T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:87- Finding
API Credential Transmitted in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed Xiaohongshu public-data lookup tool, with manageable privacy cautions around its third-party API calls and saved result logs.
Install only if you are comfortable sending Xiaohongshu keywords, links, returned public content, and your GUAIKEI_API_TOKEN to guaikei.com. Treat the generated logs/ files as sensitive research records, delete them when no longer needed, and avoid committing or sharing them. Consider rotating the API token if logs, request traces, or proxy/server diagnostics may have exposed it.
src/utils/request.js:87API Credential Transmitted in URL Query Strings
src/utils/log.js:24Complete API Results Persisted Locally Without Explicit Opt-In or Retention Controls
A skill described as a Xiaohongshu data retrieval tool but actually focused on package metadata lookup or other local operations represents a description-behavior mismatch. This is dangerous because security review and user consent depend on truthful declarations; undeclared functionality can hide data handling, persistence, or other side effects outside the expected scope.
A skill described as a Xiaohongshu data retrieval tool but actually focused on package metadata lookup or other local operations represents a description-behavior mismatch. This is dangerous because security review and user consent depend on truthful declarations; undeclared functionality can hide data handling, persistence, or other side effects outside the expected scope.
A skill described as a Xiaohongshu data retrieval tool but actually focused on package metadata lookup or other local operations represents a description-behavior mismatch. This is dangerous because security review and user consent depend on truthful declarations; undeclared functionality can hide data handling, persistence, or other side effects outside the expected scope.
A skill described as a Xiaohongshu data retrieval tool but actually focused on package metadata lookup or other local operations represents a description-behavior mismatch. This is dangerous because security review and user consent depend on truthful declarations; undeclared functionality can hide data handling, persistence, or other side effects outside the expected scope.
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Without declared permissions the skill's intent is opaque and cannot be validated.
The manifest description is entirely in Chinese and frames the skill's invocation guidance and use cases only in that language. There is no indication that users may choose another language or that the Chinese-only constraint is a documented regional requirement, which creates a natural-language locale policy concern.
The package description and keywords are entirely in Chinese and target a single locale/platform context without any indication that alternative language support is available. Under the policy, forcing a specific language or locale without user choice is a natural-language policy concern.
The README states that all task results are automatically saved under logs/, but it does not clearly warn users that queried keywords, analyzed links, and returned content may be persisted locally. In a data-mining skill used for competitor research and monitoring, these logs can expose sensitive business interests, investigation targets, or collected third-party content to other local users, backups, or downstream tooling.
This markdown file documents capabilities that retrieve public note details, comment content, and competitor/KOL account output for analysis, which can affect privacy expectations and data handling. The document includes usage guidance and execution checks, but it does not warn users that these operations collect third-party content/comments or that they should ensure lawful and appropriate use before running them.
This code sends a token and user-supplied URL to a remote API via postJson, which is a data-transmitting network operation covered by the warning requirement for code files. Although the parameters are documented for developers, there is no user-facing confirmation, warning, or disclosure here indicating that credentials and note URLs will be sent to an external service.
The getDetailTask function performs an HTTP request that includes the API token and note URL, which may expose user or system data to a remote endpoint. The file contains developer-oriented comments and retry error logging, but no user-facing notice or warning that this data is transmitted externally.
Detected: suspicious.exposed_secret_literal