Back to skill

Security audit

guaikei-xhs-collector

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its Xiaohongshu public-data collection purpose, but needs review because it sends the API token in URL query strings and automatically saves full results locally in plaintext.

Install only if you are comfortable sending Xiaohongshu query inputs, URLs, and your Guaikei API token to www.guaikei.com. Treat generated logs as sensitive: they may contain collected profile/comment data and URL tokens, so avoid syncing or committing the logs directory and rotate the API token if you suspect exposure.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Token Exposed in HTTP Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:5
Finding

Collected Data and Token-Bearing URLs Persisted in Plaintext by Default

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.substring(0, 200); } if (safeFilename === "") { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outputFilename, content); utils.printSuccess(` → 已保存到 ${outputFilename}`); } catch (error) { utils.printError(`日志写入失败: ${error.message}`); } } ``` For example, the detail workflow includes the complete source URL and API result in the persisted object: ```js const finalOutput = { status: "success", error_code: "OK", message: "详情任务完成", timestamp: new Date().toLocaleString(), request: { command: "detail", url: url, limit: limit, }, skill_metadata: { skill_version: constants.VERSION, runtime_version: process.versions.node, execution_time: Date.now() - startTime, }, results: detailTask, }; console.log(JSON.stringify(finalOutput, null, 2)); utils.p ...[truncated 2471 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (41)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书公开数据采集的业务技能,而代码片段实际只是底层通用工具模块 src/utils/args.js,用于解析 CLI 参数。该代码未体现任何与小红书平台交互、公开数据抓取、笔记搜索、详情查询、评论获取、作品列表抓取、结构化返回相关的行为。虽然参数解析可能作为实现此类技能的配套基础设施,但就该代码片段本身而言,其实际功能与声明的核心用途明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes a network/data-collection skill focused on Xiaohongshu public content retrieval and structured analysis data. The actual code shown does not perform searching, scraping, note retrieval, comment retrieval, or creator post listing. Instead, it writes content to local files in a logs directory using Node.js fs APIs. While logging can be a supporting detail, this chunk exposes a concrete file-writing capability that is not reflected in the description or declared permissions, and its behavior is unrelated to the stated primary function of Xiaohongshu public-data acquisition.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a Xiaohongshu public-data acquisition skill with several scraping/query capabilities. The supplied code chunk does not implement any of those behaviors. Instead, it is a simple utility that reads package.json from the local filesystem and returns the package name. This is materially different from the declared primary purpose and uses a different resource type than expected. While this could be a harmless support utility within a larger project, based on the supplied chunk alone the behavior does not match the declared functionality.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description is entirely written in Chinese and presents the skill as operating in that language without any mention of multilingual support or user language preference. Under the policy, locale or language constraints should either be optional or clearly documented with user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This section tells users to '优先采用以下自然语言触发方式' and provides only Chinese trigger examples, which implies a fixed language expectation. There is no indication that other languages are supported or that the user may choose their preferred language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code sends a user-provided note URL and an API token to remote endpoints via HTTP requests. While the function comments describe parameters, there is no user-facing confirmation, warning, or disclosure in the code indicating that user data and credentials will be transmitted off-system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language comments and user-facing CLI/help text entirely in Chinese, including thrown error messages and generated help output. Under the policy, forcing a specific language without offering a choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The string literals require the user to read Chinese and direct them to add a specific WeChat contact to restore functionality. This imposes a language and communication-channel constraint without offering a language choice or documenting a justified locale limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits user-facing error text in Chinese (日志文件名必须是非空字符串, 日志内容必须是非空字符串) and later also prints success/failure messages in Chinese. Because the file provides no indication that the skill is China/Chinese-specific or that users can opt into a language, it creates a locale policy violation under the natural-language policy rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The success and error output at these lines is also hard-coded in Chinese (已保存到, 日志写入失败). Without explicit user opt-in or documentation that this skill is intended only for Chinese-speaking users, the file enforces a specific language choice contrary to the stated policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code issues outbound HTTPS requests and can transmit query parameters and JSON payload data, but the file contains no confirmation prompt, user-facing log/print, or explanatory comment/docstring disclosing that network transmission occurs. For a generic request utility, that behavior is not clearly disclosed within the file itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file contains multiple user-visible error messages exclusively in Chinese, including guidance shown when API authentication fails. Under the policy, forcing a specific language without offering user choice or documenting a justified locale restriction is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JavaScript file contains multiple user-facing error strings in Chinese, such as the messages printed on invalid keyword input and option values. Because the skill forces a specific language in its natural-language output without any visible opt-in or justification that it is region-specific, it violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.