Back to skill

Security audit

guaikei-xhs-hot-content

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its broader documentation, but it needs review because it under-describes some data-collection capabilities and handles tokens/results in ways users may not expect.

Review before installing if you are uncomfortable sending Xiaohongshu research targets and URLs to the Guaikei API, or with full results being saved locally by default. Use a limited-scope API token, avoid shared workspaces for sensitive research, and clear the logs directory when results should not be retained.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Token Exposed in URL Query Strings

Content
View full analysis
{ return await postJson( "/api/xiaohongshu/detail/url", { _: Date.now(), token: token }, { url: url, limit: limit }, ); }, constants.CREATE_MAX_ATTEMPTS, (attempt, err) => { ...[truncated 2160 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:5
Finding

Automatic Plaintext Retention of Complete API Results and Access-Bearing URLs

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.substring(0, 200); } if (safeFilename === "") { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outputFilename, content); utils.printSuccess(` → 已保存到 ${outputFilename}`); } catch (error) { utils.printError(`日志写入失败: ${error.message}`); } } ``` The detail command stores the complete request and response automatically: ```js const finalOutput = { status: "success", error_code: "OK", message: "详情任务完成", timestamp: new Date().toLocaleString(), request: { command: "detail", url: url, limit: limit, }, skill_metadata: { skill_version: constants.VERSION, runtime_version: process.versions.node, execution_time: Date.now() - startTime, }, results: detailTask, }; console.log(JSON.stringify(finalOutput, null, 2)); utils.printSuccess(`详情任务完成, 已 ...[truncated 2555 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (74)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的核心能力是“按最新排序获取小红书关键词下的近期笔记”,用于观察某话题最近动向;但代码仅包含评论模块,调用的接口分别是 /api/xiaohongshu/comment/url 和 /api/xiaohongshu/comment/info,用笔记链接和评论数量创建并查询评论任务,返回评论结果。这与按关键词检索近期笔记在功能、输入对象、输出结果上都存在实质性差异,因此属于明显的描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个“关键词近期笔记检索/趋势监控”技能,核心能力应是按关键词、最新排序获取某话题近期内容,用于观察热点风向。但代码中仅有 createDetailTask 和 getDetailTask,两者都围绕单个笔记 URL 调用 /api/xiaohongshu/detail/url 与 /api/xiaohongshu/detail/info 接口,且参数为 token、url、limit,没有关键词、排序、时间范围、话题检索等逻辑。代码的主要用途是抓取指定小红书笔记的详情和评论结果,并生成笔记与用户主页链接。因此代码实际行为与声明的主要目的明显不一致,属于实质性能力不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的核心能力是:针对“小红书关键词/话题”按最新排序获取近期笔记,以监控热点风向和近期趋势。实际代码中,接口路径为 /api/xiaohongshu/post/url 和 /api/xiaohongshu/post/info,注释明确写的是“小红书博主详情、已发布笔记模块”,输入参数也是博主URL和返回数量limit。代码执行的是为某个博主创建已发布笔记抓取任务并查询结果,而不是基于关键词检索近期笔记,更没有体现“按最新排序”或“趋势/热点分析”。因此其主要用途与声明存在实质性不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向小红书的趋势监控/近期笔记获取技能,核心行为应包括访问小红书相关资源、按关键词检索、按最新排序、返回近期笔记或趋势信息。