Back to skill

Security audit

guaikei·小红书热门清单

Security checks for vulnerabilities and agentic risk

Overview

This is a real Xiaohongshu data tool, but it needs review because it sends a service token in request URLs and automatically saves full results locally.

Install only if you are comfortable sending Xiaohongshu keywords or links and your Guaikei API token to www.guaikei.com. Treat generated logs as sensitive: they may contain business research, comments, profile data, and tokenized Xiaohongshu links. Rotate the API token if you suspect URL logs may have exposed it, and delete or protect the logs directory after use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credential Transmitted in URL Query Strings

Content
View full analysis
{ return await postJson( "/api/xiaohongshu/note-search/keyword", { _: Date.now(), token: token }, { keyword, type, sort, time, limit }, ); }, ``` The polling request uses the same pattern: ```js async function getSearchTask(token, keyword, type, sort, time, limit) { return await withRetry( async () => { const res = await getJson("/api/xiaohongshu/note-search/info", { _: Date.now(), token: token, keyword, type, sort, time, limit, }); ``` `postJson()` converts all parameters, including the token, into the URL query string: ```js async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new Error("path must be a non-empty string"); } if (!params || typeof params !== "object") { throw new Error("params must be an object"); } if (!data || typeof data !== "object") { throw new Error("data must be an object"); } params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); ``` `getJson()` similarly places the token and all other parameters in the URL: ```js async function getJson(path, params) { if (!path || typeof path !== "string") { ...[truncated 2359 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/xiaohongshu/search-cli.js:183
Finding

Automatic Plaintext Persistence of Complete Results and Tokenized URLs

Content
View full analysis
Remediation
View remediation
` or `--save-results`. 2. Do not write results when the user requested stdout-only operation. 3. Redact sensitive URL query parameters before output or storage: ```js function redactUrl(value) { const parsed = new URL(value); if (parsed.searchParams.has("xsec_token")) { parsed.searchParams.set("xsec_token", "[REDACTED]"); } return parsed.toString(); } ``` 4. Minimize stored data. Save only fields specifically requested by the user rather than the complete request and response object. 5. When storage is explicitly enabled, create files with owner-only permissions: ```js await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, }); ``` 6. Create the output directory with restrictive permissions such as `0o700`, subject to platform support. 7. Add retention controls, including configurable expiration and a cleanup command. 8. Add `logs/` to `.gitignore` and warn users against committing or sharing generated files. 9. Document the exact data stored, location, permissions, retention period, and deletion procedure. 10. Consider encryption at rest if complete results must be retained in shared or multi-user environments. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (47)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

