Back to skill

Security audit

guaikei·小红书博主作品

Security checks for vulnerabilities and agentic risk

Overview

The skill largely does what it advertises, but it handles an API token insecurely and automatically saves fetched results locally without enough control or retention guidance.

Install only if you are comfortable sending Xiaohongshu keywords or URLs and your Guaikei API token to www.guaikei.com. Treat the token like a password, rotate it if exposed, and review or delete the generated logs/ files because they can retain research history, fetched content, and access-bearing Xiaohongshu URLs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:86
Finding

API Token Transmitted in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:24
Finding

Automatic Plaintext Retention of Results and Access-Bearing URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (65)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The advertised mode is pasted-link routing, but the implementation reportedly performs keyword-based search with filters, third-party task creation, and local logging. This is a material behavioral divergence that affects privacy, external data transmission, and user expectations about what inputs are processed and retained.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements a keyword-based search CLI, while the declared skill scope is limited to routing and analyzing Xiaohongshu links. That scope expansion matters because it introduces unrelated data collection and network behavior users would not reasonably expect from a link-analysis skill, increasing the chance of covert capability abuse and unauthorized processing.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill requires access to a sensitive environment variable (GUAIKEI_API_TOKEN) but does not declare any explicit tool scope or permission boundary. This makes the capability implicit and increases the risk of over-broad execution or accidental secret exposure in hosts that rely on manifest-declared permissions for containment.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16