Back to skill

Security audit

红笔记数据透镜

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform the advertised Xiaohongshu data collection, but it handles API credentials and saved social-media data in ways users should review before installing.

Review this skill before installing. Use it only if you are comfortable sending your Guaikei API token, Xiaohongshu links, keywords, and requested limits to Guaikei, and run it in a private workspace because it automatically saves retrieved content and URLs under logs/. Rotate the token if you suspect URL logs may have exposed it, and delete saved result files when they are no longer needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credential Transmitted in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:5
Finding

Automatic Plaintext Persistence of Collected Data and Access-Bearing URLs

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.substring(0, 200); } if (safeFilename === "") { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: tr ...[truncated 2538 chars]
Remediation
View remediation
` or `--save`. 2. Do not save successful responses by default when stdout already provides the requested result. 3. Redact sensitive URL parameters before printing or storing data, including `xsec_token` and any future authentication-related fields. 4. Create output directories and files with restrictive permissions: ```js await fs.promises.mkdir(directory, { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, redactedContent, { mode: 0o600, flag: "wx", }); ``` 5. Document precisely what is retained, where it is retained, and how users can delete it. 6. Provide configurable retention and an automatic cleanup mechanism. 7. Avoid storing unnecessary request metadata or full raw API responses; retain only fields explicitly requested by the user. 8. Exclude `logs/` from source control, package publication, CI artifacts, and automatic support bundles. 9. If persistence is required for sensitive deployments, support encryption using a user-managed key rather than embedding a key in the project. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (44)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A second independent mismatch report states the skill claims remote Xiaohongshu retrieval but actually accesses local filesystem/package metadata and reads package information unrelated to the advertised function. This is risky because behavior that differs from user-facing claims can conceal unauthorized local access or create a supply-chain style trust failure, especially when an API token is requested.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A second independent mismatch report states the skill claims remote Xiaohongshu retrieval but actually accesses local filesystem/package metadata and reads package information unrelated to the advertised function. This is risky because behavior that differs from user-facing claims can conceal unauthorized local access or create a supply-chain style trust failure, especially when an API token is requested.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger rules explicitly allow invocation even when the user did not clearly request collection or scraping, as long as the task seems related to obtaining Xiaohongshu content. Overly broad activation is dangerous because it can cause unintended data retrieval, surprise external requests, and collection of third-party content without sufficiently explicit user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This documentation instructs users to retrieve note details, comments, and creator posts at scale, but it does not include any warning about handling personal data, platform terms, lawful use, retention limits, or avoiding collection of sensitive/private information. In a scraping-oriented skill, omission of privacy and data-handling guidance increases the risk that users will collect and process public-but-personal content in ways that violate policy, create compliance issues, or enable downstream misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code sends a token plus a note URL to an external API endpoint via postJson, which is a privacy- and security-relevant network operation. While the function comments describe parameters, there is no confirmation prompt or user-facing disclosure that sensitive access credentials and user-provided targets will be transmitted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This function performs a network request that includes the token, URL, and query limit, exposing credentials and target data to an external service. The file contains retry logging for failures, but no warning, confirmation, or explicit disclosure to the user about this transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code sends the provided API token in HTTP requests via postJson, which is a safety-relevant network operation involving credentials. While the function has technical docstrings, there is no user-facing warning, confirmation, or disclosure about transmitting the token to an external API in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JavaScript file contains natural-language comments and user-visible messages such as errors and help text entirely in Chinese. Under the policy, forcing a specific language without user opt-in or documented justification is a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits all user-facing warnings and instructions only in Chinese, including operational guidance on how to obtain a token. The file does not offer any language choice or indicate that the skill is intentionally limited to Chinese-speaking users, which creates a locale/language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple error messages in this file are hard-coded in Chinese, including operational guidance and support contact text, with no indication that the skill is China-specific or that users can opt into another language. That creates a natural-language locale policy issue because the skill appears to force a specific language for all users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The error message explicitly references GUAIKEI_API_TOKEN, indicating this skill relies on sensitive credentials, but the file provides no warning, comment, or docstring about credential usage or handling. Under the code-file criteria, access to or dependency on sensitive credentials should have some form of visible disclosure unless already clearly documented elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code constructs and sends POST requests containing serialized JSON data to a remote host via HTTPS, but there is no confirmation prompt, log message, comment, or docstring warning that user or system data may be transmitted. For a shared request utility, that lack of disclosure makes outbound data transfer non-obvious at the point of use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language comments and user-visible error messages entirely in Chinese, such as the comment at L04 and error strings at L08, L13, L17, L21, L26, L54, L59, L64, and L68. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script reads GUAIKEI_API_TOKEN from the environment and then sends the token, note URL, and limit to external API functions createCommentTask and getCommentTask. The file contains no explicit disclosure that these inputs will be transmitted to a remote service, and the existing help text only says the environment variable must be configured, not that data is sent externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes the full comment task output to a local JSON file automatically after success, with no opt-in, disclosure, or controls over storage location or retention. Because comment data can contain personal or sensitive user-generated content, this behavior increases the risk of unintended local data exposure on shared systems, in synced folders, or through later reuse of saved artifacts.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:15