Back to skill

Security audit

guaikei·小红书内容枢纽

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform the advertised Xiaohongshu research tasks, but it needs review because it sends its API token in URL parameters and automatically saves full results locally.

Install only if you are comfortable sending Xiaohongshu keywords, links, and fetched public data to Guaikei and storing complete outputs in local logs. Use a dedicated, revocable API token and avoid running it in shared, synced, or sensitive workspaces unless you can manage or delete the generated log files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:81
Finding

API Credential Transmitted in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:25
Finding

Automatic Persistence of Full API Results Without Opt-In or Retention Controls

Content
View full analysis
Remediation
View remediation
` or `--save`. 2. Clearly disclose local persistence before execution when saving is enabled. 3. Create directories and files with owner-only permissions: ```js await fs.promises.mkdir(directory, { recursive: true, mode: 0o700 }); await fs.promises.writeFile(outputFilename, content, { mode: 0o600, flag: "wx" }); ``` 4. Redact sensitive URL parameters such as `xsec_token` before writing requests or results. 5. Avoid storing complete response objects when only a summary is required. 6. Add configurable retention limits and a cleanup command for previously generated logs. 7. Exclude the `logs/` directory from version control, package publication, backups, and synchronization by default where appropriate. 8. Document the exact data categories written to disk and their storage location. 9. Add tests confirming that no file is created unless persistence was explicitly requested and that saved files receive restrictive permissions. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (32)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书公开内容采集与分析的技能,核心能力应包括访问/抓取小红书内容、解析笔记与评论、处理博主作品等。实际代码仅是独立的通用参数解析模块,负责读取命令行参数、校验 flag、处理默认值和输出帮助信息。这属于底层支持组件,但当前提供的代码片段本身并未实现或直接体现声明中的任何核心业务能力。因此,基于该代码片段与声明用途对比,存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose focuses on fetching and analyzing public Xiaohongshu content and returning structured data. The supplied code does not perform any network access, Xiaohongshu scraping, content parsing, comment retrieval, or structured data extraction. Instead, it writes content to local log files using the filesystem. While logging can be a supporting detail, this code chunk's actual behavior is solely filesystem output, which is not represented in the description and is unrelated as the primary behavior of this snippet. Therefore this chunk does not accurately match the declared description.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill requires access to the sensitive environment variable GUAIKEI_API_TOKEN but does not declare an explicit tool/permission scope limiting that access. In an agent setting, missing scope boundaries can cause overbroad exposure of secrets or make it harder to enforce least privilege for execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill only mentions near the end that data is relayed through a third-party API, rather than warning users up front before they provide keywords, links, or potentially sensitive research targets. This creates a transparency and consent risk: users may unknowingly send their requests and retrieved content to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not clearly warn users that searched keywords, queried URLs, and collected platform data may be persisted to local files. In this skill’s context, those artifacts can contain competitive research targets, marketing plans, and scraped third-party content, creating privacy, confidentiality, and retention risks if the host is shared or the logs are later exfiltrated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all usage instructions, trigger examples, and operational guidance only in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale policy issue unless the regional/language restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The user-facing strings at L22-L25 are entirely in Chinese and the file provides no alternative language option or opt-in mechanism. This can violate language/locale policy when the skill is used in broader contexts where users have not explicitly chosen Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits user-facing status and error messages exclusively in Chinese, such as validation errors at L07 and L11. The file provides no indication that the skill is region-specific or that users can opt into this locale, which can violate a language/locale policy requiring user choice or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple user-facing error strings in this file are hard-coded in Chinese, such as 请求失败 and path 必须是非空字符串. This imposes a specific language on users without opt-in or any documented justification, which is a natural-language policy violation under the locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code includes user-facing error messages and comments entirely in Chinese, which effectively forces a specific language for users interacting with this validator. The file does not indicate that the skill is region-specific or provide any opt-in or fallback for other locales, matching the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The script reads GUAIKEI_API_TOKEN from the environment and sends the user-provided note URL and limit to remote API methods createCommentTask and getCommentTask. Although network access is core to the tool's purpose, this file does not explicitly warn the user that their input URL is transmitted to an external service or that an environment credential is used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code persists the full command output, including the requested URL and fetched comment data, to a local file via log.taskWrite. While the skill prints status messages, there is no explicit disclosure here that data will be saved to disk, which is a file-write operation with privacy and data-retention implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI persists full fetched note details and comments to a local JSON file by default, which can silently retain potentially sensitive or regulated data on disk beyond the immediate session. In shared environments, CI runners, developer workstations, or systems with broad filesystem access, this creates unnecessary data exposure and retention risk even though the source content is public.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The command description, examples, help text, validation errors, and status messages are all hard-coded in Chinese. This creates a language/locale policy issue because the skill does not offer an opt-in language choice or explain that it is intentionally limited to Chinese-speaking users or a China-specific workflow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI persists the full fetched results to a local JSON file after already returning them on stdout. That expands data handling beyond the declared behavior and can leave behind creator content, metadata, and possibly query URLs/tokens in an unprotected local artifact, increasing exposure through shared machines, backups, or later collection by other processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script transmits the user-supplied keyword to external search APIs, but the help text does not clearly disclose that queries are sent off-host to a third-party service. Users may enter sensitive business research terms, personal data, or investigative topics assuming a local-only operation, causing unintended data disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI persists full search output to a local JSON file containing the user's query and returned content metadata without explicit consent, warning, or a retention control. On shared systems or CI/agent environments, this can unintentionally expose user interests, research topics, or collected third-party data to other local users, later processes, or backup/sync services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The package description and keywords are entirely in Chinese and target a specific platform/locale, with no indication that users can choose another language or that the locale restriction is explicitly justified in this file. This can be a natural-language policy concern when a skill presents itself in only one language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Line L01 presents the document entirely in Chinese, and the file contains no indication that language selection is optional or that the skill is intentionally region-specific. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16