Back to skill

Security audit

guaikei-xhs-acquisition

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Xiaohongshu public-data retrieval tool that uses a third-party API token and saves results locally, with no hidden destructive or unrelated behavior found.

Install only if you are comfortable sending Xiaohongshu keywords or links, including any query parameters in those links, to guaikei.com using your GUAIKEI_API_TOKEN. Review or delete the generated logs if the searches, target profiles, comments, or returned public content are sensitive for your team.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The top-level description frames the skill as keyword-based Xiaohongshu search, but the body expands scope to note-detail retrieval, comment harvesting, and creator-profile monitoring. This mismatch can cause agents or users to invoke the skill under a narrower trust assumption than its real data-collection behavior, increasing the risk of unintended third-party data exfiltration and overbroad scraping of public profile/comment data.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The README describes capabilities beyond the manifest's keyword-search-only scope, including note details, account monitoring, and comment analysis. This creates scope ambiguity that can mislead users and host systems about what the skill actually collects and processes, increasing the risk of overbroad data access and use without proper review.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The top-level description claims competitor monitoring, trend prediction, and KOL screening, which materially expands the apparent function of the skill beyond the narrower manifest description. Such overclaiming undermines informed consent and security assessment because reviewers may approve a simpler search tool while operators deploy a broader surveillance-oriented capability.

Context-Inappropriate Capability

Low
Confidence
83% confidence
Finding
The documentation states that all task results are automatically saved to a local logs directory, introducing persistence that is not necessary for basic retrieval. Even if the source data is public, automatic storage increases retention risk, exposes user queries and scraped content to other local users or processes, and expands the attack surface beyond transient execution.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The changelog advertises capabilities beyond the manifest’s declared keyword-search scope, including comment retrieval and other richer data operations. This creates a scope-mismatch risk: downstream agents or users may invoke undisclosed functionality, reducing transparency, weakening policy enforcement, and increasing the chance of unauthorized collection or processing of social-media data.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
Documenting creator-work monitoring extends the skill from simple keyword research into ongoing profile/content surveillance, which is materially different from the manifest’s stated use case. Hidden or under-declared monitoring features are risky because they can enable unexpected tracking workflows and bypass review based on the narrower manifest description.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The changelog references note-detail retrieval and comment sentiment analysis that are absent from the manifest description. Undisclosed analysis features can materially change the privacy and compliance profile of the skill, especially when processing user-generated comments and inferred sentiment, making this more dangerous than ordinary documentation drift.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The documentation advertises four operational capabilities while the manifest describes the skill as keyword-based Xiaohongshu acquisition for public notes. This scope expansion is dangerous because it can cause the agent to invoke undeclared functions such as note-detail scraping, comment collection, or creator monitoring that users and reviewers did not explicitly authorize, weakening least-privilege and transparency controls.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The blogger-profile monitoring section extends the skill from keyword search into account-level tracking of a specific creator's recent posts. That is a material functional expansion beyond the stated purpose and can enable targeted monitoring or competitive surveillance without corresponding disclosure in the manifest, making the skill more dangerous in context than simple public keyword search.

Context-Inappropriate Capability

Low
Confidence
78% confidence
Finding
Requiring a GUAIKEI_API_TOKEN is inconsistent with the stated positioning of accessing public Xiaohongshu content without login, and it introduces a secret-handling requirement that is not explained in the manifest. This is dangerous because hidden credential dependencies can create unreviewed data flows to third-party services and prompt users or agents to provision sensitive tokens without understanding why they are needed.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
This module adds comment-collection capabilities that are broader than the declared skill scope, which only covers searching public notes and returning note lists plus engagement metrics. That scope expansion is security-relevant because it enables collection of user-generated comment content, increasing privacy, compliance, and data-minimization risk beyond what users and reviewers would reasonably expect from the manifest.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The CLI creates and retrieves a comment-harvesting task, which materially expands the skill beyond the declared scope of keyword-based note discovery and ranking. In this context, collecting comment content can expose additional user-generated data not necessary for the advertised research function, increasing privacy and scope-creep risk.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
Returning full note comments is not justified by the stated purpose of keyword/topic research over public notes, so the data access appears excessive relative to user expectations. Even if the source is public, unnecessary collection and redistribution of comment content broadens privacy exposure and may violate least-privilege/data-minimization principles.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The CLI’s implemented behavior is to collect posts from a specific blogger profile URL, while the declared skill scope is keyword-based discovery of public notes and trend research. This scope mismatch materially expands the data-access capability of the skill into targeted account collection, which can bypass user expectations, policy review assumptions, and least-privilege boundaries.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Accepting a direct profile URL enables targeted collection against a named account, which is broader and more privacy-invasive than aggregate keyword trend research. In the context of a social-content research skill, this creates an unjustified capability that could be repurposed for profiling, monitoring, or bulk extraction of a specific creator’s public content.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The CLI writes the full search output, including the user's keyword and returned results, to a local JSON file without any visible disclosure or consent flow in this file. This creates an unnecessary data-retention surface: queries may reveal sensitive research interests, and cached result sets can be exposed to other local users, backups, or later compromise.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The description says the skill may be used even when the user only says broad phrases like '最近什么火' or '帮我找热门内容' if the context seems related to social-media mining. Overbroad trigger conditions can cause accidental invocation on ambiguous requests, sending user queries to a third-party API without sufficiently clear platform-specific intent or informed consent.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README says all task results are automatically saved locally but does not clearly warn that user-supplied keywords/URLs and collected content may be persisted. This lack of disclosure can cause unintentional storage of potentially sensitive research terms, targets, or collected datasets, which is especially concerning in a monitoring and scraping context.

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The tool sends a user-supplied URL together with an API token to backend comment-task endpoints without a clear user-facing disclosure that the target URL and related request data will be transmitted to an external service. Because note links may contain tracking or access parameters such as xsec_token, this can unintentionally disclose sensitive URL components and surprise users about off-box processing.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The tool writes fetched profile post results to a local JSON file by default without explicit user notice or opt-in. Even if the source content is public, silent persistence increases the risk of unintended retention, secondary disclosure, and collection of targeted account data beyond the user’s immediate task.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This is the same underlying behavior as SDI-1 viewed through a privacy/disclosure lens: search results are silently persisted to disk. Even if the data is publicly sourced, silently saving user queries and output can violate user expectations and increase privacy and compliance risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.