Back to skill

Security audit

guaikei·小红书数据助手

Security checks for vulnerabilities and agentic risk

Overview

The skill largely does what it claims, but needs Review because it sends the API token in URL query strings and saves fetched results locally by default.

Install only if you are comfortable sending Xiaohongshu keywords, URLs, and your Guaikei API token to Guaikei. Treat GUAIKEI_API_TOKEN as a secret, rotate it if exposed, and review or delete the logs/ directory because saved outputs may contain comments, business research, and signed Xiaohongshu links.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:86
Finding

Raw API Token Transmitted in URL Query Strings

Content
View full analysis

Vulnerability Details

File Location: src/utils/request.js:86-96, src/utils/request.js:108-117; token parameters originate from src/api/search.js:23-26,52-55, src/api/comment.js:20-23,46-49, src/api/detail.js:20-23,46-49, and src/api/post.js:20-23,46-49
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: Medium

Vulnerable Code

src/api/search.js:23-27:

js
return await postJson(
  "/api/xiaohongshu/note-search/keyword",
  { _: Date.now(), token: token },
  { keyword, type, sort, time, limit },
);

src/api/search.js:52-60:

js
const res = await getJson("/api/xiaohongshu/note-search/info", {
  _: Date.now(),
  token: token,
  keyword,
  type,
  sort,
  time,
  limit,
});

src/utils/request.js:86-96:

js
params.skill_name = skillName();
const fullPath = `${path}?${querystring.stringify(params)}`;
const jsonData = JSON.stringify(data);
const options = {
  host: constants.BASE_URL,
  path: fullPath,
  method: "POST",
  headers: {
    "Content-Type": "application/json",
    "Content-Length": Buffer.byteLength(jsonData),
  },
};

src/utils/request.js:108-117:

js
params._ = Date.now();

const fullPath = `${path}?${querystring.stringify(params)}`;
const options = {
  host: constants.BASE_URL,
  path: fullPath,
  method: "GET",
  headers: {
    "Content-Type": "application/json",
  },
};

Technical Analysis

The API modules pass the raw GUAIKEI_API_TOKEN as a member of the params object. The request utility serializes all parameters with querystring.stringify() and appends them directly to the request path. The same pattern is used by all four supported operations.

The token validation function does not derive a temporary credential or otherwise transform the secret; src/utils/key.js returns the supplied token unchanged. Consequently, the original API cred ...[truncated 1512 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the token from all query-parameter objects.

  2. Transmit it in an HTTP authorization header, for example:

    js
    headers: {
      "Authorization": `Bearer ${token}`,
      "Content-Type": "application/json",
    }
    
  3. Refactor postJson() and getJson() to accept the token separately from ordinary request parameters so callers cannot accidentally serialize credentials into URLs.

  4. Ensure server, proxy, and application logs redact authorization headers and any legacy token query parameter.

  5. Rotate tokens that may already have appeared in infrastructure logs.

  6. Add automated tests asserting that generated request paths never contain token, api_key, authorization, or the configured credential value.

  7. Prefer short-lived, narrowly scoped credentials where supported.

T09 · Insecure Skill Coding Practices

Note
Location
src/xiaohongshu/detail-cli.js:155
Finding

Successful Results Automatically Stored in Plaintext Log Files

Content
View full analysis

Vulnerability Details

File Location: src/xiaohongshu/detail-cli.js:155-161; equivalent behavior exists in src/xiaohongshu/comment-cli.js:155-161, src/xiaohongshu/post-cli.js:157-163, and src/xiaohongshu/search-cli.js:203-211; file creation occurs in src/utils/log.js:24-35
Vulnerability Type: Plaintext persistence of retrieved data and signed URLs
Risk Level: Low

Vulnerable Code

src/xiaohongshu/detail-cli.js:155-161:

js
console.log(JSON.stringify(finalOutput, null, 2));
utils.printSuccess(`详情任务完成, 已返回结果`);

await log.taskWrite(
  `${startTime}_${validator.url2Name(url)}_detail.json`,
  JSON.stringify(finalOutput, null, 2),
);

src/utils/log.js:24-35:

js
const outputFilename = path.join(
  path.dirname(__filename),
  "..",
  "..",
  "logs",
  safeFilename,
);

try {
  await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true });
  await fs.promises.writeFile(outputFilename, content);
  utils.printSuccess(`  → 已保存到 ${outputFilename}`);

The stored object contains request details and the complete returned result:

js
const finalOutput = {
  status: "success",
  error_code: "OK",
  message: "详情任务完成",
  timestamp: new Date().toLocaleString(),
  request: {
    command: "detail",
    url: url,
    limit: limit,
  },
  skill_metadata: {
    skill_version: constants.VERSION,
    runtime_version: process.versions.node,
    execution_time: Date.now() - startTime,
  },
  results: detailTask,
};

Technical Analysis

Every successful CLI operation automatically serializes its complete output to a JSON file under the project-level logs/ directory. The stored data can include retrieved posts, comments, creator information, request metadata, and Xiaohongshu URLs containing xsec_token parameters.

This persistence is mentioned in readme.md, so it is not hidden behavior. However, it is mandatory in the ...[truncated 1745 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make result persistence opt-in through an explicit option such as --output or --save.