但给定代码片段完全是通用 CLI 参数处理模块,不包含任何网络请求、平台访问、搜索、排序、笔记抓取或趋势分析逻辑。虽然这类参数解析可能是某个更大工具的辅助组件,但就该代码片段本身而言,其实际行为与声明用途明显不符,属于材料性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明的用途是获取并分析小红书关键词近期笔记/趋势,属于外部平台内容检索能力;而实际代码仅执行本地日志写入,没有任何与小红书、关键词搜索、排序、笔记抓取或趋势监控相关的逻辑。代码还使用了未声明的本地文件系统访问能力(mkdir、writeFile),这与描述的核心功能和资源访问均不一致。因此属于明显描述-行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书的近期笔记/趋势获取技能,但提供的代码片段只是一个工具函数:通过 fs 和 path 定位并读取本地 package.json,然后返回 pkg.name。它没有任何网络请求、关键词处理、平台数据获取、排序、趋势分析或监控逻辑。相反,它执行的是本地元数据读取这一完全不同的功能。因此该代码片段与声明用途存在明显实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个面向小红书内容检索与趋势观察的技能,但给出的代码片段仅实现了通用重试逻辑(withRetry),没有任何网络请求、平台访问、关键词处理、排序、笔记抓取或趋势分析行为。虽然重试机制可能是实现该技能的辅助组件,但就该代码片段本身而言,其实际行为与声明的主要用途并不一致,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向小红书内容检索与趋势监控的技能,而提供的代码片段没有任何网络请求、平台访问、关键词搜索、排序、数据抓取或趋势分析相关逻辑。它只是一个通用工具文件,用于打印 banner 和分级日志。从该代码片段本身看,其实际行为与声明的主要用途明显不一致。尽管这可能是整个技能中的辅助模块,但基于当前提供的代码块,无法支持所声明的核心能力,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向“小红书关键词近期内容/热点趋势获取”的技能,核心能力应包括关键词检索、按最新排序、获取近期笔记以及趋势监控。实际代码却只是在本地处理 URL:将 http 规范为 https、拒绝非 https 和含空格链接、识别链接是否属于笔记页或用户主页页,并生成基于 URL 的名称。代码中没有任何关键词搜索、数据抓取、排序、趋势分析或近期笔记获取逻辑。相反,它还包含对用户主页链接的识别,这与声明的关键词热点用途并不相符。因此描述与实际行为存在明显且实质性的不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是“按关键词获取近期笔记/热点趋势”的搜索能力,核心对象是关键词与近期笔记列表;而实际代码处理的是单个笔记链接的评论采集。代码要求输入笔记 URL(不是关键词),调用 comment.createCommentTask 和 comment.getCommentTask 获取评论数据,并输出 command: "comment" 的结果。这与声明的主要用途、输入类型、输出内容都明显不一致,因此属于实质性能力不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是“基于关键词获取小红书近期笔记、用于追踪热点趋势”的搜索/趋势类能力;但代码实际实现的是 detail-cli,输入必须是笔记链接而非关键词,核心调用也是 createDetailTask/getDetailTask 来获取单篇笔记详情和评论数量。代码没有体现关键词检索、最新排序、近期笔记列表、趋势分析或热点监控等行为。其主要目的与声明明显不同,因此属于高置信度不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明的技能用途是基于‘关键词’获取小红书近期笔记,以捕捉热点风向和话题趋势;但代码实际接受的唯一必填参数是小红书博主主页链接(--url),并明确校验其为 profile URL。随后调用的是 createPostTask/getPostTask,日志与输出文案也都表明是在获取‘主页笔记’或‘博主笔记’。代码中没有任何关键词搜索、最新排序控制、话题趋势分析或近期话题监控的实现。因此其主要目的与声明明显不符,属于实质性能力和目标对象不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明将该技能定位为“按最新排序获取近期笔记、捕捉热点风向”的专用能力,但代码实际实现的是一个更通用的小红书搜索工具。代码中 --sort 默认值为 0(综合),不是最新(1);--time 默认值为 0(不限),也不是近期过滤。因此其默认和核心行为并不等同于“按最新排序获取近期笔记”。虽然用户可以通过参数设置成最新和近期,但这只是可选模式,不是代码所固定提供的主功能。此外,代码还提供内容类型筛选、多种热度排序,以及日志写文件等未在描述中体现的能力。综合来看,描述缩窄且误导了实际行为,存在明显不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file implements comment-collection APIs for Xiaohongshu notes, which materially exceeds the declared skill purpose of retrieving recent hot notes by keyword and monitoring topical trends. Scope expansion like this increases the chance of collecting unrelated user-generated content and enables data access paths the user would not reasonably expect from the manifest, creating a privacy and capability-mismatch risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.