Back to skill

Security audit

guaikei·小红书挑热门的

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Xiaohongshu public-data retrieval skill, with practical privacy and credential-handling cautions but no evidence of hidden or malicious behavior.

Install only if you are comfortable sending Xiaohongshu keywords, note/profile URLs, and retrieved public-data tasks to guaikei.com. Keep GUAIKEI_API_TOKEN private, rotate it if you suspect exposure, and review or delete the local logs directory because results and xsec_token-bearing URLs are saved automatically.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credential Exposed in Request URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/xiaohongshu/detail-cli.js:143
Finding

Automatic Persistence of Sensitive URLs and Retrieved Data

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.substring(0, 200); } if (safeFilename === "") { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outpu ...[truncated 2536 chars]
Remediation
View remediation
` or `--save`. 2. Do not include complete sensitive URLs in saved request metadata. 3. Parse URLs and redact sensitive parameters before printing or writing them: ```js const parsedUrl = new URL(url); for (const key of ["xsec_token", "token", "access_token"]) { if (parsedUrl.searchParams.has(key)) { parsedUrl.searchParams.set(key, "[REDACTED]"); } } ``` 4. Review returned result objects and redact query tokens from generated note and profile URLs before persistence unless they are strictly required. 5. Create files with restrictive permissions: ```js await fs.promises.writeFile(outputFilename, content, { mode: 0o600 }); ``` 6. Document the storage location, stored fields, retention period, and deletion procedure in `SKILL.md`. 7. Add a retention policy or cleanup command and avoid keeping results indefinitely. 8. Add `logs/` to `.gitignore` and relevant backup or workspace-exclusion rules. 9. Provide a `--no-save` mode for backward compatibility if automatic persistence cannot immediately be removed. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (74)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The manifest claims a specialized 'latest-sorted recent notes' skill, but the documented search command supports multiple sort orders and unrestricted time ranges by default. This is primarily a scope-integrity issue: users and routing systems may invoke the skill believing it is tightly limited when it is actually a more general search tool.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
node src/xiaohongshu/detail-cli.js --url "<笔记链接>" [--limit N]

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This module creates and retrieves Xiaohongshu comment-collection tasks, which materially exceeds the declared skill purpose of fetching recent hot notes by keyword. That scope expansion increases data collection sensitivity and can enable scraping of user-generated interactions without a clear functional justification, making the mismatch itself a security and compliance risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says this skill should fetch recent Xiaohongshu notes under a keyword sorted by latest to monitor topic trends. This file instead creates and queries tasks for a blogger URL's published notes, using endpoints and parameters centered on url and published-post retrieval rather than keyword/topic hot-trend collection.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a skill for getting recently published Xiaohongshu notes under a keyword to monitor trends, but this file implements a different operation: it accepts a note URL and retrieves that note's comments. Fetching comments for a specific note is a materially different user intent from keyword-based hot-note discovery and trend monitoring.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says the skill is for fetching recent Xiaohongshu notes under a keyword, sorted by newest, to monitor topic trends. In this file, the CLI requires a specific note URL, validates it as a note link, creates a detail task, fetches note details, and optionally retrieves up to 10,000 comments, which is a different user intent and behavior than keyword trend monitoring.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The CLI schema requires a profile URL and labels it as a blogger homepage link, which directly conflicts with the skill manifest claiming keyword-based retrieval of recent hot notes. This kind of capability mismatch is dangerous because an agent or user may invoke the skill expecting topic-trend monitoring but instead collect creator-specific profile data, causing unauthorized data scope changes, privacy surprises, and incorrect downstream decisions.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16