Back to skill

Security audit

guaikei-xhs-see-details

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Xiaohongshu public-data collection tool, with the main cautions being third-party API use and automatic local result logging.

Before installing, confirm you are comfortable sending Xiaohongshu keywords, note/profile URLs, request options, and your GUAIKEI_API_TOKEN to guaikei.com. Also treat the generated logs as potentially sensitive business research and delete or protect artifact/logs if the workspace is shared or synced.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding
The top-level description narrows the skill to analyzing a blogger's public posts, but the body documents broader capabilities: keyword search, arbitrary note detail/comment retrieval, and local log persistence. This mismatch can mislead users and reviewers about scope, cause unintended data collection or retention, and weakens informed consent around what the skill actually does.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The markdown says the skill depends on a third-party API service, but it does not clearly warn users which inputs are sent off-platform, such as note URLs, profile URLs, keywords, and possibly retrieved content identifiers. Without a precise disclosure, users may unknowingly transmit competitor-research targets or other sensitive business context to an external service.

Missing User Warnings

Low
Confidence
76% confidence
Finding
The CLI writes the full result set to a predictable local JSON file without a clear upfront warning in the interface. Even though the skill is intended for public Xiaohongshu data, the output may still include scraped profile activity, comments, or derived intelligence that users may not expect to persist on disk, increasing the chance of unintended local disclosure on shared systems or in synced workspaces.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The CLI persists search results to a local JSON file without explicit notice, consent, retention controls, or output redaction. Even if the data is public content, local storage can create unnecessary data exposure on shared systems, leak search history and monitored targets, and accumulate potentially sensitive business intelligence about competitors or tracked accounts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16