Back to skill

Security audit

guaikei-xhs-comment-list

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it handles API credentials and saved social-media data in ways users should review before installing.

Install only if you are comfortable sending Xiaohongshu keywords, URLs, and task parameters to guaikei.com using a GUAIKEI_API_TOKEN. Treat the token as sensitive, rotate it if it may have appeared in logs, and avoid running this in shared, synced, or CI workspaces unless you are prepared to manage and delete the generated logs directory. Review whether automatic local saving and token-in-query behavior are acceptable for your use case.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:77
Finding

API Token Transmitted in URL Query Strings

Content
View full analysis
{ return await postJson( "/api/xiaohongshu/note-search/keyword", { _: Date.now(), token: token }, { keyword, type, sort, time, limit }, ); }, constants.CREATE_MAX_ATTEMPTS, (attempt, err) => { utils.printError( `【创建任务重试】 ${attempt + 1}/${constants.CREATE_MAX_ATTEMPTS} 次 - ${err.message}`, ); }, ); } ``` GET polling requests expose the token in the same way: ```js async function getSearchTask(token, keyword, type, sort, time, limit) { return await withRetry( async () => { const res = await getJson("/api/xiaohongshu/note-search/info", { _: Dat ...[truncated 2372 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:5
Finding

Automatic Plaintext Persistence of Sensitive URLs and Retrieved Data

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.substring(0, 200); } if (safeFilename === "") { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outputFilename ...[truncated 3224 chars]
Remediation
View remediation
` or `--save`. 2. Do not write successful results by default when the same data has already been returned through standard output. 3. Redact sensitive query parameters before printing or saving URLs: ```js function redactUrl(rawUrl) { const parsed = new URL(rawUrl); if (parsed.searchParams.has("xsec_token")) { parsed.searchParams.set("xsec_token", "[REDACTED]"); } return parsed.toString(); } ``` 4. Recursively redact `xsec_token`, API tokens, cookies, authorization values, and comparable secrets from returned objects before persistence. 5. Create directories and files with restrictive permissions, such as directory mode `0700` and file mode `0600`: ```js await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, content, { mode: 0o600, }); ``` 6. Add configurable retention and automatic cleanup for old result files. 7. Warn users before storing datasets in shared, synchronized, backed-up, or CI workspace directories. 8. Document automatic persistence, stored fields, retention, and deletion procedures prominently in `SKILL.md`. 9. Avoid placing sensitive identifiers in filenames, even after sanitization. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

