Back to skill

Security audit

guaikei-xhs-blogger-list

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed public Xiaohongshu data-fetching skill that uses a Guaikei API token and saves results locally, with some scope-labeling issues users should notice.

Install only if you are comfortable sending Xiaohongshu keywords or URLs, plus your Guaikei API token, to guaikei.com and keeping fetched public data in local JSON logs. Review the broader capabilities beyond keyword search before enabling it for an agent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The manifest and top-level description materially understate the skill's actual scope: it can retrieve note details, comments, and blogger post histories, not just recent keyword-sorted notes. This mismatch can mislead users or orchestrators into invoking broader data-collection behavior than expected, weakening informed consent and policy enforcement around third-party data access.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The description says the skill is for keyword-based recent-note retrieval, but the documentation exposes additional collection paths for note details, comments, and blogger post monitoring. Scope deception is dangerous because downstream agents may authorize or route requests under a narrower trust assumption than the skill actually deserves.

Description-Behavior Mismatch

Medium
Confidence
86% confidence
Finding
The package metadata advertises a broad Xiaohongshu analytics and growth toolkit, including competitor monitoring, KOL screening, and data mining, which is materially broader than the declared skill purpose of only retrieving recent posts by keyword. This scope mismatch is dangerous because it can mask additional capabilities from reviewers and operators, weakening trust boundaries and increasing the chance that a narrowly approved skill actually ships broader data-collection behavior.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The declared scripts expose operations for detail retrieval, posting, and commenting, which go beyond the manifest’s read-only trend-monitoring purpose. This is dangerous because extra write-capable or expanded interaction surfaces can enable unauthorized actions on the platform, accidental misuse by the agent runtime, or hidden capability escalation if these entry points are invoked despite the skill being presented as read-only.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The README materially overstates the skill’s capabilities compared with the manifest, describing competitor monitoring, KOL screening, comment analysis, and broader data-mining functions beyond the declared 'latest keyword posts' trend-monitoring scope. This can mislead users or downstream agents into invoking the skill for unintended data collection or analysis tasks, weakening scope-based safety controls and increasing the chance of misuse.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The usage examples directly instruct execution of detail lookup, profile post monitoring, and comment retrieval commands that fall outside the manifested skill purpose. In agent ecosystems, executable examples are especially risky because they can serve as operational guidance for over-broad behavior, enabling collection of additional public-but-sensitive engagement or profile data not covered by the approved scope.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The changelog indicates the skill has expanded capabilities beyond the manifest’s narrow description of fetching recently published Xiaohongshu posts by keyword. This creates a scope mismatch that can mislead users, reviewers, and enforcement systems about what the skill can actually do, increasing the risk of unreviewed data access or functionality being invoked under a narrower trust assumption.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The changelog explicitly states support for note details, comment retrieval, and creator work monitoring, while the manifest presents the skill as a single-purpose keyword recency search tool. Hidden or undocumented collection/monitoring features are dangerous because they can bypass user expectations and reduce scrutiny over broader scraping, profiling, or surveillance behavior.

