T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:87- Finding
API Credential Transmitted in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to perform the advertised public Xiaohongshu data lookups, but its handling of API tokens and saved results needs user review before installation.
Install only if you are comfortable sending Xiaohongshu links, keywords, and your Guaikei API token to guaikei.com. Treat generated logs as sensitive, delete them when no longer needed, avoid shared or CI workspaces, and do not print the token value in terminals or logs.
src/utils/request.js:87API Credential Transmitted in URL Query Strings
src/utils/log.js:33Automatic Plaintext Persistence of Complete Results and Access-Bearing URLs
The declared description presents a broader multi-purpose Xiaohongshu data collection skill, including keyword note search, note detail viewing, comment retrieval, and creator works scraping. The supplied code only supports one subset: creating and querying a task to retrieve a blogger's published notes from a creator URL. There is no evidence in this chunk of keyword search, note detail access, or comment fetching. While the implemented behavior is within the general declared domain of public Xiaohongshu data retrieval and does not introduce dangerous undeclared actions like login or publishing, the description does not accurately represent what this specific code chunk actually does, because it materially overstates the implemented capabilities.
声明描述的是一个面向小红书公开内容采集与结构化返回的业务技能,但提供的代码片段仅是 src/utils/args.js,一个通用 CLI 参数解析器。它处理命令行参数、帮助信息和错误校验,属于支持性基础设施;然而当前被审查的代码本身完全没有实现声明中的核心能力。由于实际代码的主要行为与声明用途 materially different,且缺失声明中的关键功能,因此应判定为描述与行为不匹配。
The declared purpose describes network-style Xiaohongshu public data collection features such as search, note detail retrieval, comments retrieval, and creator post listing. The supplied code does none of those things. Instead, it writes arbitrary string content to a local file in a logs directory using Node.js filesystem APIs. While logging can be a supporting detail in a larger skill, this chunk itself exposes a concrete undeclared capability: local filesystem write access. That behavior is not represented in the description or permissions, and the primary behavior of this code chunk is unrelated to the declared Xiaohongshu scraping functionality.
The declared description describes a network/data-extraction skill focused on Xiaohongshu public content. The supplied code chunk does not implement any of those behaviors. Instead, it uses Node.js fs/path modules to locate package.json, read it from disk, parse it, and return the package name. That is a materially different purpose and resource access pattern from the declared scraping/search/detail/comment retrieval functionality. While this may be a small utility file, based on the supplied chunk alone, the actual behavior shown is unrelated to the declared purpose, so this should be flagged as a mismatch.
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |
Referenced artifact was not completely inspected
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |
Referenced artifact was not completely inspected
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |
Without declared permissions the skill's intent is opaque and cannot be validated.
The README states that all task results are automatically saved under logs/ using time plus keyword/link naming, but it does not clearly warn users that scraped URLs, search keywords, note details, and comment data may be persisted locally. For a scraping/data-collection skill, this increases the risk of unintended retention and secondary exposure of potentially sensitive business intelligence or user-generated content through local files, backups, or shared workstations.
The document provides detailed workflows for collecting public note details, comments, and creator post lists, but it omits any guidance on lawful basis, platform terms, minimization, retention, or handling of personal data in comments and profile content. Even when data is publicly accessible, aggregating and structuring it for competitive intelligence or KOL monitoring can increase privacy risk and facilitate profiling at scale.
This code sends a user-supplied note URL and an API token to a remote API via postJson, which is a network operation involving potentially sensitive data. While the function names and comments describe the API call technically, there is no confirmation prompt or user-facing disclosure here warning that input data and credentials are transmitted off-process.
The getJson call transmits the token, URL, and limit to a remote API endpoint. This is a safety-relevant network operation involving credentials and user data, but the code provides no visible prompt or notice to the user that these values are being sent externally.
The function sends the provided token in network requests via postJson, which is a sensitive credential transmission. While the docstring names the parameter as an API token, there is no explicit warning, confirmation, or user-facing disclosure about transmitting credentials to the remote API in this file.
This function performs a network call with token, url, and limit parameters, transmitting sensitive credential material and user-supplied resource data. The code includes retry error logging, but no user-facing disclosure or warning that these values are sent to a remote service.
This JavaScript file contains user-facing strings entirely in Chinese, including warnings and instructions, with no indication that the skill supports other languages or that Chinese-only output is a justified regional constraint. That creates a natural-language policy concern under the locale/language rule because the skill imposes a language choice on users without opt-in.
The manifest frames the skill as a read-oriented public data acquisition tool that searches notes, fetches note details/comments, and returns structured data. This module adds persistent local file-writing behavior for arbitrary content under a logs directory, which is not part of the described retrieval-and-return scope.
Multiple user-visible error messages are hard-coded in Chinese, including credential and network failure text, with no indication that the skill supports locale choice or is intentionally limited to a Chinese-speaking region. This creates a natural-language locale policy issue because the skill implicitly forces one language on all users.
No suspicious patterns detected.