T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Credential Exposed in Request URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed Xiaohongshu public-data retrieval skill, with practical privacy and credential-handling cautions but no evidence of hidden or malicious behavior.
Install only if you are comfortable sending Xiaohongshu keywords, note/profile URLs, and retrieved public-data tasks to guaikei.com. Keep GUAIKEI_API_TOKEN private, rotate it if you suspect exposure, and review or delete the local logs directory because results and xsec_token-bearing URLs are saved automatically.
src/utils/request.js:76API Credential Exposed in Request URL Query Strings
src/xiaohongshu/detail-cli.js:143Automatic Persistence of Sensitive URLs and Retrieved Data
The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.
The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.
The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.
The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.
The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.
The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.
The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.
The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.
The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.
The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.
The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.
The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.
The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.
The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.
The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
node src/xiaohongshu/detail-cli.js --url "<笔记链接>" [--limit N]
This module creates and retrieves Xiaohongshu comment-collection tasks, which materially exceeds the declared skill purpose of fetching recent hot notes by keyword. That scope expansion increases data collection sensitivity and can enable scraping of user-generated interactions without a clear functional justification, making the mismatch itself a security and compliance risk.
The manifest says this skill should fetch recent Xiaohongshu notes under a keyword sorted by latest to monitor topic trends. This file instead creates and queries tasks for a blogger URL's published notes, using endpoints and parameters centered on url and published-post retrieval rather than keyword/topic hot-trend collection.
The manifest describes a skill for getting recently published Xiaohongshu notes under a keyword to monitor trends, but this file implements a different operation: it accepts a note URL and retrieves that note's comments. Fetching comments for a specific note is a materially different user intent from keyword-based hot-note discovery and trend monitoring.
The manifest says the skill is for fetching recent Xiaohongshu notes under a keyword, sorted by newest, to monitor topic trends. In this file, the CLI requires a specific note URL, validates it as a note link, creates a detail task, fetches note details, and optionally retrieves up to 10,000 comments, which is a different user intent and behavior than keyword trend monitoring.
The CLI schema requires a profile URL and labels it as a blogger homepage link, which directly conflicts with the skill manifest claiming keyword-based retrieval of recent hot notes. This kind of capability mismatch is dangerous because an agent or user may invoke the skill expecting topic-trend monitoring but instead collect creator-specific profile data, causing unauthorized data scope changes, privacy surprises, and incorrect downstream decisions.
Detected: suspicious.exposed_secret_literal