Description-Behavior Mismatch

High
Confidence
94% confidence
Finding
Creator work monitoring goes materially beyond keyword trend discovery and introduces ongoing tracking of specific individuals or accounts. In this skill context, that is more sensitive because the declared purpose is trend spotting, so undisclosed monitoring functionality can enable profiling or persistent surveillance under a misleadingly limited description.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The changelog discloses note-detail extraction and comment sentiment analysis, both of which exceed the described functionality of retrieving recent keyword-matched posts. These additional analytical and data-collection capabilities can expose more user-generated content and enable richer profiling than reviewers or users would expect from the manifest alone.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The documentation expands the skill from the manifested 'keyword recent trend/list' scope into four broader capabilities, including note-detail, comment extraction, and creator post monitoring. This scope drift is dangerous because an agent may invoke capabilities the user or platform did not expect, increasing the chance of over-collection, privacy-sensitive scraping, or policy bypass through mismatched documentation.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
Claiming consistency with a new SKILL.md while presenting broader behavior than the manifested intent can mislead orchestration systems, reviewers, or downstream agents into trusting unsupported actions. That inconsistency weakens security review and makes unauthorized capability expansion harder to detect.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
This module performs comment-task creation and retrieval for a Xiaohongshu note URL, which exceeds the skill’s declared purpose of fetching recent notes by keyword for trend monitoring. That scope expansion is dangerous because it enables collection of user-generated comment data not disclosed by the manifest, increasing privacy, data-minimization, and consent risks while potentially exposing users to unexpected scraping behavior.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The file is explicitly documented as a comment module, which contradicts the stated skill behavior of recent-note keyword monitoring. Such undocumented capability mismatch is dangerous because it hides real data access behavior from reviewers and users, undermining trust boundaries and making it easier for privacy-invasive or out-of-scope collection to be shipped unnoticed.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The file implements creation and retrieval of note detail and comment data, which goes beyond the declared skill scope of listing recent Xiaohongshu notes by keyword sorted by latest. This capability expansion increases data access and collection surface, enabling retrieval of richer per-post and user-linked information than users or platform reviewers would expect from the manifest.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The code implements blogger post retrieval by URL, while the skill manifest says the skill should fetch recent keyword-sorted Xiaohongshu notes for trend monitoring. This capability mismatch is dangerous because a user invoking a keyword-trend skill could unknowingly trigger collection of a specific blogger's data instead, creating an undeclared data-access path and violating user expectations about what the skill does.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The module comments explicitly describe blogger detail and published-note functionality that contradict the manifest's keyword-trend purpose. In security terms, this discrepancy is a strong indicator of hidden or mislabeled behavior, which can mislead reviewers and users and make unauthorized data collection harder to detect.

Context-Inappropriate Capability

Medium
Confidence
78% confidence
Finding
The CLI enables harvesting comment data from a public note URL even though the declared skill purpose is trend monitoring by keyword. That undisclosed expansion of data collection increases privacy and misuse risk, because operators may collect user-generated comments at scale without clear limitation, consent messaging, or purpose binding.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The implemented CLI schema and help text clearly accept a blogger profile URL and fetch profile posts, while the skill manifest describes a keyword-based recent-notes trend capability. This mismatch is dangerous because users and downstream agents may invoke the skill under false assumptions, causing unintended scraping of a specific person’s content instead of topic monitoring and undermining security/privacy expectations tied to tool selection.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The generated output, request metadata, and persisted filename all represent a profile-based post task, not topic trend monitoring as advertised. This broadens the impact of the manifest mismatch by producing and storing data for a different collection target than the caller likely intended, increasing the chance of privacy, compliance, and operational misuse in agent workflows.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The code writes the full comment task output to a local JSON file automatically using a filename derived from the target URL, without any explicit user warning, consent, or retention control. Persisting harvested comment data locally can create unintended exposure on shared systems, leak sensitive or personal content, and expand the blast radius beyond transient CLI output.

Missing User Warnings

Medium
Confidence
76% confidence
Finding
The tool sends a user-supplied note URL and API token to external services via detail task creation and retrieval, but the interface does not clearly warn users that their input will be transmitted off-box. In this skill context, users may expect local trend analysis from the manifest description, so undisclosed external transmission increases privacy and trust risk, especially if URLs contain tracking parameters or sensitive access tokens.

Missing User Warnings

Medium
Confidence
81% confidence
Finding
The CLI persists fetched results to a local JSON file without clearly informing the user beforehand. Because results may include note content, comments, and metadata, silent local storage can create unintended data retention and exposure on shared systems or in synced working directories.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The CLI sends the user-supplied profile URL together with an API token to remote task endpoints, but the user-facing interface does not clearly disclose that network transmission will occur. In an agent setting, that hidden data flow can cause users or orchestrators to reveal URLs, identifiers, or access credentials to an external service without informed consent.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill persists fetched results to a local JSON file without clearly informing the user that scraped data will be stored on disk. Silent persistence increases the risk of unintended retention of scraped content, metadata, or identifiers on shared systems, which can create privacy and data-handling issues beyond the immediate command execution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16