代码行为聚焦于小红书 note-search 接口:通过关键词、类型、排序、时间、数量创建搜索任务,并查询搜索结果。结果处理中仅为笔记和用户拼接详情页/profile URL,属于搜索结果增强,不等于实际拉取笔记详情、评论或博主作品列表。未发现访问其他平台、登录相关操作或明显越权能力,但声明的功能范围明显大于该代码块实际实现,因此存在描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description says the skill is specifically for retrieving Xiaohongshu note, comment, and creator data. However, the supplied code only contains generic configuration values and points to a base URL on www.guaikei.com, which is not identified as Xiaohongshu in the code. There is no evidence in this chunk of note search, detail retrieval, comment lookup, creator lookup, or Xiaohongshu-specific resource access. Because the visible implementation targets an inconsistent resource and does not substantiate the declared primary purpose, this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是面向小红书数据检索/查看的业务技能,但提供的代码片段仅实现了通用参数解析与帮助文本生成。它没有访问小红书、没有处理笔记/评论/博主数据、没有网络请求、也没有与声明触发条件相关的业务逻辑。因此该代码块的实际行为与声明用途存在明显不匹配,且其主要目的与声明的核心功能不同。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是面向小红书内容检索/详情/评论/博主数据查询的技能能力,但代码片段实际仅实现了一个本地日志写入工具,没有任何与小红书、搜索、笔记详情、评论或博主作品抓取相关的逻辑。虽然日志可能是辅助实现,但就该代码片段本身而言,其主要行为是文件系统写入,这属于声明中未体现的能力与资源访问,因此描述与实际行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
node src/xiaohongshu/detail-cli.js --url "<笔记链接>" [--limit N]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill declares access to a sensitive environment variable (GUAIKEI_API_TOKEN) but does not define explicit tool scope or permissions boundaries. That makes secret use implicit and harder to audit, increasing the risk of accidental token exposure or unauthorized external requests if the runtime or surrounding agent invokes the skill too broadly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation text says the skill should be used even when the user did not explicitly request 'data' or 'search' as long as they mention Xiaohongshu and seem to want content understanding. That broad trigger can cause the agent to invoke third-party data retrieval unexpectedly, leading to unintended data transfer and action beyond clear user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill admits that requests are mediated through a third-party API, but the per-command/per-scenario instructions do not consistently require a user-facing warning before sending keywords or Xiaohongshu links externally. This can create an informed-consent and privacy gap, especially when links may contain tokens or identifiers and users may assume only local processing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The example trigger phrases use broad, conversational wording such as '看看' or '怎么样,' which can blur the boundary between normal discussion and explicit permission to fetch external data. In an agent setting, that increases the chance of overbroad invocation and silent transmission of user-provided links or queries to the third-party backend.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a relatively narrow data-access skill: search Xiaohongshu notes, view note details, fetch comments, and list a blogger's works. In contrast, the README frames the skill as a 'professional data analysis tool' offering '竞品监控', '趋势预测', and 'KOL筛选', which are higher-level analytical/monitoring capabilities not reflected in the manifest description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly states that all task results are automatically saved to a local logs directory, which creates a data retention surface beyond transient read-only querying. Because this skill processes URLs, keywords, comments, and blogger-related analysis results, automatic persistence can expose sensitive business intelligence, user-provided links, or collected content to other local users, backups, or downstream tooling without the user's clear consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatically saving task results to logs without warning about sensitive content can leak URLs containing tokens, searched keywords, competitor-monitoring targets, and scraped analysis outputs. In this skill context, users are likely handling marketing intelligence and third-party content, so silent disk persistence increases the chance of unintended disclosure through shared systems, backups, or accidental redistribution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document instructs users to retrieve public note details, comments, and creator post data at scale, but it does not warn about privacy, platform terms, or the need for lawful authorization and appropriate downstream use. In a scraping/data-collection skill, this omission increases the risk of misuse for unauthorized profiling, monitoring, or bulk collection of user-generated content, especially when comments and account activity are involved.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code sends the provided API token as part of an HTTP request when creating a detail task. Although the docstring names the parameter, there is no explicit warning, confirmation, or user-facing disclosure that sensitive credential material will be transmitted to an external API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The function performs a network request that transmits both the API token and the target URL to an external endpoint. The file contains no explicit user warning beyond parameter names, so users may not be adequately informed that potentially sensitive input and credentials are being sent off-system.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a skill for searching Xiaohongshu notes, viewing note details, comments, and creator works, and explicitly frames it as obtaining platform content rather than performing local system operations. This helper creates directories and writes caller-controlled content to disk under a logs folder, which is not an obvious or necessary capability for the user-facing purpose described in the manifest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple user-visible error strings in this file are hard-coded in Chinese, including request failures and token guidance. This imposes a specific language choice with no indication of user preference, opt-in, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI persists fetched note details to a local JSON file after printing success, but it does not clearly disclose that data will be stored on disk. Note details and comments can contain sensitive or personal information, and silent persistence increases the risk of unintended retention, later leakage, or exposure to other local users/processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The calls to createPostTask and getPostTask send user-supplied data to an external API, which is a network operation covered by this rule. While the help mentions the API token requirement, it does not clearly warn that the target URL and associated parameters will be transmitted to a remote service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI writes the full fetched result set to a local JSON file after returning it to stdout, but the skill description only presents the behavior as retrieving Xiaohongshu data. Silent persistence increases data exposure because note, profile, or comment data may remain on disk longer than the user expects and can be accessed by other local users, backup systems, or later processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The program stores fetched results to a JSON file without explicit user warning or consent, creating a privacy and data-retention issue. Even if the data is publicly accessible on Xiaohongshu, silently creating local copies can expose it through shared machines, endpoint monitoring, or backups.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16