Back to skill

Security audit

guaikei·小红书公开内容情报

Security checks across malware telemetry and agentic risk

Overview

This public Xiaohongshu research skill is mostly purpose-aligned, but it automatically stores full fetched results and URLs locally without opt-out or redaction controls.

Review before installing on shared or managed machines. Use only for public Xiaohongshu research, expect keywords and supplied URLs to be sent to Guaikei, and treat artifact/logs as sensitive because they can retain full results and xsec_token-bearing URLs until manually deleted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The top-level description presents the skill as keyword-based public-note search, but the body expands behavior to note-detail retrieval, comment scraping, and creator post monitoring by URL. This scope mismatch can cause users or orchestrators to invoke the skill under a narrower trust assumption than its real data-collection behavior, increasing the risk of unintended data access and policy bypass.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest advertises only keyword-based search, while the documentation enables additional collection paths for note details, comments, and blogger posts. This discrepancy undermines informed consent and security review because downstream systems may approve or auto-trigger the skill based on an incomplete understanding of what data it can gather.

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The package metadata claims broad analytics, competitor monitoring, KOL screening, and user profiling capabilities, while the stated skill scope is limited to searching public Xiaohongshu notes by keyword. This mismatch can mislead reviewers and users about what the skill does, hide scope creep, and normalize collection or inference behaviors beyond the approved public-content-intel use case.

Description-Behavior Mismatch

Medium
Confidence
81% confidence
Finding
The declared CLI entry points include detail, post, and comment operations in addition to search, suggesting the package may retrieve individual post details or comments beyond simple public search-result retrieval. In this skill context, extra entry points increase the risk of undeclared data access paths and capability expansion that could be used to scrape more content than users and reviewers expect.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The README advertises capabilities well beyond the declared skill scope, including note detail retrieval, account monitoring, comment analysis, and KOL/competitor profiling. Scope drift is dangerous because it can mislead reviewers and users about what the skill actually does, masking higher-risk data collection behaviors and enabling over-privileged or policy-violating use under a narrower manifest description.

Context-Inappropriate Capability

Low
Confidence
88% confidence
Finding
The documentation states that all task results are automatically saved locally in a logs directory, which creates an unnecessary data retention surface for scraped content and user-supplied queries or URLs. Even when handling only public data, persistent local storage increases the chance of inadvertent disclosure, over-collection, and misuse on shared systems or downstream backups.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The changelog states the skill supports creator post monitoring and other capabilities beyond the manifest’s declared scope of keyword-based public note search. Scope drift like this is dangerous because agents or reviewers may rely on incomplete metadata, causing the skill to be invoked for broader collection activities than users or policy systems expect.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The changelog documents note detail access and comment-related retrieval/analysis that are not declared in the manifest. This mismatch can bypass governance based on manifest metadata, leading to unexpected collection or processing of additional public content and interaction data.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The latest changelog explicitly lists multiple operating modes—keyword search, note detail, comment retrieval, and creator works monitoring—while the manifest describes only keyword-based public content search. In an agent setting, this discrepancy increases the risk of overbroad invocation, insufficient consent signaling, and policy evasion through undocumented functionality.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The documentation advertises four capabilities, including note detail/comments and blogger post retrieval, while the manifest describes a narrower keyword-search-only public-content intelligence skill. This scope mismatch can cause an orchestrator or reviewer to grant broader trust and invoke behaviors the user did not expect, increasing the chance of over-collection or unauthorized use of adjacent functionality.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
Documenting blogger profile post retrieval expands the apparent operational scope from keyword-based public content search to tracking a specific creator's output. In a skill intended for public-content keyword research, this broadening raises privacy, policy, and least-privilege concerns because it enables targeted monitoring not clearly disclosed in the manifest.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The CLI persists fetched comment results to a local JSON file without any indication in the skill description that data will be stored on disk. Even though the content is public, local persistence can create unexpected data retention, expose potentially sensitive user research artifacts to other local users/processes, and broaden the privacy footprint beyond transient query execution.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The CLI creates and fetches a detail task for an individual Xiaohongshu note, returning the full note details and associated comment data. This exceeds the skill’s declared purpose of keyword-based public content trend research and introduces a broader data-collection capability than users and reviewers would reasonably expect, increasing privacy and scope-creep risk.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The --limit parameter explicitly controls comment retrieval, making comment collection a first-class feature rather than an incidental byproduct. For a skill described as supporting keyword research, popularity comparison, and trend discovery, collecting comment bodies is a materially broader capability that can capture user-generated content not necessary for the stated use case.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The CLI writes full search results, including user-supplied keywords and returned content data, to a local file without disclosing that persistence behavior in the skill description or at runtime. This creates unnecessary data retention and possible privacy leakage on shared hosts, CI runners, or agent environments where local artifacts may be inspected, synced, or exfiltrated.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger guidance includes broad phrases like '最近什么火' and '帮我找热门内容', which can overlap with ordinary brainstorming or general social-media requests. Overbroad activation criteria can cause accidental invocation, resulting in unnecessary external data transmission and collection when the user did not specifically ask for this integration.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill states late in the document that every execution result is automatically written to a local `logs/` directory, but this persistence behavior is not prominently disclosed up front. Silent or under-disclosed local retention increases the risk that queried URLs, content data, and analysis outputs are stored longer than users expect, creating privacy and data-handling exposure.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The README says results are automatically written to disk but does not clearly warn users that scraped content and user-provided keywords or links may be persisted in local files. This is dangerous because users may unknowingly create sensitive local records of research targets, monitored accounts, or collected content, which can then be exposed through shared devices, backups, or log collection systems.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
Writing fetched comment data to a local file without explicit user warning can surprise users and create avoidable privacy and retention risks. Depending on the environment, the saved JSON may be readable by other users, included in backups, or collected by other tooling, turning a one-time query into durable data exposure.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The help text explicitly encourages passing profile URLs that may contain an xsec_token query parameter, and the program later echoes the full URL into stdout JSON and uses it in downstream processing/logging. This can expose sensitive query data to terminals, shell history, calling systems, CI logs, or persisted task logs, enabling replay or unintended disclosure of access-associated tokens.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
Search output is persisted locally with no explicit warning or consent, so users may assume the tool only returns results to stdout while it actually leaves recoverable artifacts on disk. In an agent or multi-tenant environment, those files can disclose research topics, query history, and collected content metadata beyond the user's expectation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.