Back to skill

Security audit

guaikei·小红书内容雷达

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it handles API credentials and saved results in ways users should review before installing.

Install only if you are comfortable sending Xiaohongshu queries, supplied links, and a GuaiKei API token to the third-party service. Treat GUAIKEI_API_TOKEN as a secret, rotate it if exposed, and watch the logs directory because results are saved automatically and may contain research history, public comments, and tokenized URLs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credential Exposed in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/api/search.js:64
Finding

Automatic Plaintext Persistence of Tokenized URLs and Retrieved Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (47)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

该代码片段仅实现了通用参数解析与帮助文本生成:读取命令行参数、识别 flag/别名、处理布尔值与位置参数、校验必填项、生成帮助信息。它没有任何与小红书相关的网络请求、数据抓取、公开内容读取、关键词搜索、笔记详情查询、评论获取或博主作品列表获取逻辑。因此,代码实际行为与技能声明的核心用途存在显著不匹配。这不是单纯的底层辅助细节,因为从提供的代码片段来看,其功能完全是通用 CLI 工具,而不是声明中的小红书公开数据技能。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is a Xiaohongshu public-data retrieval skill, but the supplied code does not perform search, fetch note details/comments, or list creator works. Instead, it writes content to local files on the filesystem. While logging can be a supporting detail in a larger system, this chunk exposes a concrete undeclared capability—local file writing—which is materially different from the declared external data-access purpose and uses a resource (filesystem) not mentioned in the description or permissions.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill content is entirely written as if operation and user interaction are expected in Chinese, and examples, labels, and guidance do not provide any opt-in or alternative language behavior. Under the policy, a skill that effectively enforces a specific language without user choice can be a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest limits the skill to public Xiaohongshu data retrieval actions such as keyword search, note details, comments, and author post lists. In contrast, the package description and keywords claim broader behavior like 'data mining', 'trend monitoring', 'competitor monitoring', 'KOL screening', 'user profiling', and helping achieve 'precise marketing' and account growth, which goes beyond the declared retrieval-only scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README markets capabilities such as trend prediction, competitor monitoring, KOL screening, bulk data retrieval, and broad 'valuable data' return that exceed the manifest’s narrower scope of keyword search, note detail, comments, and creator post lists. This kind of scope inflation can mislead users or downstream agents into invoking the skill for higher-risk analytics workflows or assuming unsupported data access, increasing the chance of policy bypass, overcollection expectations, and unsafe delegation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

清单描述将技能范围限定为小红书关键词搜索、笔记详情、笔记评论和博主作品列表等公开数据能力,但该更新日志在 L42 明确写出“评论情绪分析功能”。情绪分析属于额外的数据处理/分析能力,并未出现在清单声明的能力边界中,形成文档层面的能力范围不一致。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The entire skill documentation, including invocation examples and operating guidance, is written exclusively in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-only audience. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code sends the user's API token and the provided note URL to a remote endpoint via postJson, but the function contains no confirmation prompt or user-facing warning beyond developer-oriented parameter comments. For code files, network calls that transmit user or system data should have some visible disclosure unless already clearly warned elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The getCommentTask function performs a network request that includes the API token, note URL, and limit values, but provides no visible user disclosure such as a prompt, warning, or user-facing log. This matches the code-file warning criterion for network calls that transmit user or system data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code sends the provided API token as part of outbound HTTP requests, which is a privacy- and credential-relevant operation. Although the parameters are documented in comments, there is no visible confirmation prompt, user-facing warning, or disclosure message in the code about transmitting the token to the remote API.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code contains hard-coded Chinese user-facing warnings and instructions, including the token status message and contact guidance. Because the file provides no opt-in, language selection, or indication that the skill is intentionally limited to a Chinese-speaking context, it violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

A skill whose stated purpose is fetching public Xiaohongshu content would obviously need network access, parsing, and read-only data handling. A reusable function that accepts an arbitrary filename and arbitrary string content and persists it to disk is a broader capability that is not inherently required for that purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits user-facing status and error messages exclusively in Chinese, such as the validation errors on L07 and L11. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest frames this skill as only performing public Xiaohongshu data retrieval such as keyword search, note details, comments, and creator post listings. This utility creates directories and writes caller-provided content to files under a logs directory, which is a local write capability not reflected in that read-only description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple error messages in this file are hard-coded in Chinese, which imposes a specific language on users without offering a locale choice or documenting that the skill is region- or language-specific. This is a natural-language policy issue because users may receive operational and error guidance in a language they did not select.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains multiple user-facing error strings in Chinese, such as at L08, L13, L17, L21, L26, L54, L59, L64, and L68. Under the policy for natural-language violations, forcing a specific language without user opt-in or documented regional justification is a locale policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code sends the provided note URL and limit to remote comment task APIs and later writes the returned results to a local JSON file. While the CLI prints progress messages, it does not explicitly disclose that user-supplied inputs and retrieved data will be transmitted to an external service and persisted on disk, which is relevant safety information for a code file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI writes the full request metadata and fetched results to a local JSON file automatically, without any user opt-in, warning, redaction, or control over storage location/retention. Even though the skill is limited to public Xiaohongshu data, the saved output can still contain sensitive operational metadata, scraped content, and potentially identifying URLs or comments that persist on disk and may be exposed to other local users, backups, or log collection systems.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16