Back to skill

Security audit

guaikei-xhs-explorer

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but it handles API credentials and saves token-bearing URLs and collected data in ways users should review before installing.

Install only if you are comfortable sending Xiaohongshu keywords, target URLs, and your GUAIKEI API token to the Guaikei service. Treat generated logs as sensitive: review or delete the logs directory, avoid running in shared or CI workspaces, and rotate the API token if logs or request URLs may have been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credential Transmitted in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/xiaohongshu/detail-cli.js:136
Finding

Automatic Plaintext Persistence of Tokenized URLs and Complete Result Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (46)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill that claims note search, detail retrieval, comment access, and creator post listing but apparently lacks those functions is a trust-boundary problem. Even if not overtly malicious, this kind of description-behavior mismatch can mislead operators into approving secrets, network access, or deployment of software whose actual capabilities are opaque.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill that claims note search, detail retrieval, comment access, and creator post listing but apparently lacks those functions is a trust-boundary problem. Even if not overtly malicious, this kind of description-behavior mismatch can mislead operators into approving secrets, network access, or deployment of software whose actual capabilities are opaque.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill that claims note search, detail retrieval, comment access, and creator post listing but apparently lacks those functions is a trust-boundary problem. Even if not overtly malicious, this kind of description-behavior mismatch can mislead operators into approving secrets, network access, or deployment of software whose actual capabilities are opaque.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill declares access to an environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool/permission scope such as permissions or allowed-tools. In an agent ecosystem, missing scope declarations can cause over-broad execution assumptions and make secret access less auditable, especially when the skill also instructs runtime command execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description and the entire SKILL.md are written as Chinese-only operating instructions, including trigger examples and execution guidance, with no indication that users may choose another language. Under the stated policy, forcing a specific language or locale without opt-in is a natural-language policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states that all task results are automatically saved to a local logs/ directory, but it does not clearly warn users that searched keywords, fetched URLs, note details, comments, and analysis outputs may persist on disk. For a data-harvesting tool used in marketing and competitive analysis, these logs can expose sensitive research targets, business intent, or collected third-party content to other local users, backups, or downstream systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly encourages collecting public note details, comments, and competitor/KOL account posts for analysis, but does not warn about privacy, profiling, terms-of-service, or downstream misuse risks. Even when data is publicly accessible, aggregating comments and account activity at scale can enable surveillance, profiling, or non-consensual monitoring, making the capability more sensitive in this marketing-intelligence context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends the provided API token in outbound HTTP requests, which is a sensitive credential operation covered by the warning requirement for code files. While the parameter docstring names the token, there is no explicit warning, confirmation, or user-facing disclosure here that the credential will be transmitted to a remote API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The query path performs another outbound HTTP request carrying both the API token and the user-supplied URL. For code files, network transmission of sensitive data should have some visible disclosure, but this file only documents parameters and retries, not that user/system data is being sent externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code sends an API token and a user-provided URL to a remote endpoint via postJson, but the function contains no confirmation prompt or user-facing warning about transmitting potentially sensitive data. The docstring documents parameters and errors, but it does not disclose the privacy or data-transfer behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The getJson call includes the API token and target URL in the request parameters, which transmits user or system data over the network. There is retry logging for failures, but no warning, confirmation, or explicit disclosure that these inputs are sent to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The user-facing strings in this file are entirely in Chinese and there is no indication that the skill offers locale selection or that it is intentionally limited to a Chinese-only audience. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This utility performs outbound HTTPS requests and can send both query parameters and JSON body data to a remote host, but the file contains no confirmation prompt, user-facing log, or explanatory comment/docstring disclosing that behavior. Because network transmission of user or system data is a safety-relevant operation, the absence of any warning in this code is notable.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI persists fetched comment data to a local JSON file after printing results, but gives no explicit warning, consent prompt, or option to disable storage. Because comment content and associated metadata may contain sensitive business intelligence, personal data, or regulated content, silent local retention increases the risk of unintended disclosure on shared machines, CI runners, or logged workspaces.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.