Back to skill

Security audit

小红书笔记洞察

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Xiaohongshu public-data research tool, with practical privacy cautions around its API token handling and automatic local result logs.

Install only if you are comfortable sending Xiaohongshu keywords, note/profile URLs, and a Guaikei API token to guaikei.com. Treat saved logs as potentially sensitive, review or delete artifact/logs after use, and avoid running it in shared workspaces unless file permissions and token rotation are handled.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:84
Finding

API Credential Exposed in Request URL Query Strings

Content
View full analysis
&keyword= ``` HTTPS encrypts the request while it is in transit, but it does not prevent the request URL from being retained after TLS termination. Query string ...[truncated 1735 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:24
Finding

Automatic Plaintext Retention of Retrieved Content and Access-Bearing URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (73)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose centers on keyword-based discovery of public Xiaohongshu notes, including ranking, time filtering, and comparing keyword popularity. The provided code does something materially different: it creates and queries comment scraping tasks for a specific Xiaohongshu note URL via /api/xiaohongshu/comment/url and /api/xiaohongshu/comment/info. This is not a supporting detail of keyword search; it is a separate capability focused on comment retrieval for an individual note. Therefore the code does not accurately represent the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明的核心能力是“按关键词搜索公开笔记并排序/筛选”,属于搜索与榜单分析场景。实际代码则调用 /api/xiaohongshu/detail/url 和 /api/xiaohongshu/detail/info,明显是针对具体笔记链接的详情及评论任务创建与结果获取,不是关键词检索。代码中也没有任何关键词参数、排序字段、时间筛选逻辑或多笔记列表处理。相反,它还包含了评论抓取和详情URL、用户URL补全等与声明不一致的能力。因此描述与实际行为存在明显且实质性的不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的核心能力是“按关键词搜索小红书公开笔记并做排序、时间筛选、热度调研”。但代码并未出现关键词、排序字段、时间范围等参数或逻辑;相反,它接收的是博主URL和返回数量limit,创建并查询的是‘已发布笔记任务/博主详情’。这说明代码的主要功能是获取某个博主的已发布笔记,而不是做关键词检索与热度分析。属于主要用途和能力上的明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书公开内容搜索与分析的技能,而提供的代码片段仅是基础的命令行参数解析模块(parseArgs/readValueAfterFlag/buildHelp)。它不访问小红书,不发起网络请求,不处理搜索关键词到平台查询,不进行排序或时间过滤,也不生成笔记结果。虽然这类参数解析代码可能是完整技能的辅助组件,但就该代码片段本身而言,其实际行为与声明的核心功能明显不一致,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

根据提供的代码片段,其核心行为只是管理和校验一个API TOKEN,并在无效时输出暂停服务提示及微信联系方式。这与声明的主要用途——搜索小红书公开笔记并返回互动数据——存在明显的目的不一致。虽然TOKEN管理可能是某个更大技能的辅助实现细节,但就该代码片段本身而言,并没有实现或接触任何与小红书内容检索相关的资源、逻辑或输出。因此应判定为描述与实际代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书公开笔记的搜索/分析技能,但提供的代码片段只是一个日志工具函数 taskWrite,用于将内容写入本地 logs 目录。它不包含网络请求、平台搜索、数据抓取、排序筛选或结果返回逻辑。相反,它访问了本地文件系统并执行写入操作,这属于声明中未体现的能力。因此该代码片段与声明用途存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for a social-media search/research capability targeting Xiaohongshu public notes. The supplied code chunk does not implement any of that behavior. Instead, it performs a simple local utility function: reading package.json and returning the package name. This is materially different from the declared primary purpose. While helper utilities can be legitimate supporting code, this snippet alone shows only unrelated filesystem/package-metadata access and none of the described platform-search behavior, so the description is not accurately represented by this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is for a feature-rich Xiaohongshu search/research capability. However, the supplied code chunk contains only generic logging and banner-printing helpers. While utility code can support a larger system, this chunk by itself does not implement or evidence the declared functionality. Therefore, based on description-versus-behavior for the supplied code, there is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个面向小红书内容检索与分析的技能,核心能力应包括关键词搜索、结果排序、时间筛选以及返回笔记互动指标。给出的代码片段却只是 URL 工具函数:将 http 规范化为 https,限制特定域名/路径,判断链接是否为笔记或主页链接,并生成一个基于 URL 的名称。它既没有执行搜索,也没有访问或解析笔记内容,更没有任何排序、筛选或互动数据处理逻辑。虽然代码仍与小红书领域相关,但其实际功能与声明的主要用途明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的核心能力是“按关键词搜索小红书公开笔记,并支持排序、时间筛选,返回笔记列表与互动数据”。但代码文件 comment-cli.js 的实际功能是针对单个小红书笔记链接获取评论:它要求传入 --url/笔记链接 和 --limit/评论数量,校验是否为笔记URL,调用 createCommentTask/getCommentTask 获取评论,并输出评论结果。代码中没有实现关键词搜索、排序筛选、多关键词对比或笔记列表返回等声明中的主要能力。因此这不是轻微实现细节差异,而是主要用途明显不同,属于描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是“小红书关键词搜索”能力,强调关键词检索、排序筛选、返回笔记列表和互动数据。实际代码文件是 detail-cli.js,要求提供 --url/笔记链接,并可指定评论数量 limit。它校验小红书笔记URL后,通过 detail.createDetailTask 和 detail.getDetailTask 获取该笔记的详情/评论结果,输出 command: "detail" 的结构化结果。代码中未体现任何关键词搜索、排序、时间筛选或多笔记列表返回逻辑。因此其主用途与声明存在实质性不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的核心能力是基于关键词搜索小红书公开笔记,并支持排序与时间筛选,用于发现热门内容和比较关键词表现。但代码的核心流程是解析 --url/--limit 参数,要求提供小红书博主主页链接,校验是否为 profile URL,随后调用 createPostTask/getPostTask 获取该主页下的笔记列表。代码中没有任何关键词参数、搜索逻辑、排序字段、时间筛选条件或多关键词比较能力。虽然返回的可能也是小红书笔记数据,但其访问对象和主要用途与声明明显不同,因此构成实质性描述-行为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16