Back to skill

Security audit

guaikei-rednote-intel

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Xiaohongshu public-data research tool that requires an API token and saves command results locally, with no evidence of hidden execution or destructive behavior.

Install only if you are comfortable sending Xiaohongshu keywords, links, xsec_token-bearing URLs, and your GUAIKEI API token to guaikei.com, and remember that successful outputs are saved locally under logs/ until you delete them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The package metadata advertises broad growth-marketing, competitor monitoring, KOL screening, and user profiling capabilities, while the declared skill scope is limited to routing and understanding Xiaohongshu links. This scope mismatch is dangerous because it can conceal collection or processing behaviors beyond user expectations, increasing the risk of deceptive capability expansion and unauthorized competitive-intelligence use.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The manifest describes a link-driven workflow, but the package exposes generic CLI operations such as search and post that suggest broader interaction paths than simple link analysis. Hidden or undocumented entry points are risky because they may enable scraping, posting, or data access behaviors not disclosed to users or reviewers.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The README advertises broad data-mining, competitor monitoring, KOL screening, trend prediction, and bulk export features that materially exceed the manifest's stated purpose of routing and analyzing pasted Xiaohongshu links. This kind of scope mismatch is dangerous because it can hide undeclared collection and surveillance capabilities from reviewers and users, undermining informed consent and trust boundaries.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The documentation states that all task results are automatically saved to a logs/ directory, but the manifest describes a read-oriented analysis skill and does not disclose local persistence. Undeclared storage of scraped links and content increases data retention risk and can expose sensitive research targets, query history, or collected public content beyond the user's expectations.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
Claiming collection of up to 10,000 records and bulk operations is inconsistent with the narrow link-content understanding use case described in the skill metadata. Excessive collection capacity raises the risk of covert scraping, mass surveillance, or overbroad data processing beyond what a user would reasonably expect from a simple link-analysis skill.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The documentation exposes a keyword-search capability that goes beyond the manifest’s stated scope of routing user-provided Xiaohongshu links for content understanding. This creates a scope mismatch that can cause an agent to invoke broader collection behavior than users or platform policy expect, increasing the risk of unintended scraping, overcollection, and bypass of safety assumptions tied to link-only operation.

Description-Behavior Mismatch

Low
Confidence
87% confidence
Finding
The top-level description frames the skill as a general competitive-intelligence assistant, which broadens operator expectations beyond the manifest’s narrower link-based analysis purpose. That framing can steer an agent into overbroad use cases and invoke capabilities not clearly disclosed, weakening trust boundaries and making misuse easier even if no direct exploit code is present.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
This function creates arbitrary keyword-based search tasks against Xiaohongshu, which goes beyond the declared skill scope of analyzing user-provided links and instead enables general content discovery. In the context of a link-routing intelligence skill, this scope expansion increases privacy and policy risk because the skill can be used to enumerate or monitor content unrelated to a supplied URL.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The code rewrites search results into direct note and profile URLs, making the skill a content discovery and profile enumeration tool rather than only a parser for supplied links. That mismatch matters because it lowers friction for large-scale exploration of notes and user profiles, which is more sensitive than simply resolving a user-provided link.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The CLI persists the full fetched result set, including note details and potentially large comment content, to a local JSON file by default. For a skill whose stated purpose is routing and summarizing Rednote/Xiaohongshu links, this adds unnecessary data retention and can expose scraped content to other local users, backups, or downstream tooling without explicit user consent.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
This CLI performs free-form keyword search against Xiaohongshu, but the declared skill scope is limited to analyzing user-provided Xiaohongshu links and routing by link type. That scope expansion enables collection and retrieval of arbitrary platform content unrelated to a supplied link, creating an unjustified capability increase and a clear mismatch between declared behavior and actual code.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
Automatic saving of task results to logs/ without a clear warning about persistent storage of scraped content and URLs creates a data-handling transparency issue. Even if the data is public, retained logs may contain sensitive search interests, monitored accounts, xsec_token-bearing URLs, or other operationally sensitive artifacts that can later be accessed or leaked.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The CLI writes the full comment results to a predictable local JSON file without asking for consent, warning the user, or offering a way to disable persistence. If comments contain personal data, sensitive content, or regulated information, this creates unintended local data retention and increases exposure to other local users, backups, or log collectors.

Missing User Warnings

Low
Confidence
86% confidence
Finding
The script writes fetched results to a local JSON log file without explicit notice or user control. Even if intended for debugging or audit purposes, silent persistence of scraped content increases privacy risk and can surprise users who only expected immediate console output.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The CLI persists the full search output to a local JSON file without explicit notice or consent at the point of use. Search results may include sensitive interests, queried topics, or user-derived content, and local persistence increases the risk of unintended retention, later disclosure, or access by other local users/processes.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16