Back to skill

Security audit

guaikei·小红书营销数据

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Xiaohongshu public-data research tool that uses a Guaikei API token and saves results locally, with no hidden or destructive behavior found.

Install only if you are comfortable sending Xiaohongshu keywords or links and your GUAIKEI_API_TOKEN to Guaikei's API. Treat saved logs as potentially sensitive business research or comment data, exclude them from commits/backups where appropriate, and use the tool only for lawful, public, platform-compliant data collection.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill requires access to the environment variable `GUAIKEI_API_TOKEN`, but no explicit permission declaration or prominent disclosure is provided to users. This creates a transparency and trust gap: users or host systems may not realize the skill consumes secrets and sends user inputs to a third-party API, increasing the risk of unintended credential use or policy bypass.

Tp4

High
Category
MCP Tool Poisoning
Confidence
82% confidence
Finding
The metadata frames the skill primarily as a blogger-post monitoring tool, but the documented behavior also includes generic keyword search, standalone note detail retrieval, and comment scraping. This broader capability can cause users or policy engines to approve the skill under a narrower use case than it actually supports, enabling over-collection of third-party content beyond expected scope.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill documentation does not give an upfront warning that user-supplied links, keywords, and resulting content are sent to an external API provider. This is dangerous because users may provide sensitive research targets, internal monitoring interests, or proprietary analysis context without informed consent, resulting in unintended third-party data disclosure.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The README states that all task results are automatically saved to the logs/ directory, but it does not warn users that scraped outputs may contain sensitive business intelligence, comment text, profile URLs, or other retained data that could be exposed to other local users, backups, or accidental commits. In the context of a marketing scraping tool, persistent logging increases risk because collected competitor-monitoring data can accumulate silently and be retained longer than intended.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly guides collection and analysis of third-party public note details, comments, and competitor/KOL posting behavior, but it provides no guardrails about privacy expectations, platform terms, retention limits, lawful use, or downstream handling of scraped personal data. Even when content is public, aggregating comments and behavioral patterns at scale can create privacy, compliance, and misuse risks, especially for competitive intelligence and profiling workflows.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The CLI sends user-supplied note URLs and retrieves comment data from a remote API, then writes the returned results to a local JSON file without any explicit user-facing notice about external transmission or disk persistence. In this skill context, the data is intended to be public Xiaohongshu content, which lowers severity somewhat, but persisted output may still expose collected competitor-monitoring data, query targets, API error details, or unexpectedly sensitive metadata on shared systems.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.