T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Credentials and Sensitive Request Parameters Exposed in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does the advertised Xiaohongshu data collection, but its handling of tokens, access-bearing URLs, and saved results needs review before installation.
Review this skill before installing if the API token, searched topics, Xiaohongshu links, or collected comments/profile data are sensitive. Use it only where sending those targets to Guaikei and storing local logs is acceptable, and avoid committing or sharing the generated logs.
src/utils/request.js:76API Credentials and Sensitive Request Parameters Exposed in URL Query Strings
src/xiaohongshu/detail-cli.js:125Plaintext Persistence of Access-Bearing URLs and Complete API Results
The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.
The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.
The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.
The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.
The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.
The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.
The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.
The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.
The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.
The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.
The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.
The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.
The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.
The description strongly emphasizes 'latest' and recent-trend monitoring, but the documented parameters allow multiple sort modes and broader time ranges. While not as severe as undisclosed comment/profile retrieval, this still creates a trust mismatch that can cause users or reviewers to misunderstand how the skill prioritizes and scopes data.
Referenced artifact was not completely inspected
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
The documentation exposes and normalizes capabilities well beyond the skill's declared scope of 'latest-sorted keyword trend insights', including note detail scraping, comment extraction, and creator post monitoring. This scope expansion can cause an orchestrating agent to invoke undisclosed data-collection behaviors, undermining least-privilege expectations and increasing privacy/compliance risk.
This file implements comment-collection tasks for a Xiaohongshu note URL, which materially expands the skill beyond its declared purpose of recent keyword-based trend monitoring. Scope expansion is dangerous because it enables collection of user-generated comment data that may contain personal data, increases compliance/privacy risk, and gives the skill surveillance capability not disclosed by its metadata.
Detected: suspicious.exposed_secret_literal