Back to skill

Security audit

小红书数据助手 SocialDataX

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent read-only Xiaohongshu data tool, but it needs review because it tells agents to preserve and share full tokenized note links broadly.

Install only if you are comfortable providing a SocialDataX API key and having full Xiaohongshu note links, including xsec_token query parameters, appear in outputs. Avoid sharing saved transcripts or reports containing those full links unless the recipients should have them; prefer note IDs or sanitized links when exact tokenized URLs are not necessary.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to preserve and forward full `note_url` values including `xsec_token` query parameters in all outputs and references. Query tokens often function as access-bearing or tracking parameters, so propagating them without minimization or user opt-in can leak sensitive URLs to logs, downstream tools, other users, or third-party systems.

Ssd 3

Medium
Confidence
97% confidence
Finding
The instruction to preserve and forward full returned note URLs, including sensitive query tokens, creates unnecessary data exposure across the agent workflow. Even if the skill is otherwise read-only, this expands the blast radius of tokenized links by encouraging disclosure in final answers, storage, and forwarding, which can enable unauthorized reuse, tracking, or leakage into telemetry and audit trails.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.