Back to skill

Security audit

guaikei-xhs-tool

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do what it says, but it should be reviewed because it sends credentials and research URLs to a third-party API in URL query strings and saves fetched results locally by default.

Install only if you are comfortable sending Xiaohongshu queries, note/profile URLs, and your Guaikei API token to the third-party Guaikei service. Treat saved logs as potentially sensitive business or user-generated content, delete them when no longer needed, and prefer rotating or restricting the API token if available.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credentials and Sensitive Request Data Exposed in URL Query Strings

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (45)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill that claims to fetch only structured public Xiaohongshu data but appears to perform no such retrieval, no token handling, and instead accesses local files represents a significant trust-boundary violation. Even if not overtly malicious, this kind of misrepresentation can be exploited to smuggle unrelated behavior into environments where users expect narrowly scoped network retrieval only.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

A skill that claims to fetch only structured public Xiaohongshu data but appears to perform no such retrieval, no token handling, and instead accesses local files represents a significant trust-boundary violation. Even if not overtly malicious, this kind of misrepresentation can be exploited to smuggle unrelated behavior into environments where users expect narrowly scoped network retrieval only.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A skill that claims to fetch only structured public Xiaohongshu data but appears to perform no such retrieval, no token handling, and instead accesses local files represents a significant trust-boundary violation. Even if not overtly malicious, this kind of misrepresentation can be exploited to smuggle unrelated behavior into environments where users expect narrowly scoped network retrieval only.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares access to an environment variable (GUAIKEI_API_TOKEN) but does not define explicit tool scope or permissions boundaries. In practice, this can cause the host agent to over-grant capabilities or make secret handling ambiguous, which increases the risk of unintended secret exposure or misuse when the skill is invoked.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The package metadata description and keywords are entirely in Chinese, which indicates a language-specific presentation without any visible opt-in, fallback, or explanation that the skill is intentionally region-specific. Under the policy for natural-language violations, forcing a specific language without user choice can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README states that all task results are automatically saved to a local logs/ directory, but it does not clearly warn users that scraped content, URLs, keywords, and potentially sensitive business research data will persist on disk. In this skill’s context, the outputs may include competitor monitoring data, comment text, and analyst queries, so silent retention increases the risk of unintended disclosure on shared machines, synced folders, backups, or CI/workstation environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This file is a markdown document, so SQP-2 applies to omissions in user-facing warnings. Multiple sections instruct the user to fetch Xiaohongshu note details, comments, and creator publication data, but there is no warning about handling third-party content, possible personal data in comments, or the need to comply with platform rules and privacy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file instructs users to configure GUAIKEI_API_TOKEN but provides no guidance on protecting the secret from shell history, logs, screenshots, shared terminals, or source control. In practice, API tokens are commonly leaked through these channels, which could allow unauthorized use of the external service, quota exhaustion, or access under the victim's account.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JavaScript file contains natural-language documentation and messages only in Chinese, including the module description, parameter docs, and retry/error output. Under the policy, forcing a specific language without user opt-in or a documented justified locale scope is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code sends an API token and user-supplied search keyword to a remote endpoint via postJson, which is a network operation involving potentially sensitive data. Although the function has technical comments, there is no confirmation prompt, user-facing disclosure, or warning in this file that the token and query will be transmitted externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The getJson call transmits the API token plus search criteria over the network, which affects user privacy and can involve sensitive credentials. The file contains no confirmation prompt or explicit user-facing notice that these values are sent to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The user-facing strings are entirely in Chinese and there is no indication that the skill adapts to the user's preferred language or offers an opt-in choice. This creates a natural-language policy concern because the skill appears to enforce a specific language for warnings and recovery instructions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code builds GET and POST requests from caller-supplied params and data and sends them over the network via https.request, but the file contains no confirmation prompt, logging, or explanatory comments/docstrings disclosing that user or system data may be transmitted. For a generic request utility, that network transmission is not explained here, so users and integrators may not realize data leaves the local environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The CLI writes the full fetched comment payload to a local JSON file after printing it, creating persistent storage of scraped data that users may not expect from a tool described primarily as returning structured JSON. Even if the source data is public, comments can contain personal information or sensitive contextual data, and local persistence increases exposure through disk retention, backups, shared workstations, or later unauthorized access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.