Back to skill

Security audit

guaikei-xhs-public-data

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does the stated Xiaohongshu public-data lookup work, but it handles its API token in ways that could expose the credential.

Review this before installing if the Guaikei token has paid quota or broad account permissions. Prefer a version that sends the token in an authorization header, avoid running the documented `echo $GUAIKEI_API_TOKEN` troubleshooting step in shared or logged environments, and remember that Xiaohongshu keywords, note/profile URLs, and returned results are sent to and stored through a third-party API workflow.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credential Exposure Through URL Query Parameters

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (52)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书运营分析的数据技能,核心能力应至少表现为抓取、查询、整理或返回小红书相关结构化数据。但给出的代码文件 src/utils/args.js 只是通用参数解析器:读取 flag 值、校验参数、处理 boolean/default/required、支持帮助文本生成。这类代码可以作为任意 CLI 工具的辅助组件,但它本身并不执行任何小红书相关功能,也不体现声明中的业务目标。因此,这不是单纯的“支持实现细节已展示”,而是当前代码片段与声明用途之间存在显著目的不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向小红书数据分析/洞察的数据获取技能,但提供的代码片段并未体现任何与小红书、数据抓取、竞品监控、KOL筛选或评论洞察相关的功能。其实际行为只是将字符串内容写入本地日志文件,属于通用日志/文件输出能力。这与声明的主要用途明显不一致,且代码执行了未声明的本地文件系统写入能力。虽然日志可能是辅助实现细节,但在当前提供的代码片段中,唯一可见功能就是日志写入,因此与技能描述存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明的核心用途是提供小红书相关的数据支持能力,但所给代码片段的实际行为仅是读取本地 package.json 文件并返回包名。这不是对声明能力的支撑性细节,而是完全不同的功能。代码既没有访问小红书数据,也没有进行竞品监控、KOL筛选、评论洞察或任何结构化数据处理,因此描述与行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向小红书运营分析的数据采集/提供技能,核心应涉及内容、账号、评论或竞品等结构化数据的获取与支撑分析。实际代码却只是本地的 URL 工具函数:规范化 URL、判断是否为笔记或主页链接、以及从 URL 生成名称。它既没有访问数据源、也没有抓取/解析小红书内容,更没有实现爆款、竞品、KOL 或评论相关分析能力。因此代码的实际主要用途与声明的技能能力存在明显且实质性的不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

该描述把技能定位为通用的小红书运营数据能力集合,适用于爆款挖掘、竞品监控、KOL筛选、评论洞察等多个场景;而提供的代码块仅完成“根据博主主页链接抓取一定数量的主页笔记”这一较窄的功能。代码没有看到评论数据提取、竞品对比、KOL筛选逻辑、爆款判定逻辑,也没有任何面向这些场景的输入参数或处理流程。因此,代码行为明显比声明狭窄,不能充分支撑描述中的主要能力范围,构成描述与实际行为不一致。命令行、token、日志文件属于实现细节,不是核心问题;核心问题是声明的能力面显著大于代码实际提供的能力。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill declares use of an environment variable (GUAIKEI_API_TOKEN) but does not define any explicit tool/permission scope such as allowed tools or access boundaries. In an agent environment, undeclared secret access increases the risk of over-broad credential exposure and makes it harder for the runtime or reviewer to enforce least privilege.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation guidance is overly broad: it says the skill should be used even when the user does not explicitly mention operations, as long as the goal involves Xiaohongshu data-driven decisions. In an agentic system, broad triggers can cause unnecessary invocation of third-party integrations, leading to unintended data disclosure to external APIs or execution in contexts the user did not clearly consent to.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

All usage guidance, trigger examples, and operating instructions are presented exclusively in Chinese, and the file does not mention that the skill is Chinese-only or offer any user language/locale choice. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The functions accept an API token and include it in outbound request parameters, which constitutes access to and use of credentials. The comments describe the parameter for developers, but there is no user-facing notice in this file explaining that a credential will be used and sent to the service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code sends an API token and note URL to remote endpoints via postJson/getJson, which is a safety-relevant network operation involving potentially sensitive user data. While the functions have developer-facing docstrings and retry error logs, there is no user-facing confirmation, disclosure, or warning in this file that these values will be transmitted externally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JavaScript file contains natural-language comments and runtime-visible retry/error messages in Chinese, but there is no indication that the skill is region-specific or that users can opt into a language/locale. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file emits all user-facing status and warning text exclusively in Chinese, including the token warning and recovery instructions. This imposes a specific language on users without any opt-in or documented locale constraint, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest frames the skill as a data provider for Xiaohongshu analytics and explicitly says it 'only负责拿数据', which implies returning data rather than creating local artifacts. This helper persists caller-provided content into files under a local logs directory, adding a file-writing side effect that is outside the described read-oriented data delivery behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Several thrown error messages are written only in Chinese, including operational guidance to check an environment variable and contact support. This imposes a language choice on users without opt-in or justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.