Back to skill

Security audit

小红书趋势洞察

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Xiaohongshu data tool, but its primary description understates its broader search/profile/detail capabilities and it handles tokens and saved results in ways users should review first.

Install only if you want the broader Xiaohongshu trend/search/detail/profile tool, not just comment analysis. Use a scoped Guaikei token, avoid shared or synced workspaces unless you are comfortable with logs being written, clear the logs directory after use, and consider rotating tokens used with this version.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/api/comment.js:17
Finding

API Credential Transmitted in URL Query Strings

Content
View full analysis
{ return await postJson( "/api/xiaohongshu/comment/url", { _: Date.now(), token: token }, { url, limit }, ); }, ``` Polling requests expose the same credential: ```js async function getCommentTask(token, url, limit) { return await withRetry( async () => { const res = await getJson("/api/xiaohongshu/comment/info", { _: Date.now(), token: token, url, limit, }); ``` The shared request implementation serializes those parameters directly into the URL: ```js async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new Error("path must be a non-empty string"); } if (!params || typeof params !== "object") { throw new Error("params must be an object"); } if (!data || typeof data !== "object") { throw new Error("data must be an object"); } params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Content-Length": Buffer.byteLength(jsonData), }, }; return await request(options, jsonData); } ``` ```js async function getJson(path, params) { if (!path || typeof path !== "string") { throw new Error("path must be a non-empty string"); } if (!params || typeof params !== "object ...[truncated 2304 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/log.js:5
Finding

Automatic Plaintext Persistence of URLs and Retrieved Data

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.substring(0, 200); } if (safeFilename === "") { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outputFilename, content); utils.printSuccess(` → Saved to ${outputFilename}`); } catch (error) { utils.printError(`Log write failed: ${error.message}`); } } ``` Each successful command automatically persists the complete output. For example, the comment command performs the following write: ```js await log.taskWrite( `${startTime}_${validator.url2Name(url)}_comment.json`, JSON.stringify(finalOutput, null, 2), ); ``` The search, detail, and post commands contain equivalent unconditional calls. ### Technical Analysis Every successful command automatically writes its complete JSON result to the project's `logs/` directory. This behavior is not controlled by an ex ...[truncated 2237 chars]
Remediation
View remediation
` or `--save-results` before writing results to disk. 3. Clearly disclose what data will be stored, where it will be stored, and how long it will remain. 4. Redact sensitive query parameters such as `xsec_token`, `token`, and similar credentials before printing or saving URLs. 5. Create directories and files with restrictive permissions: ```js await fs.promises.mkdir(directory, { recursive: true, mode: 0o700 }); await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, flag: "wx" }); ``` 6. Avoid storing complete responses when only aggregate information is needed. 7. Add configurable retention and an automatic cleanup mechanism. 8. Provide a documented command for securely removing stored results. 9. Warn users when the project directory is located in a shared, synchronized, or automatically backed-up location. 10. Add tests confirming that secrets and sensitive URL parameters are removed from persisted output. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (74)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Keyword search is a materially different capability from retrieving comments for a supplied note URL. Because search can enumerate and discover new content at scale, understating it as a comment-analysis skill increases the chance of unauthorized or unexpected collection beyond the user's original request.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Keyword search is a materially different capability from retrieving comments for a supplied note URL. Because search can enumerate and discover new content at scale, understating it as a comment-analysis skill increases the chance of unauthorized or unexpected collection beyond the user's original request.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Keyword search is a materially different capability from retrieving comments for a supplied note URL. Because search can enumerate and discover new content at scale, understating it as a comment-analysis skill increases the chance of unauthorized or unexpected collection beyond the user's original request.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Keyword search is a materially different capability from retrieving comments for a supplied note URL. Because search can enumerate and discover new content at scale, understating it as a comment-analysis skill increases the chance of unauthorized or unexpected collection beyond the user's original request.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Keyword search is a materially different capability from retrieving comments for a supplied note URL. Because search can enumerate and discover new content at scale, understating it as a comment-analysis skill increases the chance of unauthorized or unexpected collection beyond the user's original request.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Keyword search is a materially different capability from retrieving comments for a supplied note URL. Because search can enumerate and discover new content at scale, understating it as a comment-analysis skill increases the chance of unauthorized or unexpected collection beyond the user's original request.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Keyword search is a materially different capability from retrieving comments for a supplied note URL. Because search can enumerate and discover new content at scale, understating it as a comment-analysis skill increases the chance of unauthorized or unexpected collection beyond the user's original request.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Keyword search is a materially different capability from retrieving comments for a supplied note URL. Because search can enumerate and discover new content at scale, understating it as a comment-analysis skill increases the chance of unauthorized or unexpected collection beyond the user's original request.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Keyword search is a materially different capability from retrieving comments for a supplied note URL. Because search can enumerate and discover new content at scale, understating it as a comment-analysis skill increases the chance of unauthorized or unexpected collection beyond the user's original request.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Keyword search is a materially different capability from retrieving comments for a supplied note URL. Because search can enumerate and discover new content at scale, understating it as a comment-analysis skill increases the chance of unauthorized or unexpected collection beyond the user's original request.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Keyword search is a materially different capability from retrieving comments for a supplied note URL. Because search can enumerate and discover new content at scale, understating it as a comment-analysis skill increases the chance of unauthorized or unexpected collection beyond the user's original request.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Keyword search is a materially different capability from retrieving comments for a supplied note URL. Because search can enumerate and discover new content at scale, understating it as a comment-analysis skill increases the chance of unauthorized or unexpected collection beyond the user's original request.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README advertises a broad Xiaohongshu data-mining suite including keyword search, note details, competitor monitoring, KOL screening, and trend tracking, while the declared skill scope is comment-only analysis. This scope mismatch can mislead users or orchestrators into invoking capabilities beyond the approved boundary, increasing the risk of over-collection, policy bypass, and unintended access to unrelated public data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code explicitly creates and fetches a note detail task and returns note metadata such as note ID, xsec_token, and author profile information, which conflicts with the skill's stated purpose of only retrieving comments. This creates a data-scope violation: users may invoke a comment-analysis skill while the implementation silently collects and exposes additional post/body-related data and profile links they did not expect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation retrieves blogger published-post data via /api/xiaohongshu/post/* endpoints, while the skill manifest claims the skill is limited to comment content, commenter info, and interaction metrics for a single note. This scope mismatch can cause the agent to collect broader creator/post data than the user authorized or expected, creating a data over-collection and capability-misrepresentation issue.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This module performs keyword-based note discovery and constructs note/profile URLs, which exceeds the declared comment-analysis-only scope of the skill. That scope mismatch is dangerous because it enables broader content discovery and user/profile enumeration than users would reasonably expect, increasing the chance of unauthorized data collection or misuse of the skill for surveillance-style harvesting.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:15