T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Token Exposed in HTTP Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its Xiaohongshu public-data collection purpose, but needs review because it sends the API token in URL query strings and automatically saves full results locally in plaintext.
Install only if you are comfortable sending Xiaohongshu query inputs, URLs, and your Guaikei API token to www.guaikei.com. Treat generated logs as sensitive: they may contain collected profile/comment data and URL tokens, so avoid syncing or committing the logs directory and rotate the API token if you suspect exposure.
src/utils/request.js:76API Token Exposed in HTTP Query Strings
src/utils/log.js:5Collected Data and Token-Bearing URLs Persisted in Plaintext by Default
声明描述的是一个面向小红书公开数据采集的业务技能,而代码片段实际只是底层通用工具模块 src/utils/args.js,用于解析 CLI 参数。该代码未体现任何与小红书平台交互、公开数据抓取、笔记搜索、详情查询、评论获取、作品列表抓取、结构化返回相关的行为。虽然参数解析可能作为实现此类技能的配套基础设施,但就该代码片段本身而言,其实际功能与声明的核心用途明显不一致,因此应判定为描述与行为不匹配。
The declared purpose describes a network/data-collection skill focused on Xiaohongshu public content retrieval and structured analysis data. The actual code shown does not perform searching, scraping, note retrieval, comment retrieval, or creator post listing. Instead, it writes content to local files in a logs directory using Node.js fs APIs. While logging can be a supporting detail, this chunk exposes a concrete file-writing capability that is not reflected in the description or declared permissions, and its behavior is unrelated to the stated primary function of Xiaohongshu public-data acquisition.
The declared description presents a Xiaohongshu public-data acquisition skill with several scraping/query capabilities. The supplied code chunk does not implement any of those behaviors. Instead, it is a simple utility that reads package.json from the local filesystem and returns the package name. This is materially different from the declared primary purpose and uses a different resource type than expected. While this could be a harmless support utility within a larger project, based on the supplied chunk alone the behavior does not match the declared functionality.
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |
Referenced artifact was not completely inspected
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |
Referenced artifact was not completely inspected
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |
Without declared permissions the skill's intent is opaque and cannot be validated.
The manifest description is entirely written in Chinese and presents the skill as operating in that language without any mention of multilingual support or user language preference. Under the policy, locale or language constraints should either be optional or clearly documented with user opt-in or justification.
This section tells users to '优先采用以下自然语言触发方式' and provides only Chinese trigger examples, which implies a fixed language expectation. There is no indication that other languages are supported or that the user may choose their preferred language.
This code sends a user-provided note URL and an API token to remote endpoints via HTTP requests. While the function comments describe parameters, there is no user-facing confirmation, warning, or disclosure in the code indicating that user data and credentials will be transmitted off-system.
This JavaScript file contains natural-language comments and user-facing CLI/help text entirely in Chinese, including thrown error messages and generated help output. Under the policy, forcing a specific language without offering a choice or documenting a justified locale constraint is a natural-language policy violation.
The string literals require the user to read Chinese and direct them to add a specific WeChat contact to restore functionality. This imposes a language and communication-channel constraint without offering a language choice or documenting a justified locale limitation.
This code emits user-facing error text in Chinese (日志文件名必须是非空字符串, 日志内容必须是非空字符串) and later also prints success/failure messages in Chinese. Because the file provides no indication that the skill is China/Chinese-specific or that users can opt into a language, it creates a locale policy violation under the natural-language policy rule.
The success and error output at these lines is also hard-coded in Chinese (已保存到, 日志写入失败). Without explicit user opt-in or documentation that this skill is intended only for Chinese-speaking users, the file enforces a specific language choice contrary to the stated policy.
This code issues outbound HTTPS requests and can transmit query parameters and JSON payload data, but the file contains no confirmation prompt, user-facing log/print, or explanatory comment/docstring disclosing that network transmission occurs. For a generic request utility, that behavior is not clearly disclosed within the file itself.
The file contains multiple user-visible error messages exclusively in Chinese, including guidance shown when API authentication fails. Under the policy, forcing a specific language without offering user choice or documenting a justified locale restriction is a natural-language policy violation.
This JavaScript file contains multiple user-facing error strings in Chinese, such as the messages printed on invalid keyword input and option values. Because the skill forces a specific language in its natural-language output without any visible opt-in or justification that it is region-specific, it violates the language/locale policy criteria.
No suspicious patterns detected.