T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:85- Finding
API Credential Exposure Through URL Query Parameters
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to collect public Xiaohongshu data as advertised, but it needs review because it sends the API token in request URLs and automatically saves fetched results locally.
Before installing, confirm you are comfortable sending your GUAIKEI_API_TOKEN, Xiaohongshu URLs, keywords, and requested collection limits to guaikei.com. Treat the token as sensitive because this implementation places it in URL query strings. Also expect fetched post/comment results to be saved locally under logs and manage those files according to your data policy.
src/utils/request.js:85API Credential Exposure Through URL Query Parameters
声明描述的核心能力是“围绕某个博主账号做作品列表+详情+评论的竞品分析数据采集”。但这段代码的实际功能仅是调用小红书笔记关键词搜索接口:创建搜索任务、查询搜索结果,并为结果补充笔记/用户主页URL。它的主目的更接近‘关键词搜索公开笔记’,而不是‘根据博主主页抓取其作品并分析表现’。虽然都属于小红书公开内容范围,但资源对象、输入方式和核心能力都有明显差异,属于实质性不匹配。
声明描述的是一个面向小红书博主公开内容抓取与分析的技能,而实际代码仅是通用 CLI 参数解析器(parseArgs/readValueAfterFlag/buildHelp)。这段代码没有访问小红书、没有抓取作品列表、没有读取笔记详情或评论、没有做节奏/风格/互动分析。虽然参数解析器可能作为整个项目的辅助模块存在,但就该代码块本身而言,其行为与声明的核心能力不一致,属于明显的描述-行为不匹配。
声明描述的是一个用于抓取和分析小红书公开博主作品、笔记详情与评论的数据分析型技能;而提供的代码片段只处理 API TOKEN 的格式校验和错误提示,核心行为是接入控制与私有令牌配置提示。它没有体现任何与小红书页面访问、内容抓取、评论处理、节奏分析或互动表现分析相关的实现。虽然 token 管理可能是配套基础设施,但该代码片段的实际功能与声明的主要用途明显不一致,因此应判定为描述与行为不匹配。
声明描述的是一个面向小红书公开内容抓取与分析的技能,核心能力应涉及网络抓取、解析作品列表/笔记/评论,以及内容分析。实际提供的代码片段并未体现任何与小红书数据抓取、页面访问、内容分析或评论处理相关的行为,而是一个通用的本地日志写入模块,使用 fs 和 path 在本地文件系统中创建 logs 目录并写入文件。这属于与声明目的明显不一致的实际行为。尽管日志功能可能作为辅助实现存在,但当前代码片段本身的主行为与声明技能目标无直接对应,因此应判定为描述与行为不匹配。
The declared description is about collecting and analyzing public Xiaohongshu account content. The actual code chunk is a small utility that accesses the local filesystem, loads package.json, and returns the package name. This behavior is materially unrelated to the declared primary purpose. While utility code can be supportive, this snippet shows no scraping, no network access, no content analysis, and no Xiaohongshu-specific logic; instead it performs an undeclared local file read. Therefore the description does not accurately represent what this supplied code chunk actually does.
声明描述的是一个面向小红书博主竞品分析的数据采集与分析技能,核心能力应包括处理博主主页链接、抓取公开作品、获取详情与评论并进行内容表现分析。而提供的代码块只是在本地对“搜索关键词”做长度、字符、链接检测,对搜索类型/排序/时间/数量参数做默认值与范围修正。这与声明的主要用途明显不一致,且代码行为更接近‘关键词搜索输入校验模块’。尤其声明提到给博主主页链接即可适用,但代码明确将包含 http 的输入判为无效,进一步表明其与所宣称的链接驱动型博主分析场景不匹配。
声明的核心用途是对“小红书博主/竞品账号”进行账号层面的内容分析,前提能力应包括抓取博主公开作品列表,再结合多篇笔记详情与评论进行汇总分析。但这段代码只接受单个笔记 URL,调用 detail 相关接口获取该笔记详情和指定数量评论,并输出结果。它没有显示任何博主主页解析、作品列表枚举、跨多篇笔记聚合、发文节奏分析或竞品账号监控逻辑。因此其主要行为与声明的主要目的存在实质偏差。虽然后者提到会配合笔记详情与评论,但本代码只是该能力中的一个子步骤,不能单独代表已声明的完整技能。
声明描述的是一个较完整的竞品分析型技能:不仅抓取公开作品列表,还要配合笔记详情与评论,还原内容节奏和互动表现。但这段代码实际只接受博主主页 URL 和 limit,校验 URL 后调用 post 相关 API 创建/查询‘主页笔记任务’,最终返回 postTask 结果并写日志。从可见代码看,其明确行为仅能支持‘获取博主主页笔记列表/任务结果’这一层,未看到评论抓取、详情抓取、分析逻辑,也没有任何与互动表现或内容风格建模相关的处理。因此,代码行为相较声明明显更窄,存在描述与实际能力不一致。另一方面,代码使用公开主页链接且未显示登录态/私密数据访问,这部分与声明一致。
声明的核心能力是“面向特定博主账号的公开作品、详情和评论采集与分析”。但该代码块的主功能是通用关键词搜索:解析 --keyword、--type、--sort、--time、--limit 参数,校验关键词,调用 search.createSearchTask / getSearchTask 获取搜索结果并输出 JSON。它访问的是搜索接口语义,而不是博主主页/作品列表接口;也没有任何针对单个博主、作品详情、评论抓取或内容节奏分析的实现。因此这不是简单的实现细节差异,而是主要用途和能力范围都与描述明显不一致。
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Without declared permissions the skill's intent is opaque and cannot be validated.
The README advertises capabilities such as keyword search, trend monitoring, and KOL screening that go beyond the narrower manifest description of blogger post/comment insights. This scope drift is dangerous because users and orchestrators may grant or invoke the skill under an incomplete understanding of what data collection and analysis functions it performs, increasing the risk of misuse and policy bypass.
Detected: suspicious.exposed_secret_literal