Back to skill

Security audit

guaikei·小红书评论获取

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do the advertised Xiaohongshu public-data retrieval, but it handles API tokens and saved results in ways users should review before installing.

Review this before installing if your searches, target profiles, comments, or Xiaohongshu URLs are sensitive. Use a low-privilege Guaikei token, avoid printing the token, treat generated logs as sensitive, and delete or protect logs after use. The behavior looks purpose-aligned rather than malicious, but its credential and data-retention handling need caution.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
src/utils/request.js:76
Finding

API Credential Exposed in HTTP Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:150
Finding

Troubleshooting Instructions Expose the Complete API Token

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/log.js:25
Finding

Access-Bearing URLs and Complete API Results Are Persisted with Default File Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (36)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书内容采集与分析的技能,而给定代码只是在 src/utils/args.js 中提供通用命令行参数解析与帮助文本生成功能。这类代码可以作为底层支持工具,但当前片段本身没有访问小红书、处理链接、抓取公开内容、返回结构化业务数据或执行任何与爆款挖掘/竞品分析/KOL筛选相关的核心行为。根据评估标准,不应因普通支持性实现细节单独判定不符;但这里提供的代码片段与声明的核心功能相差过大,实际主行为是 CLI 工具参数处理,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向小红书公开数据抓取与分析的技能,但提供的代码片段只展示了日志写入功能,没有任何与小红书搜索、抓取笔记、获取评论、解析链接或返回结构化内容数据相关的行为。该代码实际访问的资源是本地文件系统(创建 logs 目录并写文件),这属于声明中未体现的能力。虽然日志记录可能是辅助实现细节,但当前片段本身的主要行为与声明目的明显不一致,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose describes a Xiaohongshu content retrieval and analysis skill, but the supplied code chunk is only a local utility that reads package.json to obtain the package name. This behavior is materially different from the declared primary purpose and does not implement any of the stated Xiaohongshu-related capabilities. While utility code can be supportive, this specific chunk has no observable relationship to the declared functionality other than generic skill metadata handling, so the code and description do not align for this chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document instructs users to configure an API token and use commands that fetch Xiaohongshu public content, comments, and profile data, but it does not clearly disclose that these actions send user-supplied keywords, URLs, and retrieved content to an external service. This creates a transparency and consent problem: users may provide sensitive targets, research topics, or links without realizing they are being transmitted off-platform to a third-party API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The function sends the provided API token as part of an HTTP request, which is a sensitive credential operation covered by the warning requirement for code files. Although the JSDoc names the parameter as an API token, there is no explicit user-facing warning, confirmation, or disclosure here that credentials will be transmitted to a remote endpoint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This function performs an HTTP GET request that transmits the API token and user-supplied search keyword, which may contain sensitive or private user data. The file includes no user-facing warning or disclosure that these values are sent to a remote service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The user-facing strings are entirely in Chinese and provide no indication that other languages are supported or that the user can choose a preferred language. This creates a natural-language policy issue because the skill imposes a specific language on users without documented opt-in or locale justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple error strings are hard-coded in Chinese, including credential and request-failure messages. This imposes a specific language on users without offering locale selection or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code builds and sends HTTPS GET and POST requests using caller-supplied params and data, which may include user or system data. There is no confirmation prompt, logging, comment, or docstring in this file disclosing that data is transmitted over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language comments and user-facing error messages exclusively in Chinese, such as at L04-L05 and L08-L68. Under the policy, forcing a specific language without user opt-in or a documented locale justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This JavaScript code reads a credential from the GUAIKEI_API_TOKEN environment variable and then calls remote task APIs with the user-supplied URL. While the CLI prints status messages, it does not clearly disclose that user input and authentication data will be sent to an external service, which is a safety-relevant network operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The calls to search.createSearchTask(...) and search.getSearchTask(...) transmit the user's keyword and related search parameters to an external service. While network use is implied by the tool's purpose, this file's help text does not explicitly warn that user input is sent to a remote API, which is relevant for privacy-sensitive searches.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script persists full search results to a local JSON file without clearly warning the user in help or runtime messaging. Even if the queried content is public, saved files can accumulate sensitive research terms, analyst activity, or scraped datasets on shared systems, creating an avoidable privacy and data-retention risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The package description and keywords are entirely in Chinese and centered on the Xiaohongshu platform, which implicitly constrains the skill's language/locale context. In this manifest there is no indication that users can choose another language or that the locale restriction is explicitly documented as a justified regional limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README consistently uses Chinese for all headings, instructions, warnings, and usage examples, which imposes a specific language on users without any opt-in or alternative locale guidance. Under the policy, forcing a specific language without user choice is a natural-language policy concern unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The changelog begins with a Chinese-only heading and all visible content is written in Chinese, with no indication that language selection is optional or that the skill is specifically limited to a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

SQP-3 适用于所有文件类型,需关注语言/locale 政策。该文档从标题到触发示例均固定为中文指令和中文使用方式,没有看到任何语言选择、可切换说明,或对中文限定场景的明确理由。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file contains natural-language comments and parameter descriptions exclusively in Chinese, which can impose a specific language on users or maintainers without any opt-in. The policy explicitly calls out forced language or locale as a violation unless a justified regional constraint or user choice is provided.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16