T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:87- Finding
API Credential Exposed in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its Xiaohongshu public-data purpose, but needs Review because it sends an API token in URL parameters and automatically saves fetched URLs/results locally without redaction or opt-out.
Install only if you are comfortable sending Xiaohongshu keywords, note/profile URLs, and your Guaikei API-authenticated requests to www.guaikei.com. Treat GUAIKEI_API_TOKEN as a secret, avoid using sensitive research terms or private links, and regularly delete or protect the generated logs directory because it may contain fetched content and signed URLs.
src/utils/request.js:87API Credential Exposed in URL Query Strings
src/xiaohongshu/detail-cli.js:143Automatic Plaintext Persistence of Signed URLs and Collected Data
声明描述的是面向小红书数据运营分析的技能,核心能力应涉及获取、整理或返回小红书相关结构化数据。而提供的代码片段仅实现了通用 CLI 参数解析逻辑:读取 flag 值、校验重复参数与必填参数、识别布尔参数、处理位置参数并生成帮助文本。该行为既不涉及小红书平台,也不涉及数据抓取、竞品监控、KOL 筛选、评论洞察或任何结构化数据输出。虽然这类参数解析可能是某个更大工具的辅助模块,但就当前代码片段本身而言,其实际功能与声明的技能目的明显不一致,因此应判定为描述与行为不匹配。
声明描述的核心能力是小红书运营数据服务,但提供的代码片段实际只处理API token合法性检查和提示用户联系微信获取专属私有TOKEN。这与声明的主要用途在功能层面明显不一致:代码没有访问小红书数据、没有结构化分析逻辑、没有监控或洞察功能。虽然token管理可能是某个更大技能的辅助实现细节,但就该代码片段本身而言,其实际行为与声明描述的业务能力不匹配,且包含未声明的联系方式/营销提示行为。
声明描述的是面向小红书数据驱动决策的数据服务能力,而实际代码片段只是一个本地日志写入模块,没有体现任何小红书相关的数据获取、结构化处理、竞品监控、KOL筛选或评论洞察功能。虽然日志功能可能是配套实现细节,但就该代码片段本身而言,其行为与声明的核心用途明显不一致,并且涉及未声明的本地文件系统写入能力。根据给定标准,这属于描述与实际行为不匹配。
声明描述的是一个面向小红书运营分析的数据技能,但提供的代码片段只实现了一个工具函数:通过读取本地 package.json 获取包名。该行为既不涉及小红书内容、竞品、KOL、评论等数据,也不体现任何结构化数据获取或分析能力。虽然读取 package.json 可能是内部辅助实现细节,但就当前代码片段可见的实际行为而言,其功能与声明的核心目的明显不一致,因此应判定为描述与行为不匹配。
该代码块的核心功能是根据用户提供的小红书博主主页 URL 拉取该主页的一定数量笔记数据。这可以算作“小红书结构化数据获取”的一个子能力,但与声明描述的多种场景化能力相比,代码所展示的实际能力明显更单一、具体,仅限博主主页笔记数据获取。尤其是爆款挖掘、竞品监控、KOL筛选、评论洞察等关键声明能力,在该代码中均没有直接体现。因此,描述没有准确代表这段代码的实际行为,属于能力范围被显著夸大的不匹配。
代码行为与声明存在明显范围不一致。当前代码只实现了基于关键词的小红书内容搜索,支持按内容类型、排序、发布时间和数量筛选,并输出结果。它没有表现出竞品监控、KOL筛选、评论洞察等声明中的核心能力,也没有显示更完整的‘爆款挖掘’分析逻辑,只是提供基础搜索结果。因此从已给代码片段看,实际能力明显窄于声明的用途范围。此外,代码还会将结果写入本地日志文件,这属于声明中未提及的附加行为。虽然“提供数据”这一高层方向部分吻合,但声明对功能覆盖面的表述明显超出了该代码片段实际实现的内容。
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
node src/xiaohongshu/detail-cli.js --url "<笔记链接>" [--limit N]
Without declared permissions the skill's intent is opaque and cannot be validated.
The activation condition is unusually broad: it says the skill should be used even when the user does not mention operations, as long as the goal is data-driven decision-making for Xiaohongshu. Over-broad routing can cause the agent to invoke the skill in loosely related conversations, unnecessarily sending user inputs or links to a third-party API and increasing privacy and data-minimization risk.
The package description and keywords are entirely in Chinese and describe the skill specifically around the Xiaohongshu platform, with no indication that users can choose another language or locale. This can violate language/locale policy when a skill implicitly requires a specific language without documenting user opt-in or a justified locale restriction.
The README states that all task results are automatically saved to the logs/ directory, but it does not clearly warn users that searched keywords, profile/note URLs, and fetched content may persist locally. In this skill’s context, the data being collected is marketing intelligence and comment/content data from a third-party platform, so silent persistence increases the risk of unintended disclosure, retention of sensitive business research, or mishandling on shared systems.
The document instructs users to configure a persistent API credential (GUAIKEI_API_TOKEN) and to retrieve remote Xiaohongshu data, but it provides no guidance on secret handling, least-privilege use, redaction, or the privacy/security implications of transmitting user-supplied URLs and query terms to an external service. In an agent setting, this omission can lead to accidental token exposure in logs, screenshots, shell history, or model-visible outputs, and users may not realize that content and links are being sent to a third-party API.
This code sends an API token and a note URL in an HTTP POST request, which qualifies as transmitting user or system data over the network. Although the function has technical docstrings, there is no visible confirmation prompt or user-facing disclosure in this file explaining that these values are sent to a remote API.
This function performs an HTTP GET request that includes the API token, URL, and limit as request parameters, transmitting potentially sensitive values to a remote service. The file contains retry/error logging, but no user-facing disclosure or warning that these inputs are being sent externally.
This file’s natural-language content is entirely in Chinese, including the module description and public function documentation, with no indication that the skill is region-specific or that users may choose another language. That can violate a language/locale policy requiring user opt-in or documented justification for a fixed language.
This code sends caller-supplied params and JSON data to a remote host via HTTPS using POST, but there is no confirmation prompt, user-facing log, or inline warning indicating that user or system data may be transmitted externally. Because this is a generic request utility rather than a clearly user-visible deploy/send action, the outbound transmission is not transparently disclosed here.
The GET helper serializes arbitrary params into the request URL and sends them to a remote endpoint, which can expose user or system data through network transmission. The file contains no confirmation, visible notice, or explanatory comment warning about this outbound data transfer.
This code persists the full output, including the requested URL and returned comment data, to disk via log.taskWrite. Although the CLI prints progress messages, there is no explicit disclosure near the write operation that results will be saved locally, which is a user-impacting data-handling behavior.
This code reads the sensitive environment variable GUAIKEI_API_TOKEN and then sends the user-supplied URL and limit to remote detail-task APIs. Although the help text mentions that the token must be configured, it does not clearly warn that the command transmits the note link and request parameters to an external service, so the network/privacy-impacting behavior lacks explicit user disclosure.
The manifest frames the skill as a data provider that '只负责拿数据', which implies returning structured Xiaohongshu data to the caller. This CLI additionally persists the full output to disk via log.taskWrite, creating local side effects beyond simply retrieving and returning data.
This code transmits the user-supplied Xiaohongshu profile URL to remote API functions and later persists the resulting output locally, which can affect privacy and data handling expectations. While the help mentions that the profile should be publicly accessible, it does not clearly warn users that the URL and fetched results will be sent to an external service and written to disk.
Detected: suspicious.exposed_secret_literal