Back to skill

Security audit

小红书内容洞察

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does the advertised Xiaohongshu data collection, but its handling of tokens, access-bearing URLs, and saved results needs review before installation.

Review this skill before installing if the API token, searched topics, Xiaohongshu links, or collected comments/profile data are sensitive. Use it only where sending those targets to Guaikei and storing local logs is acceptable, and avoid committing or sharing the generated logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credentials and Sensitive Request Parameters Exposed in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/xiaohongshu/detail-cli.js:125
Finding

Plaintext Persistence of Access-Bearing URLs and Complete API Results

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.substring(0, 200); } if (safeFilename === "") { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outputFilename, content); ...[truncated 3265 chars]
Remediation
View remediation
` or `--save`. Do not automatically save every successful response. 3. **Use restrictive permissions** Create the log directory and files with owner-only permissions: ```js await fs.promises.mkdir(logDirectory, { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, content, { mode: 0o600, }); ``` 4. **Implement retention controls** Support configurable expiration and automatic deletion of old result files. Document the default retention period. 5. **Prevent accidental repository inclusion** Add `logs/` to `.gitignore` and include a warning in documentation against uploading result files to public repositories or support systems. 6. **Minimize stored data** Store stable note or profile identifiers instead of complete URLs. Allow users to choose whether comments, profile details, and other bulk results are retained. 7. **Update privacy documentation** Explicitly state that returned public content may contain user-related fields and that URL access parameters must be protected. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (78)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation exposes and normalizes capabilities well beyond the skill's declared scope of 'latest-sorted keyword trend insights', including note detail scraping, comment extraction, and creator post monitoring. This scope expansion can cause an orchestrating agent to invoke undisclosed data-collection behaviors, undermining least-privilege expectations and increasing privacy/compliance risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file implements comment-collection tasks for a Xiaohongshu note URL, which materially expands the skill beyond its declared purpose of recent keyword-based trend monitoring. Scope expansion is dangerous because it enables collection of user-generated comment data that may contain personal data, increases compliance/privacy risk, and gives the skill surveillance capability not disclosed by its metadata.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:15