  2. If automatic persistence must remain, provide a --no-save option and clearly state the destination before execution.

  3. Create the directory and files with restrictive permissions:

    js
    await fs.promises.mkdir(logDirectory, {
      recursive: true,
      mode: 0o700,
    });
    
    await fs.promises.writeFile(outputFilename, content, {
      mode: 0o600,
      flag: "wx",
    });
    
  4. Remove or redact sensitive query parameters such as xsec_token before storing request URLs and returned links.

  5. Store only fields necessary for the user’s requested analysis instead of the complete raw response.

  6. Implement configurable retention and a cleanup command for old result files.

  7. Add logs/ to .gitignore and exclude it from build artifacts, support bundles, and automated backups unless explicitly required.

  8. Warn users that saved results may contain signed links and should not be shared without review.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (45)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes a domain-specific integration for accessing public Xiaohongshu data through an external API. The actual code shown does not interact with Xiaohongshu, any network service, authentication token, or structured content data. It only provides a reusable utility for parsing CLI arguments and generating usage/help text. This is not merely a supporting implementation detail unless clearly embedded within a larger Xiaohongshu skill; evaluated on this chunk alone, its behavior is materially different from the declared skill purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code chunk does not reflect the declared Xiaohongshu data-collection functionality. Its primary behavior is writing content to local files in a logs directory, which is an unrelated capability compared with public data search/monitoring APIs. While logging can be a supporting detail in a larger skill, this chunk by itself exposes filesystem-writing behavior that is not mentioned in the description, and it shows none of the core declared behaviors such as note search, detail fetching, comment retrieval, creator monitoring, or GUAIKEI API access. Therefore the supplied code chunk materially differs from the declared purpose.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares use of a sensitive environment variable (GUAIKEI_API_TOKEN) but does not define any explicit tool/permission scope to constrain access. In agent ecosystems, missing scope boundaries can cause over-broad invocation and secret exposure assumptions, especially when the skill is callable in contexts that do not clearly require this token.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says the skill should be used even when the user did not explicitly mention Xiaohongshu, as long as the context vaguely involves note/content mining. That broad trigger can cause accidental invocation on unrelated requests, leading to unnecessary third-party data transmission, token use, and platform confusion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill discloses only near the end that data is routed through a third-party API, rather than surfacing that warning in the main activation and usage path. Users may provide URLs, keywords, or commercially sensitive research targets without realizing their requests are being sent to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not clearly describe what data is persisted, how long it is retained, or whether scraped content, URLs, comments, and analyst queries may be stored. In a data-collection skill handling third-party platform content, silent persistence can expose sensitive business research, collected datasets, or regulated personal data to other local users, backups, or downstream tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file documents capabilities that retrieve public note details, comment data, and competitor account content for analysis, but it does not include any warning about handling third-party data, respecting platform rules, or potential privacy implications. Under SQP-2 for markdown files, behaviors that could affect user data or privacy should be accompanied by an explicit warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs operators to configure GUAIKEI_API_TOKEN but gives no warning that the token is sensitive, should not be echoed, logged, committed, or included in outputs. In agent and CLI environments, missing credential-handling guidance can lead to accidental secret disclosure through shell history, debug logs, screenshots, or shared transcripts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function sends an API token and note URL to a remote endpoint via postJson, which is a data-transmitting network operation covered by the missing-warning rule for code files. Although the docstring describes parameters and errors, it does not explicitly warn users that their token and target URL will be transmitted to an external API, and there is no confirmation prompt or user-facing disclosure here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code performs an HTTP request that includes the API token and note URL as request parameters, which may expose user or system data to a backend service. The code has retry logging for failures, but it lacks any visible warning, confirmation, or explicit disclosure that these values are being sent off-box.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The function sends an API token and user-provided search keyword to a remote endpoint via postJson, which is a network operation involving potentially sensitive data. Although the JSDoc documents parameters, there is no user-facing warning, confirmation, or explicit disclosure in this file that the token and query are transmitted externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This function performs a GET request containing the API token, keyword, and other search metadata, which transmits user or system data to a remote service. The file includes technical comments but no user-facing warning or disclosure that these values are sent over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JavaScript file contains natural-language comments, error messages, and generated help text entirely in Chinese, including user-facing CLI output. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Multiple user-visible error strings are hard-coded in Chinese, including failure and authentication guidance, with no indication that the skill is region-specific or that users can opt into another language. This can violate language/locale policy when the skill is used in broader contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code constructs and sends HTTPS GET and POST requests using caller-supplied params and data, which may include user or system information. The file contains no confirmation prompt, logging, comment, or docstring disclosing that data is transmitted over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language comments and error messages exclusively in Chinese, such as the validation errors printed to users. Under the policy, forcing a specific language without user opt-in or a documented locale-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The CLI sends the supplied note URL and API token to an external service to create and fetch comment tasks, but this file does not clearly disclose that user input and access credentials are transmitted off-host. In a data-extraction skill this network behavior is expected, yet the lack of explicit transparency can mislead operators about data flow and may expose internal or mistyped URLs and usage metadata to the third-party service.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI persists retrieved comment data to a local JSON file after already printing the results, creating an additional undisclosed data sink. Even though the source data is described as public Xiaohongshu content, comments can still contain personal data or sensitive business intelligence, and silent local storage increases retention, exposure to other local users/processes, and accidental leakage through backups or repository commits.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file writes comment data to local storage without any user-facing warning or consent specific to persistence behavior. Silent storage is risky because users may assume the tool only returns structured output to stdout, while the saved file creates a durable copy that may later be exposed, shared, or harvested from disk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16