17