T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:82- Finding
API Credential Exposed in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill generally does what it claims, but it sends an API token in URL query strings and automatically saves fetched data locally.
Review this skill before installing. It appears purpose-aligned for Xiaohongshu public-data collection, but you should only use it if you are comfortable sending keywords and Xiaohongshu URLs to Guaikei, storing a GUAIKEI_API_TOKEN, and having fetched results automatically saved in local logs. Rotate the token if exposed, avoid shared or synced workspaces for sensitive research, and delete logs when they are no longer needed.
src/utils/request.js:82API Credential Exposed in URL Query Strings
src/utils/log.js:24Automatic Plaintext Persistence of Collected Data and Tokenized URLs
The declared description is specifically about collecting public Xiaohongshu data. However, the supplied code chunk contains only generic constants and a base URL for www.guaikei.com, which is not identified as a Xiaohongshu domain in the description. No code in this chunk demonstrates searching Xiaohongshu notes, fetching note details, retrieving comments, or listing a blogger’s works. Because the visible behavior/configuration is oriented to a different resource and lacks the declared primary capabilities, this is a description-behavior mismatch based on the supplied code.
声明描述的是一个面向小红书公开内容采集/检索的技能,应体现搜索笔记、读取详情、评论或博主作品等平台数据访问能力。但给出的代码片段仅实现了通用 CLI 参数解析器,包括读取 flag 值、校验重复/缺失参数、解析布尔和位置参数,以及生成 help 文本。代码没有任何与小红书、链接识别、公开内容抓取、JSON 输出、评论或博主数据访问相关的行为。虽然这类参数解析可能是某个更大工具的配套基础设施,但就该代码块本身而言,其实际行为与声明用途明显不一致。
This code chunk does not implement Xiaohongshu content retrieval, note/comment fetching, creator page scraping, or JSON output logic. Instead, it performs local file logging by writing arbitrary provided content to disk. While logging can be a supporting utility, the declared description does not mention any filesystem-writing capability, and the behavior shown is materially unrelated to the stated primary purpose of collecting public Xiaohongshu data. Therefore this chunk is a description-behavior mismatch.
The declared description is about collecting public Xiaohongshu content and producing structured JSON from platform data. The supplied code chunk does not implement any of those behaviors. Instead, it performs a local filesystem read of package.json and returns the package name. This is materially unrelated to the declared primary purpose. While utility code can be supporting, this snippet shows only unrelated local metadata access and no evidence of the advertised Xiaohongshu retrieval capabilities, so this should be flagged as a mismatch.
Referenced artifact was not completely inspected
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
The skill requires an environment secret (GUAIKEI_API_TOKEN) but does not declare a restrictive tool scope such as explicit permissions or allowed-tools. That creates ambiguity about what runtime capabilities the skill is expected to use and weakens least-privilege controls, making accidental overreach or unsafe execution more likely.
The trigger conditions are intentionally broad, activating on many aliases, loose references, and even links without explicit platform naming. Over-broad invocation can cause the agent to route unrelated user requests or pasted URLs to this third-party data skill, increasing unnecessary data disclosure and the chance of unintended external requests.
The skill sends user-provided URLs, keywords, and requested content lookups to a third-party service (guaikei.com) but does not present that as a prominent upfront warning. Users may reasonably believe the retrieval is first-party or local, leading to uninformed disclosure of browsing targets, research intent, and possibly personal or business-sensitive data to an external provider.
The README states that all task results are automatically saved to the logs directory, but it does not clearly warn users that scraped platform content, including note details, comments, and profile-derived data, will be persisted locally. In a data-collection skill, silent local storage increases the risk of unintended retention, disclosure, or mishandling of collected third-party content, especially on shared machines or in synced workspaces.
This markdown file documents capabilities that collect public content, comments, and creator-post data for analysis, including comment summarization and competitor monitoring. Under the markdown-specific SQP-2 criteria, the description should include a user-facing warning about potential privacy, compliance, or responsible-use implications when retrieving and analyzing third-party content, but no such warning appears in these sections.
The file explicitly requires the environment variable GUAIKEI_API_TOKEN before execution, which involves credential use. For a markdown file, this should be accompanied by a warning not to expose, log, or share the token and to store it securely, but the document only states that it must be configured.
This code contains user-facing messages only in Chinese, including warning and informational output, with no indication that users can opt into another language. Per the policy, forcing a specific language without user choice is a natural-language policy violation unless clearly justified as region-specific.
Several error strings are presented only in Chinese, including operational guidance for invalid credentials. This forces a specific language for user-visible messaging without offering locale selection or documenting a justified region-specific constraint.
This JavaScript file contains multiple user-facing error messages exclusively in Chinese, such as at L08, L13, L17, L21, L26, L54, L59, L64, and L68. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.
Multiple descriptions and help messages are presented only in Chinese, and the file provides no mechanism for the user to choose another language or locale. This is a natural-language policy issue because the skill imposes a specific language on all users by default.
The CLI writes fetched comment results to a local JSON file after already printing them to stdout, creating additional persistent storage of scraped public content without clear necessity or user consent. In this skill's context, comment data may contain personal information, usernames, or sensitive opinion data, so silent local retention increases privacy, data-handling, and host exposure risk beyond simple retrieval.
Comment results are written to disk without any user-facing warning in this file, so operators may believe the tool only returns structured JSON to the console while it also leaves recoverable artifacts on the local machine. For a scraping skill focused on comments and sentiment analysis, undisclosed persistence raises privacy and compliance concerns and can expose data to other local users, backups, or log collectors.
Detected: suspicious.exposed_secret_literal