Back to skill

Security audit

小红书博主洞察

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it sends an API token in request URLs and automatically saves queried URLs and returned data locally in plaintext.

Install only if you are comfortable sending Xiaohongshu queries and URLs to the Guaikei API and having results saved locally. Use a dedicated, revocable API token, avoid running it from shared or synced folders, review and delete logs regularly, and rotate the token if URLs or infrastructure logs may have exposed it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credential Exposed in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/xiaohongshu/detail-cli.js:138
Finding

Automatic Plaintext Persistence of Requested URLs and API Results

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.substring(0, 200); } if (safeFilename === "") { safeFilename = `log_${Date.now()}`; } const outputFilename = path.j ...[truncated 2835 chars]
Remediation
View remediation
` rather than writing every successful result automatically. 2. Remove or redact sensitive query parameters before printing or storing URLs: ```javascript function redactUrl(value) { const parsed = new URL(value); if (parsed.searchParams.has("xsec_token")) { parsed.searchParams.set("xsec_token", "[REDACTED]"); } return parsed.toString(); } ``` 3. Store a sanitized request object rather than the original URL. 4. Create the log directory and files with owner-only permissions: ```javascript await fs.promises.mkdir(logDirectory, { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, }); ``` 5. Document what data is stored, where it is stored, and how users can disable or delete it. 6. Implement retention controls, such as age-based deletion and a `--no-save` mode. 7. Add `logs/` to `.gitignore`, package ignore rules, backup exclusions, and artifact-upload exclusions. 8. Consider encryption at rest when persisted results may contain sensitive data. 9. Apply the same redaction and opt-in changes consistently to the search, detail, comment, and post CLIs. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (68)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents a skill for assessing a Xiaohongshu blogger's real engagement level using public works and note-level like/comment/favorite data. However, the code chunk is narrowly scoped to comment-task creation and retrieval for a single note URL through /api/xiaohongshu/comment/url and /api/xiaohongshu/comment/info. There is no code here for obtaining likes, favorites, creator-wide public works, or any analysis layer that judges whether engagement is inflated. This is a material mismatch in primary capability, not just an implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明的核心用途是评估某个博主或单篇笔记的真实互动数据(点赞/评论/收藏),重点是博主互动质量分析。实际代码并未获取或校验“真实点赞/评论/收藏数据”,也没有针对特定博主做互动质量评估;它只是调用关键词搜索接口获取笔记搜索结果,并补充结果链接。该行为的主要目的与声明不一致,属于搜索发现功能,而非博主互动数据分析功能。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书博主互动数据获取与评估的业务技能,但提供的代码片段只是通用CLI参数解析器,不包含任何网络请求、平台访问、数据提取、数据分析或与小红书相关的逻辑。该代码的主要用途与声明的核心功能明显不一致,因此属于实质性描述-行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose describes a data-retrieval and analytics capability focused on Xiaohongshu engagement quality. The actual code chunk is an authentication/helper module for checking whether a token is present and valid, then printing success or failure messages. This is materially different from the declared primary purpose, and the code shown does not implement any of the promised analytics behavior. While token management could be a supporting detail in a larger system, this chunk by itself does not match the declared functionality and instead introduces an unrelated contact/upsell message for obtaining a private token.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是面向小红书博主互动数据获取与分析的业务能力,但代码片段实际仅实现了本地日志文件写入功能,使用了文件系统和路径模块,对传入的文件名和内容进行校验与清洗后写入本地 logs 目录。该行为既没有体现获取小红书公开作品数据、点赞/评论/收藏统计,也没有任何互动质量评估逻辑。