Back to skill

Security audit

guaikei-viral

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Xiaohongshu public-data lookup tool that uses a third-party API and saves results locally, with no hidden install steps or destructive behavior found.

Install only if you are comfortable sending Xiaohongshu keywords, note URLs, profile URLs, and the GUAIKEI_API_TOKEN-backed requests to guaikei.com. Review or delete the generated logs directory when results may reveal sensitive research targets, comments, or competitive analysis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The documented behavior materially differs from the advertised purpose: it expands from a single note-analysis workflow to keyword search, profile monitoring, third-party API transmission, and local log storage, while overstating analytical capabilities it does not actually implement. This is dangerous because users may provide URLs, competitive research targets, and API credentials under incomplete or misleading expectations, increasing the risk of unintended data disclosure and unsafe operational use.

Description-Behavior Mismatch

Low
Confidence
80% confidence
Finding
The CLI writes full search results to a local JSON file automatically, which can persist potentially sensitive search data and metadata beyond the user's immediate session. In a content-analysis skill, this increases data exposure on shared machines, CI runners, or multi-user environments because users may not expect retention of results on disk.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README states that all task results are automatically saved under `logs/` and earlier examples show those tasks may include searched keywords, note URLs, profile URLs, fetched comments, and interaction data. Writing this material to disk without an explicit data-retention warning increases the risk of unintended local disclosure through shared machines, backups, source control, or support bundle collection.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs users to submit keywords and Xiaohongshu note/profile URLs to CLI tools and an external API token-backed service, but it does not clearly disclose that these inputs will be transmitted to third-party services. This can lead to unintended sharing of sensitive research targets, private tracking links, or user-supplied data, especially in enterprise or competitive-intelligence contexts where URLs and keywords may themselves be confidential.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The CLI writes the full result payload, including note details/comments and the input URL, to a predictable local JSON file without any explicit opt-in or warning to the user. In this skill’s context, comment data and scraped content may be sensitive or regulated, and silent persistence increases the risk of unintended disclosure through shared machines, backups, logs, or source-controlled working directories.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The CLI persists the full result set to a local JSON file automatically, without clear advance notice or opt-in. Because the output includes collected profile/post data and metadata, this can create unintended local retention of potentially sensitive or regulated data, increasing exposure to other local users, backups, or later compromise.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
Search results are silently saved to disk without warning or explicit consent, which can expose user queries, result data, and execution metadata to other local users or later processes. Because the skill’s purpose involves collecting note and comment-related data, undisclosed persistence increases privacy and operational risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.