Back to skill

Security audit

guaikei-xhs-insight

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform the advertised public Xiaohongshu data lookups, but its handling of API tokens and saved results needs user review before installation.

Install only if you are comfortable sending Xiaohongshu links, keywords, and your Guaikei API token to guaikei.com. Treat generated logs as sensitive, delete them when no longer needed, avoid shared or CI workspaces, and do not print the token value in terminals or logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:87
Finding

API Credential Transmitted in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:33
Finding

Automatic Plaintext Persistence of Complete Results and Access-Bearing URLs

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.substring(0, 200); } if (safeFilename === "") { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outputFilename, content); utils.printSuccess(` → 已保存到 ${outputFilename}`); } catch (error) { utils.printError(`日志写入失败: ${error.message}`); } } ``` Each successful CLI execution passes its complete result object to this function. For example: ```js console.log(JSON.stringify(finalOutput, null, 2)); utils.printSuccess(`详情任务完成, 已返回结果`); await log.taskWrite( `${startTime}_${validator.url2Name(url)}_detail.json`, JSON.stringify(finalOutput, null, 2), ); ``` The result transformation can add URLs containing Xiaohongshu `xsec_token` values: ```js if (res.data.id && res.data.xsec_token) { res.data.url = "https://www.xiaohongshu.com/explore/" + res.data.id + ...[truncated 2466 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (48)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a broader multi-purpose Xiaohongshu data collection skill, including keyword note search, note detail viewing, comment retrieval, and creator works scraping. The supplied code only supports one subset: creating and querying a task to retrieve a blogger's published notes from a creator URL. There is no evidence in this chunk of keyword search, note detail access, or comment fetching. While the implemented behavior is within the general declared domain of public Xiaohongshu data retrieval and does not introduce dangerous undeclared actions like login or publishing, the description does not accurately represent what this specific code chunk actually does, because it materially overstates the implemented capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向小红书公开内容采集与结构化返回的业务技能,但提供的代码片段仅是 src/utils/args.js,一个通用 CLI 参数解析器。它处理命令行参数、帮助信息和错误校验,属于支持性基础设施;然而当前被审查的代码本身完全没有实现声明中的核心能力。由于实际代码的主要行为与声明用途 materially different,且缺失声明中的关键功能,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes network-style Xiaohongshu public data collection features such as search, note detail retrieval, comments retrieval, and creator post listing. The supplied code does none of those things. Instead, it writes arbitrary string content to a local file in a logs directory using Node.js filesystem APIs. While logging can be a supporting detail in a larger skill, this chunk itself exposes a concrete undeclared capability: local filesystem write access. That behavior is not represented in the description or permissions, and the primary behavior of this code chunk is unrelated to the declared Xiaohongshu scraping functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description describes a network/data-extraction skill focused on Xiaohongshu public content. The supplied code chunk does not implement any of those behaviors. Instead, it uses Node.js fs/path modules to locate package.json, read it from disk, parse it, and return the package name. That is a materially different purpose and resource access pattern from the declared scraping/search/detail/comment retrieval functionality. While this may be a small utility file, based on the supplied chunk alone, the actual behavior shown is unrelated to the declared purpose, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that all task results are automatically saved under logs/ using time plus keyword/link naming, but it does not clearly warn users that scraped URLs, search keywords, note details, and comment data may be persisted locally. For a scraping/data-collection skill, this increases the risk of unintended retention and secondary exposure of potentially sensitive business intelligence or user-generated content through local files, backups, or shared workstations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document provides detailed workflows for collecting public note details, comments, and creator post lists, but it omits any guidance on lawful basis, platform terms, minimization, retention, or handling of personal data in comments and profile content. Even when data is publicly accessible, aggregating and structuring it for competitive intelligence or KOL monitoring can increase privacy risk and facilitate profiling at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code sends a user-supplied note URL and an API token to a remote API via postJson, which is a network operation involving potentially sensitive data. While the function names and comments describe the API call technically, there is no confirmation prompt or user-facing disclosure here warning that input data and credentials are transmitted off-process.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The getJson call transmits the token, URL, and limit to a remote API endpoint. This is a safety-relevant network operation involving credentials and user data, but the code provides no visible prompt or notice to the user that these values are being sent externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function sends the provided token in network requests via postJson, which is a sensitive credential transmission. While the docstring names the parameter as an API token, there is no explicit warning, confirmation, or user-facing disclosure about transmitting credentials to the remote API in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This function performs a network call with token, url, and limit parameters, transmitting sensitive credential material and user-supplied resource data. The code includes retry error logging, but no user-facing disclosure or warning that these values are sent to a remote service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JavaScript file contains user-facing strings entirely in Chinese, including warnings and instructions, with no indication that the skill supports other languages or that Chinese-only output is a justified regional constraint. That creates a natural-language policy concern under the locale/language rule because the skill imposes a language choice on users without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest frames the skill as a read-oriented public data acquisition tool that searches notes, fetches note details/comments, and returns structured data. This module adds persistent local file-writing behavior for arbitrary content under a logs directory, which is not part of the described retrieval-and-return scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple user-visible error messages are hard-coded in Chinese, including credential and network failure text, with no indication that the skill supports locale choice or is intentionally limited to a Chinese-speaking region. This creates a natural-language locale policy issue because the skill implicitly forces one language on all users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.