Back to skill

Security audit

小红书数据分析 SocialDataX 笔记详情

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a coherent read-only XHS detail helper, but it tells agents to preserve tokenized note URLs in answers, storage, and forwarding, which needs review before use.

Review this skill before installing if note URLs may be shared outside your workspace. Use it only when you are comfortable sending requests to SocialDataX with SOCIALDATAX_API_KEY and with full XHS note URLs, including xsec_token parameters, appearing in chat outputs or saved references.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Ssd 3

High
Confidence
98% confidence
Finding
The skill explicitly instructs the agent to preserve and forward full returned note URLs including xsec_token query parameters in final answers, storage, references, and forwarding. If those tokens are bearer-like, session-bound, or access-controlling, this creates a direct secret-propagation risk that can leak access tokens into logs, chats, downstream tools, or shared outputs.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.