T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:81- Finding
API Credential Transmitted in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to perform the advertised Xiaohongshu research tasks, but it needs review because it sends its API token in URL parameters and automatically saves full results locally.
Install only if you are comfortable sending Xiaohongshu keywords, links, and fetched public data to Guaikei and storing complete outputs in local logs. Use a dedicated, revocable API token and avoid running it in shared, synced, or sensitive workspaces unless you can manage or delete the generated log files.
src/utils/request.js:81API Credential Transmitted in URL Query Strings
src/utils/log.js:25Automatic Persistence of Full API Results Without Opt-In or Retention Controls
声明描述的是一个面向小红书公开内容采集与分析的技能,核心能力应包括访问/抓取小红书内容、解析笔记与评论、处理博主作品等。实际代码仅是独立的通用参数解析模块,负责读取命令行参数、校验 flag、处理默认值和输出帮助信息。这属于底层支持组件,但当前提供的代码片段本身并未实现或直接体现声明中的任何核心业务能力。因此,基于该代码片段与声明用途对比,存在明显不匹配。
The declared purpose focuses on fetching and analyzing public Xiaohongshu content and returning structured data. The supplied code does not perform any network access, Xiaohongshu scraping, content parsing, comment retrieval, or structured data extraction. Instead, it writes content to local log files using the filesystem. While logging can be a supporting detail, this code chunk's actual behavior is solely filesystem output, which is not represented in the description and is unrelated as the primary behavior of this snippet. Therefore this chunk does not accurately match the declared description.
Referenced artifact was not completely inspected
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |
Referenced artifact was not completely inspected
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |
Referenced artifact was not completely inspected
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |
The skill requires access to the sensitive environment variable GUAIKEI_API_TOKEN but does not declare an explicit tool/permission scope limiting that access. In an agent setting, missing scope boundaries can cause overbroad exposure of secrets or make it harder to enforce least privilege for execution.
The skill only mentions near the end that data is relayed through a third-party API, rather than warning users up front before they provide keywords, links, or potentially sensitive research targets. This creates a transparency and consent risk: users may unknowingly send their requests and retrieved content to an external service.
The README states that all task results are automatically saved to the logs/ directory, but it does not clearly warn users that searched keywords, queried URLs, and collected platform data may be persisted to local files. In this skill’s context, those artifacts can contain competitive research targets, marketing plans, and scraped third-party content, creating privacy, confidentiality, and retention risks if the host is shared or the logs are later exfiltrated.
This markdown file presents all usage instructions, trigger examples, and operational guidance only in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale policy issue unless the regional/language restriction is explicitly justified.
The user-facing strings at L22-L25 are entirely in Chinese and the file provides no alternative language option or opt-in mechanism. This can violate language/locale policy when the skill is used in broader contexts where users have not explicitly chosen Chinese.
This code emits user-facing status and error messages exclusively in Chinese, such as validation errors at L07 and L11. The file provides no indication that the skill is region-specific or that users can opt into this locale, which can violate a language/locale policy requiring user choice or documented justification.
Multiple user-facing error strings in this file are hard-coded in Chinese, such as 请求失败 and path 必须是非空字符串. This imposes a specific language on users without opt-in or any documented justification, which is a natural-language policy violation under the locale rule.
This code includes user-facing error messages and comments entirely in Chinese, which effectively forces a specific language for users interacting with this validator. The file does not indicate that the skill is region-specific or provide any opt-in or fallback for other locales, matching the language/locale policy violation criteria.
The script reads GUAIKEI_API_TOKEN from the environment and sends the user-provided note URL and limit to remote API methods createCommentTask and getCommentTask. Although network access is core to the tool's purpose, this file does not explicitly warn the user that their input URL is transmitted to an external service or that an environment credential is used.
This code persists the full command output, including the requested URL and fetched comment data, to a local file via log.taskWrite. While the skill prints status messages, there is no explicit disclosure here that data will be saved to disk, which is a file-write operation with privacy and data-retention implications.
The CLI persists full fetched note details and comments to a local JSON file by default, which can silently retain potentially sensitive or regulated data on disk beyond the immediate session. In shared environments, CI runners, developer workstations, or systems with broad filesystem access, this creates unnecessary data exposure and retention risk even though the source content is public.
The command description, examples, help text, validation errors, and status messages are all hard-coded in Chinese. This creates a language/locale policy issue because the skill does not offer an opt-in language choice or explain that it is intentionally limited to Chinese-speaking users or a China-specific workflow.
The CLI persists the full fetched results to a local JSON file after already returning them on stdout. That expands data handling beyond the declared behavior and can leave behind creator content, metadata, and possibly query URLs/tokens in an unprotected local artifact, increasing exposure through shared machines, backups, or later collection by other processes.
The script transmits the user-supplied keyword to external search APIs, but the help text does not clearly disclose that queries are sent off-host to a third-party service. Users may enter sensitive business research terms, personal data, or investigative topics assuming a local-only operation, causing unintended data disclosure.
The CLI persists full search output to a local JSON file containing the user's query and returned content metadata without explicit consent, warning, or a retention control. On shared systems or CI/agent environments, this can unintentionally expose user interests, research topics, or collected third-party data to other local users, later processes, or backup/sync services.
The package description and keywords are entirely in Chinese and target a specific platform/locale, with no indication that users can choose another language or that the locale restriction is explicitly justified in this file. This can be a natural-language policy concern when a skill presents itself in only one language without opt-in.
Line L01 presents the document entirely in Chinese, and the file contains no indication that language selection is optional or that the skill is intentionally region-specific. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
Detected: suspicious.exposed_secret_literal