因此这不是单纯的支撑细节可直接对应声明目的,而是一个与声明主功能明显不一致的代码片段,应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description claims a data-collection and analysis skill focused on Xiaohongshu engagement metrics, but the supplied code chunk merely reads package.json from the local filesystem and returns the package name. This is a materially different purpose and uses unrelated resources. While this may be a small utility file, based on the supplied code alone it does not implement or support the claimed functionality in any meaningful, domain-specific way.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose centers on obtaining and assessing Xiaohongshu public engagement data for KOL analysis. However, this code chunk contains only helper functions for printing a banner and log messages. While such utilities could support a larger system, this supplied chunk does not itself perform any of the declared core behavior. Given the evaluation is based on the supplied code chunk versus the description, the actual behavior shown is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个面向小红书博主互动数据获取与评估的技能,核心能力应包括访问/解析公开作品或笔记数据,并计算或判断互动质量。而给定代码只是一个通用的输入校验模块:检查关键词长度、特殊字符、http 链接,清洗关键词字符集,并规范化 type/sort/time/limit 等搜索参数。它没有网络请求、没有平台数据访问、没有点赞评论收藏字段处理、也没有任何评估逻辑。因此,这段代码的实际行为与声明用途存在明显且实质性的不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Yes, there is a mismatch. The declared description promises a data-retrieval and evaluation capability focused on real likes, comments, favorites, and engagement quality for Xiaohongshu creators. However, the supplied code chunk contains only helper functions for URL normalization, URL type checking, and turning URLs into names. It does not fetch data from Xiaohongshu, parse note/profile contents, compute engagement metrics, or perform any KOL screening analysis. This is a materially different actual behavior from the declared purpose, not merely an implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个用于评估小红书博主真实互动水平的分析型技能,核心能力应包括获取博主或作品的点赞、评论、收藏等多维互动数据,并据此支持KOL筛选或数据注水判断。但该代码片段只实现了针对单篇笔记 URL 的评论抓取流程:校验链接、设定评论数量 limit、调用 createCommentTask/getCommentTask、输出评论任务结果、记录日志。没有任何代码表明它会获取点赞数、收藏数、博主作品列表、博主层级聚合数据,或进行“真实互动质量评估”。因此代码实际用途明显窄于且不同于声明用途,属于实质性描述不符。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明的核心能力是“获取博主及笔记真实互动数据并评估互动质量”,目标对象是博主/KOL分析。实际代码仅是搜索CLI入口,要求用户提供关键词,并通过 search.createSearchTask / getSearchTask 执行搜索,返回的是搜索结果列表。代码中没有体现按博主ID/主页抓取公开作品、提取单篇笔记真实点赞评论收藏、计算互动指标、识别注水,或输出任何KOL评估结论。虽然搜索结果可能间接包含小红书内容,但其主要用途与声明的分析型技能明显不同,因此属于实质性描述与行为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says this skill is for retrieving public Xiaohongshu blogger works and true like/comment/favorite metrics to assess engagement quality for KOL screening and anti-inflation checks. In contrast, the package description and keywords claim additional capabilities such as mining viral notes, monitoring competitors, market research, trend monitoring, user profiling, and driving account growth/precision marketing, which materially exceed the stated analytic scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest says this skill is for retrieving a Xiaohongshu blogger’s public works and note-level true like/comment/favorite metrics to assess interaction quality, and explicitly says it is not for follower estimation or backend data. The README instead presents the skill as a general Xiaohongshu data-mining tool for爆款挖掘, competitor monitoring, keyword search, comment analysis, and market trend prediction, which materially expands the stated purpose beyond blogger engagement evaluation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states that all task results are automatically saved to a local logs directory, but does not clearly warn that searched keywords, queried profile/note URLs, comments, and collected interaction data may be persisted on disk. In a marketing-intelligence context, this can create unintended local data retention and exposure risks, especially on shared machines, synced folders, or environments with weak file permissions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Manifest 将技能定位为获取博主公开作品及单篇笔记的真实点赞/评论/收藏数据,并用于互动质量评估,不用于粉丝数估算或后台数据。但更新日志明确记载了“关键词搜索”“获取评论信息”“博主作品监控”等附加能力,说明技能实际范围比描述更广,存在语义层面的能力不一致。

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:15