T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Credential Exposed in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it claims, but it handles API credentials and saved results in ways users should review before installing.
Install only if you are comfortable sending Xiaohongshu queries, supplied links, and a GuaiKei API token to the third-party service. Treat GUAIKEI_API_TOKEN as a secret, rotate it if exposed, and watch the logs directory because results are saved automatically and may contain research history, public comments, and tokenized URLs.
src/utils/request.js:76API Credential Exposed in URL Query Strings
src/api/search.js:64Automatic Plaintext Persistence of Tokenized URLs and Retrieved Content
该代码片段仅实现了通用参数解析与帮助文本生成:读取命令行参数、识别 flag/别名、处理布尔值与位置参数、校验必填项、生成帮助信息。它没有任何与小红书相关的网络请求、数据抓取、公开内容读取、关键词搜索、笔记详情查询、评论获取或博主作品列表获取逻辑。因此,代码实际行为与技能声明的核心用途存在显著不匹配。这不是单纯的底层辅助细节,因为从提供的代码片段来看,其功能完全是通用 CLI 工具,而不是声明中的小红书公开数据技能。
The declared purpose is a Xiaohongshu public-data retrieval skill, but the supplied code does not perform search, fetch note details/comments, or list creator works. Instead, it writes content to local files on the filesystem. While logging can be a supporting detail in a larger system, this chunk exposes a concrete undeclared capability—local file writing—which is materially different from the declared external data-access purpose and uses a resource (filesystem) not mentioned in the description or permissions.
Referenced artifact was not completely inspected
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |
Referenced artifact was not completely inspected
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |
Referenced artifact was not completely inspected
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |
Without declared permissions the skill's intent is opaque and cannot be validated.
The skill content is entirely written as if operation and user interaction are expected in Chinese, and examples, labels, and guidance do not provide any opt-in or alternative language behavior. Under the policy, a skill that effectively enforces a specific language without user choice can be a natural-language policy violation unless the locale constraint is explicitly justified.
The manifest limits the skill to public Xiaohongshu data retrieval actions such as keyword search, note details, comments, and author post lists. In contrast, the package description and keywords claim broader behavior like 'data mining', 'trend monitoring', 'competitor monitoring', 'KOL screening', 'user profiling', and helping achieve 'precise marketing' and account growth, which goes beyond the declared retrieval-only scope.
The README markets capabilities such as trend prediction, competitor monitoring, KOL screening, bulk data retrieval, and broad 'valuable data' return that exceed the manifest’s narrower scope of keyword search, note detail, comments, and creator post lists. This kind of scope inflation can mislead users or downstream agents into invoking the skill for higher-risk analytics workflows or assuming unsupported data access, increasing the chance of policy bypass, overcollection expectations, and unsafe delegation.
清单描述将技能范围限定为小红书关键词搜索、笔记详情、笔记评论和博主作品列表等公开数据能力,但该更新日志在 L42 明确写出“评论情绪分析功能”。情绪分析属于额外的数据处理/分析能力,并未出现在清单声明的能力边界中,形成文档层面的能力范围不一致。
The entire skill documentation, including invocation examples and operating guidance, is written exclusively in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-only audience. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.
This code sends the user's API token and the provided note URL to a remote endpoint via postJson, but the function contains no confirmation prompt or user-facing warning beyond developer-oriented parameter comments. For code files, network calls that transmit user or system data should have some visible disclosure unless already clearly warned elsewhere.
The getCommentTask function performs a network request that includes the API token, note URL, and limit values, but provides no visible user disclosure such as a prompt, warning, or user-facing log. This matches the code-file warning criterion for network calls that transmit user or system data.
This code sends the provided API token as part of outbound HTTP requests, which is a privacy- and credential-relevant operation. Although the parameters are documented in comments, there is no visible confirmation prompt, user-facing warning, or disclosure message in the code about transmitting the token to the remote API.
This code contains hard-coded Chinese user-facing warnings and instructions, including the token status message and contact guidance. Because the file provides no opt-in, language selection, or indication that the skill is intentionally limited to a Chinese-speaking context, it violates the language/locale policy criteria.
A skill whose stated purpose is fetching public Xiaohongshu content would obviously need network access, parsing, and read-only data handling. A reusable function that accepts an arbitrary filename and arbitrary string content and persists it to disk is a broader capability that is not inherently required for that purpose.
This code emits user-facing status and error messages exclusively in Chinese, such as the validation errors on L07 and L11. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.
The manifest frames this skill as only performing public Xiaohongshu data retrieval such as keyword search, note details, comments, and creator post listings. This utility creates directories and writes caller-provided content to files under a logs directory, which is a local write capability not reflected in that read-only description.
Multiple error messages in this file are hard-coded in Chinese, which imposes a specific language on users without offering a locale choice or documenting that the skill is region- or language-specific. This is a natural-language policy issue because users may receive operational and error guidance in a language they did not select.
This JavaScript file contains multiple user-facing error strings in Chinese, such as at L08, L13, L17, L21, L26, L54, L59, L64, and L68. Under the policy for natural-language violations, forcing a specific language without user opt-in or documented regional justification is a locale policy issue.
This code sends the provided note URL and limit to remote comment task APIs and later writes the returned results to a local JSON file. While the CLI prints progress messages, it does not explicitly disclose that user-supplied inputs and retrieved data will be transmitted to an external service and persisted on disk, which is relevant safety information for a code file.
The CLI writes the full request metadata and fetched results to a local JSON file automatically, without any user opt-in, warning, redaction, or control over storage location/retention. Even though the skill is limited to public Xiaohongshu data, the saved output can still contain sensitive operational metadata, scraped content, and potentially identifying URLs or comments that persist on disk and may be exposed to other local users, backups, or log collection systems.
Detected: suspicious.exposed_secret_literal