Back to skill

Security audit

guaikei·小红书评论舆情

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to retrieve Xiaohongshu data as advertised, but it handles tokens and saved results in ways users should review before installing.

Install only if you are comfortable sending Xiaohongshu keywords, links, and a Guaikei API token to guaikei.com. Use a scoped, revocable token, avoid private or unauthorized data, protect or delete the generated logs directory, and rotate the token if request URLs may have been captured by logs or telemetry.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credential Exposed in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:24
Finding

Automatic Plaintext Persistence of Retrieved Data and Access-Bearing URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (59)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明描述的是一个通用的小红书原始数据提供技能,覆盖“先拿小红书数据”这一广泛步骤,似乎可用于多种分析与报告前置场景。但代码内容只涉及评论模块,且接口明确是 /api/xiaohongshu/comment/...,功能局限于创建评论抓取任务和获取评论结果,并未显示支持笔记详情、作者信息、互动统计、搜索结果或其他广义“小红书数据”。因此声明范围明显宽于实际实现,属于描述与行为不完全一致的能力范围夸大。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明描述的是一个较宽泛的小红书原始数据提供技能,适用于多种后续分析场景;但实际代码仅处理特定子能力:根据博主 URL 创建并查询“已发布笔记”任务结果。虽然这仍属于“小红书数据”范畴,并且返回原始数据与声明部分一致,但声明中提到的用途如评论聚类需要评论数据支持,而该代码没有任何评论相关获取逻辑。另外,代码注释提到“博主详情、已发布笔记模块”,但实际导出的只有已发布笔记任务创建和查询,范围比声明窄。因此描述对能力边界存在夸大,属于描述与实际行为不完全一致的情况。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes a skill whose primary function is to obtain and return structured Xiaohongshu data for later analysis. However, the supplied code chunk is only a constants/config file. By itself, it does not demonstrate the advertised behavior of collecting or returning structured JSON data. While configuration files are a supporting detail, this chunk alone does not substantiate the declared purpose and instead points to an external service endpoint unrelated on its face to Xiaohongshu. Therefore, based on the provided code chunk, the description is not accurately represented.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书数据获取与结构化输出的技能,核心能力应当包括抓取、整理、返回小红书相关原始数据。但提供的代码片段仅是通用 CLI 参数解析器,处理命令行选项、位置参数、布尔开关、默认值、帮助信息等基础工具逻辑,没有任何与小红书、数据采集、JSON 结构化输出、选题分析或报告数据准备相关的实现。因此该代码的实际行为与声明用途存在明显且实质性的不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的核心能力是获取并返回结构化的小红书数据,用于后续分析流程;但提供的代码片段完全没有涉及小红书平台访问、数据抓取、JSON 结构化输出、表格/报告相关数据准备等逻辑。相反,这段代码的唯一实际功能是验证一个 API token 的格式,并在无效时输出错误提示与联系微信获取 token 的信息。因此其主要目的与声明严重不符,属于明显的描述-行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明的核心能力是提供小红书结构化数据,用于后续分析链路;而实际代码仅执行本地日志文件写入,没有任何小红书数据抓取、解析、结构化 JSON 生成或数据返回逻辑。该代码访问的资源是本地文件系统(logs 目录),这与声明中仅提供原始小红书数据的用途明显不一致,属于主要目的和能力不匹配,而非单纯的辅助实现细节。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is a data acquisition skill for structured Xiaohongshu content, but the actual code chunk is merely a utility that reads package.json from the local filesystem and returns the package name. This is materially different from the stated primary purpose and uses an unrelated resource. While reading package metadata is not necessarily harmful, it does not implement the described capability at all, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

该代码片段只是一个通用重试工具,负责在异步操作失败时按指数退避策略重试,并支持错误回调与不可重试错误的提前抛出。它没有任何与小红书相关的数据抓取、处理、结构化 JSON 输出、选题汇总、高赞对比、评论聚类或报告生成前置数据准备有关的逻辑。虽然重试机制可能作为实现小红书数据获取流程的辅助细节存在,但就此代码片段本身而言,其主要行为与声明的技能用途存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明的核心能力是提供小红书原始结构化数据,而这段代码只是一个日志/打印工具模块,用于输出 banner 和分级日志。虽然日志工具可以作为配套实现细节存在,但就该代码块本身而言,其实际行为与“返回结构化 JSON 的小红书数据”这一声明不相符,也没有展示任何数据采集、整理、序列化或返回能力,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个面向小红书数据获取与结构化输出的技能,核心能力应是拉取并返回可供后续分析的原始数据。但给出的代码片段只处理用户输入的搜索关键词和搜索参数,属于辅助性的验证/清洗逻辑。按照评估标准,单纯的支持性实现细节本身不算问题;但这里的问题在于,所展示代码完全没有体现声明中的主要目的,实际行为与声明的核心功能存在实质性偏离。因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向小红书数据获取的技能,核心能力应是返回结构化数据,供后续分析或报告使用。但提供的代码只是在本地对 URL 进行规范化和识别,判断是否为笔记链接或个人主页链接,并生成一个基于 URL 的名称。这属于输入校验辅助逻辑,而不是描述中的主要功能。虽然这些函数可能是更大系统中的支持模块,但就该代码块本身而言,其实际行为与声明的核心用途存在明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

整体上,代码与“返回结构化 JSON 的小红书数据”这一核心目标基本相关,确实会输出结构化 JSON,且结果适合后续分析使用。但描述称只提供原始数据,而代码除了输出数据外,还会把结果落盘到本地 JSON 文件,这属于未声明的附加能力。另一个轻度偏差是,代码实际只处理博主主页链接并获取主页笔记,不是广义上的所有小红书数据类型。不过其主用途仍然属于小红书数据获取,因此这是部分不一致而非完全不同功能。综合判断为存在描述与行为不完全匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill requires access to a sensitive environment variable (GUAIKEI_API_TOKEN) and instructs execution of external commands, but it declares no explicit tool scope such as allowed tools or permissions. This weakens least-privilege controls and can let an agent invoke the skill without clear gating over secret use or command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation guidance is overly broad: it says the skill should be used whenever a task chain includes 'first get Xiaohongshu data'. Overbroad routing can cause the agent to invoke an external data-fetching skill unexpectedly, exposing URLs, keywords, and tokens to a third-party service when a narrower or local workflow would suffice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill manifest says this skill only returns structured Xiaohongshu raw data for downstream reporting and analysis, and explicitly says it does not handle final report generation. In contrast, the package description and keywords position it as a full analytics and marketing-growth tool for爆款挖掘、竞品监控、KOL筛选、精准营销, which is materially broader than simple data retrieval.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README materially expands the skill’s apparent behavior beyond the manifest’s narrow claim of only returning structured Xiaohongshu data. It advertises broader monitoring, trend analysis, KOL screening, batch collection, and automatic persistence to local logs, which creates a capability mismatch that can mislead users and reviewers about what the skill actually does and what data it stores.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file title and all changelog content are written entirely in Chinese, and there is no indication that language selection is optional or that the skill is intentionally limited to a Chinese-only audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a skill focused on providing structured Xiaohongshu raw data to support later reporting or comparison tasks. The changelog states the skill added '博主作品监控' (creator works monitoring), which is a broader ongoing monitoring capability not reflected in the manifest’s narrower data-provision purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest says the skill only provides raw structured Xiaohongshu data and is not responsible for final reports. The changelog describes '竞品分析', 'KOL筛选', and '趋势监控' as core business analysis functions, which reads as broader analytical/monitoring behavior than merely returning source data for later use.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16