T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Credential Exposed in HTTP Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to do the advertised Xiaohongshu public-data retrieval, but it handles API tokens and saved results in ways users should review before installing.
Review this before installing if your searches, target profiles, comments, or Xiaohongshu URLs are sensitive. Use a low-privilege Guaikei token, avoid printing the token, treat generated logs as sensitive, and delete or protect logs after use. The behavior looks purpose-aligned rather than malicious, but its credential and data-retention handling need caution.
src/utils/request.js:76API Credential Exposed in HTTP Query Strings
SKILL.md:150Troubleshooting Instructions Expose the Complete API Token
src/utils/log.js:25Access-Bearing URLs and Complete API Results Are Persisted with Default File Permissions
声明描述的是一个面向小红书内容采集与分析的技能,而给定代码只是在 src/utils/args.js 中提供通用命令行参数解析与帮助文本生成功能。这类代码可以作为底层支持工具,但当前片段本身没有访问小红书、处理链接、抓取公开内容、返回结构化业务数据或执行任何与爆款挖掘/竞品分析/KOL筛选相关的核心行为。根据评估标准,不应因普通支持性实现细节单独判定不符;但这里提供的代码片段与声明的核心功能相差过大,实际主行为是 CLI 工具参数处理,因此应判定为描述与行为不匹配。
声明描述的是一个面向小红书公开数据抓取与分析的技能,但提供的代码片段只展示了日志写入功能,没有任何与小红书搜索、抓取笔记、获取评论、解析链接或返回结构化内容数据相关的行为。该代码实际访问的资源是本地文件系统(创建 logs 目录并写文件),这属于声明中未体现的能力。虽然日志记录可能是辅助实现细节,但当前片段本身的主要行为与声明目的明显不一致,因此应判定为描述与代码行为不匹配。
The declared purpose describes a Xiaohongshu content retrieval and analysis skill, but the supplied code chunk is only a local utility that reads package.json to obtain the package name. This behavior is materially different from the declared primary purpose and does not implement any of the stated Xiaohongshu-related capabilities. While utility code can be supportive, this specific chunk has no observable relationship to the declared functionality other than generic skill metadata handling, so the code and description do not align for this chunk.
Referenced artifact was not completely inspected
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |
Referenced artifact was not completely inspected
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |
Referenced artifact was not completely inspected
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |
Without declared permissions the skill's intent is opaque and cannot be validated.
The document instructs users to configure an API token and use commands that fetch Xiaohongshu public content, comments, and profile data, but it does not clearly disclose that these actions send user-supplied keywords, URLs, and retrieved content to an external service. This creates a transparency and consent problem: users may provide sensitive targets, research topics, or links without realizing they are being transmitted off-platform to a third-party API.
The function sends the provided API token as part of an HTTP request, which is a sensitive credential operation covered by the warning requirement for code files. Although the JSDoc names the parameter as an API token, there is no explicit user-facing warning, confirmation, or disclosure here that credentials will be transmitted to a remote endpoint.
This function performs an HTTP GET request that transmits the API token and user-supplied search keyword, which may contain sensitive or private user data. The file includes no user-facing warning or disclosure that these values are sent to a remote service.
The user-facing strings are entirely in Chinese and provide no indication that other languages are supported or that the user can choose a preferred language. This creates a natural-language policy issue because the skill imposes a specific language on users without documented opt-in or locale justification.
Multiple error strings are hard-coded in Chinese, including credential and request-failure messages. This imposes a specific language on users without offering locale selection or documenting a justified region-specific constraint.
This code builds and sends HTTPS GET and POST requests using caller-supplied params and data, which may include user or system data. There is no confirmation prompt, logging, comment, or docstring in this file disclosing that data is transmitted over the network.
This JavaScript file contains natural-language comments and user-facing error messages exclusively in Chinese, such as at L04-L05 and L08-L68. Under the policy, forcing a specific language without user opt-in or a documented locale justification is a natural-language policy violation.
This JavaScript code reads a credential from the GUAIKEI_API_TOKEN environment variable and then calls remote task APIs with the user-supplied URL. While the CLI prints status messages, it does not clearly disclose that user input and authentication data will be sent to an external service, which is a safety-relevant network operation.
The calls to search.createSearchTask(...) and search.getSearchTask(...) transmit the user's keyword and related search parameters to an external service. While network use is implied by the tool's purpose, this file's help text does not explicitly warn that user input is sent to a remote API, which is relevant for privacy-sensitive searches.
The script persists full search results to a local JSON file without clearly warning the user in help or runtime messaging. Even if the queried content is public, saved files can accumulate sensitive research terms, analyst activity, or scraped datasets on shared systems, creating an avoidable privacy and data-retention risk.
The package description and keywords are entirely in Chinese and centered on the Xiaohongshu platform, which implicitly constrains the skill's language/locale context. In this manifest there is no indication that users can choose another language or that the locale restriction is explicitly documented as a justified regional limitation.
The README consistently uses Chinese for all headings, instructions, warnings, and usage examples, which imposes a specific language on users without any opt-in or alternative locale guidance. Under the policy, forcing a specific language without user choice is a natural-language policy concern unless clearly justified as region-specific.
The changelog begins with a Chinese-only heading and all visible content is written in Chinese, with no indication that language selection is optional or that the skill is specifically limited to a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
SQP-3 适用于所有文件类型,需关注语言/locale 政策。该文档从标题到触发示例均固定为中文指令和中文使用方式,没有看到任何语言选择、可切换说明,或对中文限定场景的明确理由。
This code file contains natural-language comments and parameter descriptions exclusively in Chinese, which can impose a specific language on users or maintainers without any opt-in. The policy explicitly calls out forced language or locale as a violation unless a justified regional constraint or user choice is provided.
Detected: suspicious.exposed_secret_literal