Back to skill

Security audit

guaikei-xhs-growth

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it advertises, but it needs review because it sends credentials and target links to an external API and automatically saves full retrieved results locally.

Install only if you are comfortable sending your GUAIKEI_API_TOKEN, search terms, and Xiaohongshu links to guaikei.com. Treat xsec_token links and generated logs as sensitive, avoid running this in shared or CI workspaces, restrict access to the logs directory, delete retained outputs when no longer needed, and rotate the API token if logs or request URLs may have been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:78
Finding

API Credential Exposed Through URL Query Parameters

Content
View full analysis
{ return await postJson( "/api/xiaohongshu/note-search/keyword", { _: Date.now(), token: token }, { keyword, type, sort, time, limit }, ); }, ``` From `src/api/search.js:49-60`: ```js async function getSearchTask(token, keyword, type, sort, time, limit) { return await withRetry( async () => { const res = await getJson("/api/xiaohongshu/note-search/info", { _: Date.now(), token: token, keyword, type, sort, time, limit, }); ``` From `src/utils/request.js:73-79`: ```js async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new Error("path must be a non-empty string"); } if (!params || typeof params !== "object") { throw new Error("params must be an object"); } if (!data || typeof data !== "object") { throw new Error("data must be an object"); } params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; ``` From `src/utils/request.js:98-104`: ```js async function getJson(path, params) { if (!path || typeof path !== "string") { throw new Error("path must be a non-empty string"); } if (!params || typeof params !== "object") { throw new Error("params must be an object"); } params._ = Date.now(); const fullPath = `${path}?${querystring.stringify(params)}`; ``` The same credential-bearing param ...[truncated 2233 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/log.js:26
Finding

Automatic Plaintext Archival of Retrieved Data and Link Tokens

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (43)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This code chunk does not substantiate the declared purpose. Instead of showing behavior related to searching Xiaohongshu public notes or retrieving note/comment/blogger data, it merely exports generic constants. The only concrete resource referenced is www.guaikei.com, which is inconsistent with the description's focus on Xiaohongshu/xiaohongshu.com/xhslink.com. While configuration files can be supporting details, this specific chunk provides no evidence of the declared functionality and points to an unrelated service/domain, so the description and actual code behavior are materially mismatched.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书公开数据获取与分析的技能,核心能力应包括访问小红书内容、解析笔记/评论/博主数据并返回结构化结果。而提供的代码仅是一个通用参数解析模块,负责读取命令行选项、校验参数、处理帮助文本,没有任何与小红书、网页请求、结构化内容提取或数据分析相关的实现。虽然这类工具代码可能作为更大系统的辅助组件存在,但就当前代码片段本身而言,其行为与声明的主要用途明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose is specifically about collecting structured public Xiaohongshu content data. The supplied code chunk instead performs local log-file writing to a logs directory using fs/path APIs. While logging can be a supporting implementation detail, this chunk by itself exposes an undeclared capability: writing arbitrary content to local storage. It does not demonstrate any of the declared core behaviors such as searching Xiaohongshu, fetching note details/comments, or scraping creator post lists. Therefore the code chunk's actual behavior does not accurately represent the declared skill purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a user-facing Xiaohongshu public-data collection skill. However, the supplied code chunk does not implement any of that behavior. It merely reads package.json from the local filesystem and returns the package name. This is a materially different purpose and resource access pattern from the declared functionality. While this could be a supporting utility within a larger skill, evaluating the supplied chunk alone shows behavior unrelated to the stated Xiaohongshu data operations, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
78% confidence
Finding

The skill declares use of an environment variable (GUAIKEI_API_TOKEN) but does not define any explicit tool scope such as permissions or allowed-tools. That weakens least-privilege controls and makes it harder for a host platform to constrain what the skill may access, especially if the runtime later expands beyond the documented behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description is entirely written in Chinese and frames invocation/examples in Chinese only, with no indication that users may interact in other languages or choose their preferred locale. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not clearly warn that fetched note details, comments, links, and keyword-derived datasets will be written to local files. Because this skill is explicitly used for scraping and analyzing large amounts of third-party public content, silent persistence increases the risk of unintended retention, local exposure, and downstream mishandling of collected data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file title and the entire operational documentation are written exclusively in Chinese, and the natural-language trigger examples are also only provided in Chinese. For a general-purpose skill document, this imposes a specific language/locale without any opt-in, alternative language guidance, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guidance repeatedly shows full Xiaohongshu URLs containing xsec_token values and mentions configuring GUAIKEI_API_TOKEN, but it does not warn users against sharing, logging, or exposing these tokens. In a skill centered on collecting public-content data via URLs and environment variables, this omission increases the chance that sensitive bearer-like tokens are pasted into chats, stored in logs, or committed to repos, enabling unauthorized reuse or account/session abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The function sends a token and note URL to an external API endpoint via postJson, which is a privacy- and credential-relevant operation. Although the code comments describe parameters, there is no confirmation prompt or user-facing disclosure indicating that these values will be transmitted over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The getJson call transmits the API token, URL, and query parameters to a remote API. This is a safety-relevant network operation involving credential and target data, but the file contains no user-visible warning, confirmation, or disclosure beyond developer-oriented comments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The code sends a token to a remote API via postJson, which is a safety-relevant network operation involving credential material. While the function has developer-facing docstrings and retry error logs, there is no user-facing warning or disclosure here that the supplied API token and URL will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This function performs a network call that transmits the API token, target URL, and limit values to an external endpoint. The inline docstring describes parameters for developers, but there is no clear user warning in this file that user-provided data and credentials are being sent off-system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The user-facing strings at L22-L25 are entirely in Chinese and there is no indication that language selection is configurable or limited to a China-specific context. This creates a natural-language locale policy issue because the skill communicates in a fixed language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.