Back to skill

Security audit

guaikei·小红书盯博主做监控

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Xiaohongshu public-data collection tool that uses a third-party API and saves results locally, with no evidence of hidden account access, platform posting, destructive behavior, or unrelated data access.

Install only if you are comfortable sending Xiaohongshu keywords, note links, profile links, and a GUAIKEI API token to guaikei.com. Use it for public data only, confirm ambiguous social-media requests before running it, and periodically clear the local logs directory if saved query results should not persist on the machine.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The top-level description says the skill performs keyword-based Xiaohongshu search, but the documented behavior also includes note-detail retrieval, comment extraction, creator monitoring, and writing task results to a local logs directory. This mismatch can mislead users and orchestrators about what data will be collected, transmitted, and retained, undermining informed consent and increasing privacy/compliance risk.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The manifest frames the skill as keyword-based note search, while the body documents broader collection functions including detail retrieval, comments, and creator post monitoring. This scope expansion matters because users may provide links or subjects assuming a narrower operation, while the skill can perform more invasive data retrieval than advertised.

Description-Behavior Mismatch

Medium
Confidence
86% confidence
Finding
The package metadata advertises capabilities such as competitor monitoring, KOL filtering, precision marketing, and account growth that are materially broader than the skill's declared purpose of read-only keyword search over public Xiaohongshu notes. This kind of scope mismatch is dangerous because it can conceal undeclared data collection or behavioral expectations, reducing reviewer and user ability to accurately assess what the skill may do.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The declared CLI scripts include detail, post, and comment operations, which exceed the manifest's described read-only search behavior and suggest write or deeper retrieval capabilities not disclosed to users or reviewers. Hidden or undeclared action surfaces are risky because they may enable unintended content interaction, account misuse, or expansion from passive monitoring into active platform operations.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The README advertises capabilities such as competitor monitoring, KOL screening, comment analysis, and trend monitoring that are materially broader than the manifest’s stated purpose of keyword-based public note search. This kind of scope drift is dangerous because an agent or user may invoke the skill for higher-risk surveillance or profiling use cases that were not disclosed or reviewed in the declared interface.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The documented CLI commands include note detail retrieval, profile/post monitoring, and comment analysis, which extend beyond the manifest’s narrower keyword-search behavior. Undeclared operational paths are risky because they can expose additional data collection and monitoring functions to agents or operators without corresponding policy checks, consent review, or least-privilege scoping.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The changelog describes capabilities such as comment retrieval that expand beyond the manifest’s declared keyword-search-and-summary scope. This creates a scope mismatch that can mislead reviewers, routing systems, or users about what the skill can actually do, increasing the risk of unintended data access or use of unreviewed functionality.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The changelog records blogger/creator work monitoring, which is materially different from simple keyword search and summary. Undeclared monitoring features can enable broader surveillance-style collection or persistent tracking behavior that stakeholders did not review under the published skill description.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The changelog states support for note-detail retrieval and comment sentiment analysis, which goes beyond the manifest’s stated search-and-summary use case. Such hidden or undocumented analysis features can bypass expected review boundaries and may process additional user-generated content in ways users and integrators did not anticipate.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The documentation advertises four operational capabilities (keyword search, note detail/comments, creator posts, comment-only retrieval) even though the manifest says the skill is for keyword-based public note lookup. This scope drift is dangerous because agents may invoke broader data collection behaviors than users or platform policy expect, increasing the chance of over-collection, privacy issues, and misuse of the skill beyond its declared purpose.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The creator monitoring section materially expands the skill from topic search into tracking a specific account's publication activity. In context, this is more sensitive than generic keyword search because it enables targeted surveillance-style monitoring of identifiable creators without that behavior being disclosed in the skill metadata.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
This module implements creation and retrieval of comment-collection tasks for a specific Xiaohongshu note URL, which exceeds the stated skill purpose of keyword/topic-based discovery of public notes. That scope mismatch is dangerous because it enables collection of additional user-generated data not disclosed in the manifest, undermining user consent, reviewability, and least-privilege expectations for the skill.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The code supports retrieval of comments tied to a specific note, but the skill description only justifies topic/keyword-based content discovery. Even if comments are public, collecting them without clear purpose limitation broadens data access beyond expected behavior and can facilitate unnecessary profiling or monitoring of user interactions.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
This code adds a capability to create note-detail/comment retrieval tasks, which exceeds the declared skill scope of keyword-based discovery on public Xiaohongshu content. Scope expansion matters because it can collect richer per-entity data than users were led to expect, increasing privacy and compliance risk even if the data is publicly accessible.

Description-Behavior Mismatch

Low
Confidence
87% confidence
Finding
The result processing reconstructs direct note and profile URLs for specific entities, moving beyond aggregate keyword-search results into targeted entity access. In this skill context, that makes downstream tracking or profiling easier and conflicts with the stated limited-purpose behavior.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The file implements functionality to create and query tasks for fetching a creator's published posts by profile URL, which exceeds the declared skill scope of keyword-based discovery of public Xiaohongshu notes. This scope expansion matters because it enables targeted collection on specific individuals/accounts rather than topic-level search, increasing privacy and surveillance risk and violating least-privilege expectations for the skill.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The file implements a full comment-retrieval workflow even though the skill metadata describes a search-oriented capability for public note discovery and performance observation, not comment collection. This mismatch expands the skill’s data-access scope without clear user expectation or documented justification, increasing the risk of unauthorized scraping, privacy overreach, and policy noncompliance.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The code creates and retrieves comment tasks for a user-supplied note URL, which goes beyond the stated purpose of analyzing public note content by keyword. In this context, the hidden expansion to comment scraping is risky because comments may contain personal data or sensitive user-generated content that the skill description does not prepare users or reviewers to expect.

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The file does more than a simple keyword/topic discovery flow: it creates a remote detail task and retrieves full note detail data including comments. That exceeds the declared skill purpose of public content discovery and increases data collection scope, which is risky because users and integrators may not expect secondary scraping/enrichment behavior from this skill.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The CLI exposes a comment-count parameter and is designed to collect up to 10,000 comments, which is broader than the stated use case of understanding topic performance on social media. This creates unnecessary collection of user-generated content and metadata, expanding privacy, compliance, and misuse risk beyond what the skill description suggests.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The CLI schema requires a blogger profile URL and a post limit, which directly conflicts with the manifest’s stated purpose of keyword-based discovery of public Xiaohongshu notes. This is dangerous because it can cause the agent to collect profile-specific data when the user expects topical search, creating a capability mismatch that may expose or process different data than intended and undermine trust and policy enforcement.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The output messages, request metadata, and result handling all describe homepage/blogger post collection rather than keyword-based social-topic analysis. In the context of an agent skill, this semantic mismatch is risky because routing and user consent may rely on the manifest description; the skill can therefore be invoked under false assumptions and perform broader or different collection than authorized.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The CLI persists the full search output, including the user's keyword and returned content metadata, to a local JSON file without clear necessity or disclosure in the stated skill purpose. This creates a secondary data store that can expose user activity and collected social-media data to other local users, backup systems, or log collectors if the host is shared or compromised.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The activation guidance says the skill should be used even when the user did not explicitly ask for Xiaohongshu search, as long as the intent is to understand a term's social-media performance. Over-broad triggering can cause unintended third-party API calls, collection of extra user-supplied data, and surprising platform-specific monitoring behavior without sufficiently specific user consent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation notes that data is handled through a third-party API, but it does not clearly warn users up front that their provided keywords and links will be sent off-platform. This creates a transparency and privacy issue: sensitive research topics, creator profile URLs, or note links may be disclosed to an external service without explicit informed consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16