Back to skill

Security audit

红笔记内容脉搏

Security checks for vulnerabilities and agentic risk

Overview

The skill generally does what it claims, but it sends an API token in URL query strings and automatically saves fetched data locally.

Review this skill before installing. It appears purpose-aligned for Xiaohongshu public-data collection, but you should only use it if you are comfortable sending keywords and Xiaohongshu URLs to Guaikei, storing a GUAIKEI_API_TOKEN, and having fetched results automatically saved in local logs. Rotate the token if exposed, avoid shared or synced workspaces for sensitive research, and delete logs when they are no longer needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:82
Finding

API Credential Exposed in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:24
Finding

Automatic Plaintext Persistence of Collected Data and Tokenized URLs

Content
View full analysis
Remediation
View remediation
` or `--save`. 2. Do not write result files during normal stdout-only operation. 3. Clearly document what data is retained, where it is stored, and how users can delete it. 4. When persistence is requested, create files with restrictive permissions: ```js await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, }); ``` 5. Create the log directory with restrictive permissions where supported: ```js await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true, mode: 0o700, }); ``` 6. Remove or redact sensitive query parameters such as `xsec_token` before serialization. 7. Allow users to select a retention duration and provide a cleanup command. 8. Add `logs/` to `.gitignore` to reduce accidental source-control disclosure. 9. Avoid retaining complete result objects when a minimal operational audit record would suffice. 10. Warn users when saving into shared, synchronized, or world-readable workspaces. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (43)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description is specifically about collecting public Xiaohongshu data. However, the supplied code chunk contains only generic constants and a base URL for www.guaikei.com, which is not identified as a Xiaohongshu domain in the description. No code in this chunk demonstrates searching Xiaohongshu notes, fetching note details, retrieving comments, or listing a blogger’s works. Because the visible behavior/configuration is oriented to a different resource and lacks the declared primary capabilities, this is a description-behavior mismatch based on the supplied code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书公开内容采集/检索的技能,应体现搜索笔记、读取详情、评论或博主作品等平台数据访问能力。但给出的代码片段仅实现了通用 CLI 参数解析器,包括读取 flag 值、校验重复/缺失参数、解析布尔和位置参数,以及生成 help 文本。代码没有任何与小红书、链接识别、公开内容抓取、JSON 输出、评论或博主数据访问相关的行为。虽然这类参数解析可能是某个更大工具的配套基础设施,但就该代码块本身而言,其实际行为与声明用途明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This code chunk does not implement Xiaohongshu content retrieval, note/comment fetching, creator page scraping, or JSON output logic. Instead, it performs local file logging by writing arbitrary provided content to disk. While logging can be a supporting utility, the declared description does not mention any filesystem-writing capability, and the behavior shown is materially unrelated to the stated primary purpose of collecting public Xiaohongshu data. Therefore this chunk is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is about collecting public Xiaohongshu content and producing structured JSON from platform data. The supplied code chunk does not implement any of those behaviors. Instead, it performs a local filesystem read of package.json and returns the package name. This is materially unrelated to the declared primary purpose. While utility code can be supporting, this snippet shows only unrelated local metadata access and no evidence of the advertised Xiaohongshu retrieval capabilities, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill requires an environment secret (GUAIKEI_API_TOKEN) but does not declare a restrictive tool scope such as explicit permissions or allowed-tools. That creates ambiguity about what runtime capabilities the skill is expected to use and weakens least-privilege controls, making accidental overreach or unsafe execution more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger conditions are intentionally broad, activating on many aliases, loose references, and even links without explicit platform naming. Over-broad invocation can cause the agent to route unrelated user requests or pasted URLs to this third-party data skill, increasing unnecessary data disclosure and the chance of unintended external requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends user-provided URLs, keywords, and requested content lookups to a third-party service (guaikei.com) but does not present that as a prominent upfront warning. Users may reasonably believe the retrieval is first-party or local, leading to uninformed disclosure of browsing targets, research intent, and possibly personal or business-sensitive data to an external provider.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states that all task results are automatically saved to the logs directory, but it does not clearly warn users that scraped platform content, including note details, comments, and profile-derived data, will be persisted locally. In a data-collection skill, silent local storage increases the risk of unintended retention, disclosure, or mishandling of collected third-party content, especially on shared machines or in synced workspaces.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents capabilities that collect public content, comments, and creator-post data for analysis, including comment summarization and competitor monitoring. Under the markdown-specific SQP-2 criteria, the description should include a user-facing warning about potential privacy, compliance, or responsible-use implications when retrieving and analyzing third-party content, but no such warning appears in these sections.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file explicitly requires the environment variable GUAIKEI_API_TOKEN before execution, which involves credential use. For a markdown file, this should be accompanied by a warning not to expose, log, or share the token and to store it securely, but the document only states that it must be configured.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code contains user-facing messages only in Chinese, including warning and informational output, with no indication that users can opt into another language. Per the policy, forcing a specific language without user choice is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Several error strings are presented only in Chinese, including operational guidance for invalid credentials. This forces a specific language for user-visible messaging without offering locale selection or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains multiple user-facing error messages exclusively in Chinese, such as at L08, L13, L17, L21, L26, L54, L59, L64, and L68. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Multiple descriptions and help messages are presented only in Chinese, and the file provides no mechanism for the user to choose another language or locale. This is a natural-language policy issue because the skill imposes a specific language on all users by default.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI writes fetched comment results to a local JSON file after already printing them to stdout, creating additional persistent storage of scraped public content without clear necessity or user consent. In this skill's context, comment data may contain personal information, usernames, or sensitive opinion data, so silent local retention increases privacy, data-handling, and host exposure risk beyond simple retrieval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Comment results are written to disk without any user-facing warning in this file, so operators may believe the tool only returns structured JSON to the console while it also leaves recoverable artifacts on the local machine. For a scraping skill focused on comments and sentiment analysis, undisclosed persistence raises privacy and compliance concerns and can expose data to other local users, backups, or log collectors.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:15