Back to skill

Security audit

guaikei-xhs-kol-check

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated Xiaohongshu research purpose, but it should be reviewed because it sends a private API token and target data to a third-party service and automatically saves full results locally.

Install only if you trust Guaikei with your Xiaohongshu keywords, profile/note URLs, and API token. Avoid using sensitive business targets unless that transfer is acceptable, protect or delete the logs/ directory after runs, and rotate the API token if logs or request traces may have been shared.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:79
Finding

API Credential Exposed in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:25
Finding

Automatic Persistence of Access-Bearing URLs and Retrieved Data with Default File Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (48)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill gates functionality behind a private API token and includes marketing/contact instructions for obtaining that token, but this data-sharing and access-control model is not made prominent in the main purpose statement. That can mislead users into sending content URLs/data to a third-party service without clearly understanding the dependency on an external provider and the associated trust boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill gates functionality behind a private API token and includes marketing/contact instructions for obtaining that token, but this data-sharing and access-control model is not made prominent in the main purpose statement. That can mislead users into sending content URLs/data to a third-party service without clearly understanding the dependency on an external provider and the associated trust boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill gates functionality behind a private API token and includes marketing/contact instructions for obtaining that token, but this data-sharing and access-control model is not made prominent in the main purpose statement. That can mislead users into sending content URLs/data to a third-party service without clearly understanding the dependency on an external provider and the associated trust boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill gates functionality behind a private API token and includes marketing/contact instructions for obtaining that token, but this data-sharing and access-control model is not made prominent in the main purpose statement. That can mislead users into sending content URLs/data to a third-party service without clearly understanding the dependency on an external provider and the associated trust boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill gates functionality behind a private API token and includes marketing/contact instructions for obtaining that token, but this data-sharing and access-control model is not made prominent in the main purpose statement. That can mislead users into sending content URLs/data to a third-party service without clearly understanding the dependency on an external provider and the associated trust boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill gates functionality behind a private API token and includes marketing/contact instructions for obtaining that token, but this data-sharing and access-control model is not made prominent in the main purpose statement. That can mislead users into sending content URLs/data to a third-party service without clearly understanding the dependency on an external provider and the associated trust boundary.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill requires a sensitive environment variable (GUAIKEI_API_TOKEN) but does not declare an explicit tool/permission scope limiting how secrets may be accessed or used. In agent environments, missing scope declarations weaken least-privilege guarantees and can allow broader-than-necessary secret exposure during execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The main execution flow instructs users to send Xiaohongshu URLs and related query data to a third-party API, while the privacy/compliance warning appears later and not upfront at the point of use. This creates a transparency and consent problem: users may disclose content identifiers, research targets, or competitor-monitoring data to an external service without timely notice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not clearly warn users that scraped note details, comments, keywords, and profile URLs may be retained on disk. In a data-scraping skill focused on social content analysis, this increases the chance of unintentionally storing sensitive or regulated data longer than necessary, which can lead to privacy, compliance, or local data exposure issues if logs are shared or left unprotected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill repeatedly instructs users to submit keywords, note URLs, profile URLs, and retrieve note/comment content via external scripts, but it never clearly warns that these inputs and fetched content will be transmitted to an external service. This creates a data-transparency and consent problem: users may provide URLs, research targets, or content they do not expect to leave the local agent context, especially when doing competitor monitoring or comment analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The function sends the provided API token as part of an HTTP request, which is a safety-relevant transmission of credential material. Although the code has technical docstrings and retry logging, there is no user-facing warning, confirmation, or disclosure that a credential will be sent to a remote API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The code posts the user-provided note URL to an external endpoint, which transmits user-provided data over the network. The inline comments describe parameters but do not provide a user warning that the URL content will be sent to a third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This function performs a GET request containing the API token and user-supplied URL parameters, which is a network transmission of both credentials and target data. The file lacks any user-facing disclosure or warning that these values are being sent to a remote service to retrieve task results.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code sends the provided API token in outbound HTTP requests via both the task-creation and task-query endpoints. Although the comments document the parameter technically, there is no visible user-facing warning, confirmation, or disclosure in this file that credentials and search terms will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The user-facing strings are written entirely in Chinese and the file does not indicate any opt-in, fallback, or documented requirement that the skill operates only in Chinese. This can violate language/locale policy where skills must not force a specific language without user choice or explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code includes user-facing status and error messages only in Chinese, such as the filename/content validation errors. That imposes a specific language on users without any visible opt-in, fallback, or documented region-specific justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The success and failure messages shown to users are also hard-coded in Chinese only. Because the file provides no indication that the skill is limited to a Chinese-speaking audience or that users can choose their locale, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file returns error strings in Chinese, and there is no indication that the user can choose another language or that the skill is intentionally region-restricted. Hard-coding a single language in user-facing messages can violate language/locale policy expectations when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The 401/403 error shown to users is only in Chinese and offers no language choice. Because this is a user-visible failure path, the code enforces a locale choice without opt-in or documented regional scope.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16