T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Credential Transmitted in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill does what it claims, but it handles API credentials and saves token-bearing URLs and collected data in ways users should review before installing.
Install only if you are comfortable sending Xiaohongshu keywords, target URLs, and your GUAIKEI API token to the Guaikei service. Treat generated logs as sensitive: review or delete the logs directory, avoid running in shared or CI workspaces, and rotate the API token if logs or request URLs may have been exposed.
src/utils/request.js:76API Credential Transmitted in URL Query Strings
src/xiaohongshu/detail-cli.js:136Automatic Plaintext Persistence of Tokenized URLs and Complete Result Data
A skill that claims note search, detail retrieval, comment access, and creator post listing but apparently lacks those functions is a trust-boundary problem. Even if not overtly malicious, this kind of description-behavior mismatch can mislead operators into approving secrets, network access, or deployment of software whose actual capabilities are opaque.
A skill that claims note search, detail retrieval, comment access, and creator post listing but apparently lacks those functions is a trust-boundary problem. Even if not overtly malicious, this kind of description-behavior mismatch can mislead operators into approving secrets, network access, or deployment of software whose actual capabilities are opaque.
A skill that claims note search, detail retrieval, comment access, and creator post listing but apparently lacks those functions is a trust-boundary problem. Even if not overtly malicious, this kind of description-behavior mismatch can mislead operators into approving secrets, network access, or deployment of software whose actual capabilities are opaque.
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |
Referenced artifact was not completely inspected
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |
Referenced artifact was not completely inspected
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |
The skill declares access to an environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool/permission scope such as permissions or allowed-tools. In an agent ecosystem, missing scope declarations can cause over-broad execution assumptions and make secret access less auditable, especially when the skill also instructs runtime command execution.
The manifest description and the entire SKILL.md are written as Chinese-only operating instructions, including trigger examples and execution guidance, with no indication that users may choose another language. Under the stated policy, forcing a specific language or locale without opt-in is a natural-language policy violation unless the constraint is explicitly justified.
The README states that all task results are automatically saved to a local logs/ directory, but it does not clearly warn users that searched keywords, fetched URLs, note details, comments, and analysis outputs may persist on disk. For a data-harvesting tool used in marketing and competitive analysis, these logs can expose sensitive research targets, business intent, or collected third-party content to other local users, backups, or downstream systems.
The documentation explicitly encourages collecting public note details, comments, and competitor/KOL account posts for analysis, but does not warn about privacy, profiling, terms-of-service, or downstream misuse risks. Even when data is publicly accessible, aggregating comments and account activity at scale can enable surveillance, profiling, or non-consensual monitoring, making the capability more sensitive in this marketing-intelligence context.
This code sends the provided API token in outbound HTTP requests, which is a sensitive credential operation covered by the warning requirement for code files. While the parameter docstring names the token, there is no explicit warning, confirmation, or user-facing disclosure here that the credential will be transmitted to a remote API.
The query path performs another outbound HTTP request carrying both the API token and the user-supplied URL. For code files, network transmission of sensitive data should have some visible disclosure, but this file only documents parameters and retries, not that user/system data is being sent externally.
This code sends an API token and a user-provided URL to a remote endpoint via postJson, but the function contains no confirmation prompt or user-facing warning about transmitting potentially sensitive data. The docstring documents parameters and errors, but it does not disclose the privacy or data-transfer behavior.
The getJson call includes the API token and target URL in the request parameters, which transmits user or system data over the network. There is retry logging for failures, but no warning, confirmation, or explicit disclosure that these inputs are sent to an external service.
The user-facing strings in this file are entirely in Chinese and there is no indication that the skill offers locale selection or that it is intentionally limited to a Chinese-only audience. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation.
This utility performs outbound HTTPS requests and can send both query parameters and JSON body data to a remote host, but the file contains no confirmation prompt, user-facing log, or explanatory comment/docstring disclosing that behavior. Because network transmission of user or system data is a safety-relevant operation, the absence of any warning in this code is notable.
The CLI persists fetched comment data to a local JSON file after printing results, but gives no explicit warning, consent prompt, or option to disable storage. Because comment content and associated metadata may contain sensitive business intelligence, personal data, or regulated content, silent local retention increases the risk of unintended disclosure on shared machines, CI runners, or logged workspaces.
No suspicious patterns detected.