Back to skill

Security audit

小红书爆款笔记生成器

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Xiaohongshu-style content generator that sends the user's topic to DeepSeek, with no evidence of hidden persistence, destructive behavior, or unrelated data access.

Install only if you are comfortable with the topic text you provide being sent to DeepSeek using your configured DeepSeek API key. Avoid entering confidential business plans, personal data, or unpublished sensitive material unless that use is acceptable under your own privacy requirements.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation phrase is extremely broad: '写一篇关于 [产品/主题] 的小红书笔记' overlaps with many ordinary writing requests and lacks a distinctive trigger boundary. In an agent ecosystem, this can cause accidental activation or routing to this skill when a user merely asks for general writing help, leading to unintended behavior, prompt collisions, or reduced control over which skill handles the request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill name and description indicate the skill is specifically for generating '小红书风格' content in Chinese, but the metadata provides no indication that users can opt into this language/locale constraint. Under the policy, forcing a specific language or locale without user choice or a clearly justified regional limitation is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The system instruction is written to produce content specifically in Chinese and for the Xiaohongshu platform, with no option for the user to choose language or locale. This is a natural-language policy concern because it imposes a specific language behavior without opt-in or justification in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script sends the user-supplied topic to DeepSeek without any visible notice, consent flow, or privacy boundary, so users may unknowingly disclose sensitive or proprietary information to a third-party service. In a CLI content-generation skill this is contextually relevant because prompts often contain business plans, personal details, or unpublished marketing ideas, making the external transmission a real privacy and data-governance risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.