Back to skill

Security audit

guaikei-xhs-author-tracker

Security checks across malware telemetry and agentic risk

Overview

This skill needs review because its top description says it is comment-only, but its docs and code support broader Xiaohongshu search, note-detail, author/profile monitoring, external API processing, and automatic local result storage.

Install only if you want the broader Xiaohongshu data-collection toolkit, not just comment analysis. Expect supplied keywords, note/profile URLs, and GUAIKEI_API_TOKEN-backed requests to be sent to www.guaikei.com, and expect returned data to be saved locally under logs. Clear saved outputs when no longer needed and avoid using it for private, sensitive, or unauthorized monitoring.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The manifest markets the skill as a comment-only analyzer, but the body documents broader scraping and local logging behavior including keyword search, note detail retrieval, author monitoring, and saving results to logs. This mismatch can cause unintended activation and data collection beyond user expectations, undermining consent and increasing privacy/compliance risk when the agent invokes a broader tool than advertised.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The manifest explicitly says the skill does not fetch note正文, yet examples and routing include a detail flow that returns note正文 and author data. This is a concrete scope violation that can mislead users and orchestrators into approving access under false assumptions, increasing the chance of overcollection and misuse of scraped content.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The manifest explicitly says the skill does not fetch note正文, yet examples and routing include a detail flow that returns note正文 and author data. This is a concrete scope violation that can mislead users and orchestrators into approving access under false assumptions, increasing the chance of overcollection and misuse of scraped content.

Intent-Code Divergence

Medium
Confidence
87% confidence
Finding
The title and introduction frame the skill as a broad Xiaohongshu data-mining and marketing suite, conflicting with the narrower manifest purpose. In context, this inconsistency makes the skill more dangerous because it encourages expansive collection and profiling of authors/commenters while presenting a smaller surface area in metadata.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The package metadata advertises broad capabilities such as market research, competitor monitoring, KOL screening, and account growth, which materially exceed the skill's declared comment-only purpose. This scope mismatch is dangerous because it can mislead reviewers and users about what the codebase is intended to do, increasing the chance that unrelated or over-privileged functionality is bundled and later exposed.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The declared scripts expose search, detail, and post operations even though the skill is supposed to be limited to retrieving comments and commenter interaction data. In this skill context, extra operational entry points are more dangerous because they indicate accessible capabilities outside the approved boundary, potentially enabling broader data collection or actions that the user and platform did not authorize.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The README materially misrepresents the skill’s scope: the metadata says this skill is for comment-only analysis, but the document markets a broad Xiaohongshu data-mining, competitor-monitoring, trend-tracking, and KOL-screening toolkit. This mismatch can cause overbroad collection and use of data beyond user expectations, defeating least-privilege assumptions and increasing the chance of unauthorized scraping or policy-violating use.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The README claims the tool does not obtain user privacy data while the skill description and examples indicate retrieval of commenter information and interaction data. Even if sourced from public pages, commenter identifiers/profile metadata may still be personal data, so this contradictory disclosure can mislead users and downstream operators about privacy risk and compliance obligations.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The changelog describes capabilities that materially exceed the manifest’s stated comment-only scope, including keyword search, note detail retrieval, blogger work monitoring, and sentiment analysis. This creates a scope-mismatch risk: orchestrators or reviewers may trust the narrower manifest while the underlying skill or related assets retain broader collection/monitoring functionality, increasing the chance of over-collection, unauthorized use, or policy bypass.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The documentation materially expands the skill’s apparent behavior beyond the manifest by describing four capabilities, including search, note detail retrieval, and creator post listing. This can cause an orchestrator or user to invoke the skill for broader data collection than intended, weakening least-privilege boundaries and creating a misleading trust surface.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The '笔记详情与评论' section directly contradicts the manifest by stating the skill can fetch note details and正文 in addition to comments. In context, this is more dangerous because the skill is explicitly marketed as comment-only; the mismatch may lead to overcollection of content, privacy surprises, or incorrect routing by an agent that trusts the docs.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The code does more than the skill description promises: it creates and retrieves note detail data and also constructs author profile URLs, even though the manifest says the skill should only fetch comments and not note正文/details. This violates least-privilege and can expose extra content and identity-linked metadata to downstream consumers, increasing privacy and scope-creep risk.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The module and function documentation explicitly describe 'note detail and comments' behavior, which conflicts with the declared comments-only purpose of the skill. This mismatch is dangerous because it signals intentional over-collection or at minimum undocumented behavior, making users and integrators rely on a narrower data scope than the code actually implements.