代码片段仅实现了通用参数解析器(parseArgs、readValueAfterFlag、buildHelp),处理命令行选项、布尔值、位置参数、重复参数校验、必填检查和帮助信息生成。这与声明的“小红书内容抓取并结构化输出”主功能不一致。当前代码没有任何网络请求、平台接口调用、数据抓取、解析小红书页面/接口、评论或博主作品获取等行为。虽然 CLI 参数解析可能是抓取工具的辅助模块,但就该代码片段本身而言,其实际行为与声明用途明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书内容采集与结构化导出的技能,核心能力应包括网络请求、抓取搜索/笔记/评论/博主数据等。而给出的代码片段仅通过 fs 和 path 读取本地 package.json,并返回包名。这既没有实现也没有体现与小红书数据获取相关的行为,反而执行了一个与声明用途无关的本地元数据读取操作。虽然这可能是辅助代码片段,但基于当前提供的代码,其实际行为与声明用途存在明显不一致。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
node src/xiaohongshu/detail-cli.js --url "<笔记链接>" [--limit N]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares access to an environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool scope such as permissions or allowed-tools. That weakens least-privilege guarantees and can let the runtime expose more capability than users expect, especially when the skill also routes data to a third-party API.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation condition is intentionally broad: even when the user does not explicitly request collection or scraping, the skill should trigger for many generic Xiaohongshu data tasks. Over-broad routing can cause unintentional use of a third-party data-exfiltrating workflow, sending user-provided links, keywords, or analysis targets to an external service without clear informed intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill depends on guaikei.com as a third-party API intermediary, yet the warning about external data transfer appears later in the document under compliance notes rather than before execution guidance. Users may therefore initiate collection of Xiaohongshu URLs, keywords, and associated public content without seeing a prominent pre-execution disclosure that their requests are being sent off-platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not warn users that scraped note/comment data may contain personal or sensitive content and will persist on disk. In a data-scraping skill focused on social-media comments and profiles, silent local retention increases the risk of unintended data exposure, over-retention, and mishandling by downstream users or other local processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file instructs users to pull comment data, analyze public discussion, and monitor competitor or KOL accounts, which can affect privacy expectations and data handling. While the file explains how to run the capability, it does not include any warning or disclosure about handling scraped public content, user comments, or compliance considerations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document instructs users to set the GUAIKEI_API_TOKEN environment variable but gives no guidance on protecting the token from logs, screenshots, shell history, source control, or prompt/output disclosure. In an agent/tooling environment, missing secret-handling guidance increases the chance of accidental credential exposure and subsequent unauthorized API use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The function sends the provided API token and target URL in a network request via postJson, which is a safety-relevant data transmission. While the docstring describes parameters and errors, it does not disclose to the user that these values will be sent to an external API, and there is no confirmation or user-facing notice in the code shown.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This function performs a network call with the API token, note URL, and query parameters, but the visible documentation only states that it retrieves task results. There is no explicit warning or disclosure here that user-provided data and credentials are sent over HTTP to an external endpoint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code sends the provided API token as part of an HTTP request, which is a safety-relevant operation involving credential transmission. Although the function comments document the parameter, there is no user-facing warning, confirmation, or disclosure indicating that the token will be sent to an external API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The function performs an HTTP request that transmits user-provided search keywords together with the API token. This affects user data/privacy and credentials, but the file contains no confirmation prompt or user-facing disclosure about the outbound transmission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The user-facing strings at L22-L25 are written only in Chinese and provide no indication that other languages are supported or that Chinese is required for a region-specific purpose. This can violate language/locale policy when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file returns user-visible error messages entirely in Chinese, including guidance text, without any indication that the skill is region-specific or that users can opt into a language/locale. That creates a natural-language locale policy concern because the implementation effectively forces one language for all users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This helper constructs and sends HTTPS POST requests using caller-supplied params and JSON data, which may include user or system data, but the file provides no confirmation prompt, logging, or explanatory comment/docstring disclosing that transmission. Under the code-file criteria, network calls that transmit data should have some visible disclosure unless the warning is documented elsewhere or clearly inherent from the skill context, which is not evident from this file alone.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The GET helper appends supplied params to the request URL and sends them to a remote host, but there is no print/log/comment/docstring warning that caller-provided data is transmitted externally. For code files, outbound network transmission of user or system data should include some form of disclosure when not otherwise clearly documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JavaScript file contains natural-language comments and error messages exclusively in Chinese, such as the function descriptions and validation errors. Under the policy, forcing a specific language without offering user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI persists fetched comment data to a local JSON file by default after printing results, with no explicit consent, warning, retention control, or sanitization. Because this skill is designed to collect third-party social platform content at scale, the saved file can contain personal data or sensitive business research data that remains on disk and may later be exposed through shared machines, backups, logs, or misconfigured directories.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI writes fetched note details and comments to a local JSON file after printing results, but this file does not clearly warn the user that potentially sensitive third-party content will be persisted on disk. Local persistence increases the chance of unintended retention, exposure to other local users/processes, and accidental inclusion in backups or source control. In a scraping/export skill whose purpose is to collect and structure Xiaohongshu content at scale, silent storage is more dangerous because users may process large volumes of comment data without realizing it is being retained.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI sends the provided Xiaohongshu profile URL and an API token to backend post APIs via createPostTask and getPostTask. Although the help text mentions configuring GUAIKEI_API_TOKEN, it does not clearly warn users that input data will be transmitted to an external service, so the network behavior lacks adequate disclosure.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16