Back to skill

Security audit

guaikei-rednote-analytics

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed public Xiaohongshu data lookup skill, with the main caution that it sends queries and URLs to guaikei.com and saves results locally.

Install only if you are comfortable sending Xiaohongshu keywords or links, the GUAIKEI_API_TOKEN, and requested result limits to guaikei.com. Treat the returned public profile, post, and comment data responsibly, avoid uses that violate platform rules or privacy expectations, and periodically delete local logs if the searches or results are sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The README advertises capabilities such as keyword search, KOL screening, comment analysis, and trend monitoring that go beyond the manifest’s narrower scope of blogger post analytics. This scope drift is dangerous because downstream agents or users may invoke the skill for broader scraping and profiling tasks than were reviewed or approved, increasing the chance of policy violations, data overcollection, and unsafe automation.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The README’s claims of broad public-data mining and returning 'all visible valuable data' encourage expansive collection beyond the stated account-analysis purpose. In a scraping-oriented skill, this wording increases risk by normalizing overbroad harvesting and use of public profile, content, and engagement data, which can lead to misuse, compliance issues, and operation outside the expected trust boundary.

Description-Behavior Mismatch

Medium
Confidence
80% confidence
Finding
The CLI writes the full search output to a local file, creating data persistence beyond the user-visible retrieval flow. Even if the source content is public, stored query terms and collected results can reveal research targets, competitive-intelligence activity, or accumulate sensitive operational metadata on disk without clear user consent or retention controls.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16