Description-Behavior Mismatch

High
Confidence
94% confidence
Finding
The implementation performs blogger-detail and published-post retrieval even though the skill manifest says the skill is for comment-only note tracking and analysis. This kind of scope mismatch is dangerous because it can cause the agent to collect broader profile/content data than users expect, creating unauthorized data access and privacy overcollection risks.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The inline documentation explicitly describes blogger details and published-note functionality, which contradicts the declared comment-only purpose of the skill. Misleading internal documentation increases the risk that reviewers, maintainers, or downstream agents enable data collection beyond the authorized scope without noticing.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
This file implements generic note search task creation, while the declared skill scope is limited to retrieving comments for a specific Xiaohongshu note. That scope expansion enables discovery and collection of unrelated notes and authors, which is a capability mismatch that can facilitate broader surveillance or data harvesting beyond the user's expected operation.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The code enriches results with note URLs and user profile URLs, which materially supports account and content discovery rather than comment-only analysis. In the context of a skill advertised as only retrieving comments for a given note, exposing profile links expands the accessible graph of targets and increases privacy and misuse risk.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The CLI schema, help text, validation, and downstream API calls all implement a blogger-profile post collection flow, while the manifest claims the skill is limited to note-comment analysis only. This mismatch is dangerous because users and upstream agents may invoke the skill expecting comment-only processing, but instead disclose broader profile data and retrieve unrelated content, violating least surprise and potentially collecting more personal data than authorized.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The user-facing help explicitly describes fetching a creator profile and their homepage notes, directly contradicting the skill description that says it only retrieves comments for a single note. In an agent ecosystem, this kind of documentation drift can cause policy bypasses and unintended data collection because operators rely on manifest and CLI descriptions to determine whether a tool is appropriate to run.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
This CLI implements general Xiaohongshu keyword search for posts/videos, which materially exceeds the declared skill scope of analyzing comments for a specific note. Scope expansion is dangerous because it enables broader content discovery and collection than users or platform reviewers would expect, increasing the chance of unauthorized scraping, privacy overreach, and misuse of the skill for monitoring or intelligence gathering.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The argument schema is built around arbitrary keyword discovery rather than taking a specific note identifier, which is inconsistent with a comment-analysis-only tool. That mismatch lowers trust boundaries and makes it easy to enumerate or discover unrelated content before later collecting associated engagement data, expanding surveillance capability beyond the stated purpose.

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The skill persists search results to disk via a generated JSON file even though the declared use case is comment retrieval and analysis, not general search archival. Silent retention increases data exposure risk because scraped content and metadata may remain on disk longer than necessary, be accessed by other users/processes, or be repurposed beyond the original request.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The auto-activation guidance is broad enough to trigger on generic requests about audience feedback whenever a note link is present, even if the user did not explicitly ask for comment scraping. In a skill that collects commenter information and interaction data, overbroad triggering increases the risk of unnecessary data retrieval and external transmission to the third-party API.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
Automatically saving all task results to the logs directory creates silent data persistence for scraped comments, commenter information, links, and interaction metrics. This increases the risk of privacy leakage, accidental redistribution, excessive retention, and local compromise, especially because the README does not warn users or describe retention, access controls, or opt-out behavior.

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The CLI sends the user-supplied note URL together with an API token to external comment-task endpoints without an explicit, user-facing disclosure at execution time about data transmission. In a data-collection skill handling URLs and potentially sensitive audience-feedback data, this creates a transparency and privacy risk because users may not realize their target resource is being processed by a third-party backend.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.