Back to skill

Security audit

小红书选题分析

Security checks across malware telemetry and agentic risk

Overview

The skill is a read-only Xiaohongshu topic-research helper, but it tells agents to preserve tokenized result URLs, so users should treat shared links as potentially sensitive.

Before installing, understand that the skill runs an external npm CLI and uses your SOCIALDATAX_API_KEY to fetch Xiaohongshu search results. It is presented as read-only, but avoid forwarding or storing full result URLs with xsec_token outside the immediate analysis unless you are comfortable sharing those tokenized links.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Ssd 3

Medium
Confidence
96% confidence
Finding
The skill explicitly instructs the agent to preserve and retransmit full `note_url` values including the `xsec_token` query parameter in final answers, storage, and forwarding. If that parameter functions as an access-bearing or anti-abuse token, exposing it broadly can leak replayable access data into chat logs, downstream systems, analytics, or other users, increasing the chance of unauthorized reuse.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.