T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Credentials and Sensitive Request Data Exposed in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to do what it says, but it should be reviewed because it sends credentials and research URLs to a third-party API in URL query strings and saves fetched results locally by default.
Install only if you are comfortable sending Xiaohongshu queries, note/profile URLs, and your Guaikei API token to the third-party Guaikei service. Treat saved logs as potentially sensitive business or user-generated content, delete them when no longer needed, and prefer rotating or restricting the API token if available.
src/utils/request.js:76API Credentials and Sensitive Request Data Exposed in URL Query Strings
A skill that claims to fetch only structured public Xiaohongshu data but appears to perform no such retrieval, no token handling, and instead accesses local files represents a significant trust-boundary violation. Even if not overtly malicious, this kind of misrepresentation can be exploited to smuggle unrelated behavior into environments where users expect narrowly scoped network retrieval only.
A skill that claims to fetch only structured public Xiaohongshu data but appears to perform no such retrieval, no token handling, and instead accesses local files represents a significant trust-boundary violation. Even if not overtly malicious, this kind of misrepresentation can be exploited to smuggle unrelated behavior into environments where users expect narrowly scoped network retrieval only.
A skill that claims to fetch only structured public Xiaohongshu data but appears to perform no such retrieval, no token handling, and instead accesses local files represents a significant trust-boundary violation. Even if not overtly malicious, this kind of misrepresentation can be exploited to smuggle unrelated behavior into environments where users expect narrowly scoped network retrieval only.
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |
Referenced artifact was not completely inspected
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |
Referenced artifact was not completely inspected
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |
The skill declares access to an environment variable (GUAIKEI_API_TOKEN) but does not define explicit tool scope or permissions boundaries. In practice, this can cause the host agent to over-grant capabilities or make secret handling ambiguous, which increases the risk of unintended secret exposure or misuse when the skill is invoked.
The package metadata description and keywords are entirely in Chinese, which indicates a language-specific presentation without any visible opt-in, fallback, or explanation that the skill is intentionally region-specific. Under the policy for natural-language violations, forcing a specific language without user choice can be a locale-policy issue.
The README states that all task results are automatically saved to a local logs/ directory, but it does not clearly warn users that scraped content, URLs, keywords, and potentially sensitive business research data will persist on disk. In this skill’s context, the outputs may include competitor monitoring data, comment text, and analyst queries, so silent retention increases the risk of unintended disclosure on shared machines, synced folders, backups, or CI/workstation environments.
This file is a markdown document, so SQP-2 applies to omissions in user-facing warnings. Multiple sections instruct the user to fetch Xiaohongshu note details, comments, and creator publication data, but there is no warning about handling third-party content, possible personal data in comments, or the need to comply with platform rules and privacy expectations.
The file instructs users to configure GUAIKEI_API_TOKEN but provides no guidance on protecting the secret from shell history, logs, screenshots, shared terminals, or source control. In practice, API tokens are commonly leaked through these channels, which could allow unauthorized use of the external service, quota exhaustion, or access under the victim's account.
This JavaScript file contains natural-language documentation and messages only in Chinese, including the module description, parameter docs, and retry/error output. Under the policy, forcing a specific language without user opt-in or a documented justified locale scope is a natural-language policy violation.
This code sends an API token and user-supplied search keyword to a remote endpoint via postJson, which is a network operation involving potentially sensitive data. Although the function has technical comments, there is no confirmation prompt, user-facing disclosure, or warning in this file that the token and query will be transmitted externally.
The getJson call transmits the API token plus search criteria over the network, which affects user privacy and can involve sensitive credentials. The file contains no confirmation prompt or explicit user-facing notice that these values are sent to an external service.
The user-facing strings are entirely in Chinese and there is no indication that the skill adapts to the user's preferred language or offers an opt-in choice. This creates a natural-language policy concern because the skill appears to enforce a specific language for warnings and recovery instructions.
This code builds GET and POST requests from caller-supplied params and data and sends them over the network via https.request, but the file contains no confirmation prompt, logging, or explanatory comments/docstrings disclosing that user or system data may be transmitted. For a generic request utility, that network transmission is not explained here, so users and integrators may not realize data leaves the local environment.
The CLI writes the full fetched comment payload to a local JSON file after printing it, creating persistent storage of scraped data that users may not expect from a tool described primarily as returning structured JSON. Even if the source data is public, comments can contain personal information or sensitive contextual data, and local persistence increases exposure through disk retention, backups, shared workstations, or later unauthorized access.
No suspicious patterns detected.