Back to skill

Security audit

小红书精选

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Xiaohongshu public-data lookup tool, with manageable privacy cautions around its third-party API calls and saved result logs.

Install only if you are comfortable sending Xiaohongshu keywords, links, returned public content, and your GUAIKEI_API_TOKEN to guaikei.com. Treat the generated logs/ files as sensitive research records, delete them when no longer needed, and avoid committing or sharing them. Consider rotating the API token if logs, request traces, or proxy/server diagnostics may have exposed it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:87
Finding

API Credential Transmitted in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:24
Finding

Complete API Results Persisted Locally Without Explicit Opt-In or Retention Controls

Content
View full analysis
Remediation
View remediation
` or `--save` option. 2. Clearly document when data is written, where it is stored, what it contains, and how users can delete it. 3. Create output files with restrictive permissions: ```js await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, flag: "wx", }); ``` 4. Use `flag: "wx"` or another deliberate collision policy to prevent unintended overwrites. 5. Add `logs/` to `.gitignore` and package-exclusion configuration. 6. Provide configurable retention and automatic cleanup controls. 7. Minimize persisted content by omitting unnecessary request metadata and sensitive URL query parameters. 8. Redact Xiaohongshu access-related query parameters, including `xsec_token`, when they are not required in saved output. 9. For environments with stronger confidentiality requirements, encrypt saved results using a user-controlled key or avoid persistence entirely. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (47)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill described as a Xiaohongshu data retrieval tool but actually focused on package metadata lookup or other local operations represents a description-behavior mismatch. This is dangerous because security review and user consent depend on truthful declarations; undeclared functionality can hide data handling, persistence, or other side effects outside the expected scope.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill described as a Xiaohongshu data retrieval tool but actually focused on package metadata lookup or other local operations represents a description-behavior mismatch. This is dangerous because security review and user consent depend on truthful declarations; undeclared functionality can hide data handling, persistence, or other side effects outside the expected scope.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill described as a Xiaohongshu data retrieval tool but actually focused on package metadata lookup or other local operations represents a description-behavior mismatch. This is dangerous because security review and user consent depend on truthful declarations; undeclared functionality can hide data handling, persistence, or other side effects outside the expected scope.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill described as a Xiaohongshu data retrieval tool but actually focused on package metadata lookup or other local operations represents a description-behavior mismatch. This is dangerous because security review and user consent depend on truthful declarations; undeclared functionality can hide data handling, persistence, or other side effects outside the expected scope.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

md
- "只拉这条笔记的评论数据做观点归纳: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description is entirely in Chinese and frames the skill's invocation guidance and use cases only in that language. There is no indication that users may choose another language or that the Chinese-only constraint is a documented regional requirement, which creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The package description and keywords are entirely in Chinese and target a single locale/platform context without any indication that alternative language support is available. Under the policy, forcing a specific language or locale without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that all task results are automatically saved under logs/, but it does not clearly warn users that queried keywords, analyzed links, and returned content may be persisted locally. In a data-mining skill used for competitor research and monitoring, these logs can expose sensitive business interests, investigation targets, or collected third-party content to other local users, backups, or downstream tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file documents capabilities that retrieve public note details, comment content, and competitor/KOL account output for analysis, which can affect privacy expectations and data handling. The document includes usage guidance and execution checks, but it does not warn users that these operations collect third-party content/comments or that they should ensure lawful and appropriate use before running them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code sends a token and user-supplied URL to a remote API via postJson, which is a data-transmitting network operation covered by the warning requirement for code files. Although the parameters are documented for developers, there is no user-facing confirmation, warning, or disclosure here indicating that credentials and note URLs will be sent to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The getDetailTask function performs an HTTP request that includes the API token and note URL, which may expose user or system data to a remote endpoint. The file contains developer-oriented comments and retry error logging, but no user-facing notice or warning that this data is transmitted externally.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16