Back to skill

Security audit

guaikei·小红书趋势脉搏

Security checks for vulnerabilities and agentic risk

Overview

This skill appears purpose-built for public Xiaohongshu research, but it needs review because it passes an API credential in request URLs and saves collected results locally by default.

Review before installing if the API token has paid quota or broad account privileges. Use a dedicated low-privilege Guaikei token, avoid submitting sensitive research terms or private tracking URLs, and periodically delete or protect the generated logs directory because fetched content and target URLs are saved there automatically.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:82
Finding

API Credential Transmitted in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/xiaohongshu/detail-cli.js:145
Finding

Automatic Plaintext Persistence of Sensitive URLs and Retrieved Data

Content
View full analysis
Remediation
View remediation
` or `--save`. 2. Do not write files by default when the caller only requests stdout output. 3. Redact sensitive URL parameters before logging or persistence: ```js const parsed = new URL(url); parsed.searchParams.delete("xsec_token"); ``` 4. Consider retaining only stable public identifiers rather than complete source URLs. 5. Create files with explicitly restrictive permissions: ```js await fs.promises.writeFile(outputFilename, content, { mode: 0o600 }); ``` 6. Create the `logs/` directory with restrictive permissions and document the data retained there. 7. Add configurable retention controls and a cleanup command so old results do not remain indefinitely. 8. Add `logs/` to `.gitignore` and exclude it from default packaging, backups, diagnostics, and workspace uploads where appropriate. 9. Warn users before saving potentially sensitive query history or large comment datasets. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (42)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code snippet is only a constants/config file, so by itself it does not implement the declared Xiaohongshu public-data features. More importantly, the configured base URL is 'www.guaikei.com', which is inconsistent with a skill whose purpose is specifically to access Xiaohongshu public content. That suggests a resource mismatch. Timeout/retry/version constants are normal supporting details, but the non-Xiaohongshu base domain materially conflicts with the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code chunk does not match the declared functional purpose. The description claims the skill is for accessing Xiaohongshu public data, but the supplied code only provides reusable command-line argument parsing utilities. While such utilities could be a supporting component of a larger Xiaohongshu tool, this chunk by itself does not implement any of the declared end-user capabilities or interact with the stated resource (Xiaohongshu public notes/comments/creator posts). Therefore, based on the supplied code chunk alone, there is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill requires a sensitive environment variable (GUAIKEI_API_TOKEN) and instructs the agent to execute external Node scripts, but it declares no explicit tool/permission scope. That creates an authorization gap: an orchestrator or reviewer cannot clearly constrain environment access or understand what capabilities the skill needs before execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states only near the end that data is routed through a third-party API, but it does not provide a prominent pre-execution warning that user queries and supplied Xiaohongshu URLs will be transmitted externally. Users may share sensitive research terms, private business monitoring targets, or tracking URLs without informed consent, creating data leakage and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states that all task results are automatically saved to a local logs directory, but it does not clearly warn that fetched note details, comments, and creator post data may contain sensitive or regulated personal data and will persist on disk. In a data-scraping skill focused on competitor monitoring and comment analysis, silent local retention increases the risk of unintended disclosure, over-collection, and mishandling of public-but-still-sensitive data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code sends a token plus a user-supplied Xiaohongshu note URL to a remote API via postJson, but the file provides no confirmation prompt or explicit user-facing warning about that data transmission. Although there are function docstrings, they describe parameters technically and do not disclose the privacy-relevant behavior to users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The getCommentTask function performs a network request containing the API token, note URL, and limit, but there is no confirmation prompt or user-facing disclosure that these values are sent to an external service. The existing comments are developer-oriented and do not warn about privacy or data-sharing implications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file uses Chinese-only natural language in module comments, parameter documentation, and runtime error/log strings, which indicates a fixed language choice. Under the policy, language constraints should offer user opt-in or be clearly justified as region-specific; that justification is not present in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JavaScript file contains natural-language comments and user-facing error/help text entirely in Chinese, including thrown error messages and generated CLI help output. Because the file provides user-visible text but does not offer a language choice or document a justified locale restriction, it creates a language/locale policy concern under the stated rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The user-facing strings at L22-L25 are entirely in Chinese and provide no alternative language option or opt-in. This creates a locale/language policy issue because the skill imposes a specific language on users without indicating that the skill is intentionally China/Chinese-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Several error messages are hardcoded in Chinese, including instructions to check an environment variable and contact a WeChat number. This imposes a specific language/locale on all users without opt-in or justification, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code builds GET and POST requests to an external host and sends caller-provided params and JSON data, which may include user or system data. There is no confirmation prompt, logging, comment, or docstring warning users that data will be transmitted off-box, so the network behavior is not disclosed in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language comments and error messages exclusively in Chinese, such as the function comment at L04 and multiple user-facing errors from L08 through L68. Per the policy, forcing a specific language without offering user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The code reads GUAIKEI_API_TOKEN from the environment and uses it in createCommentTask and getCommentTask, which are network/API operations implied by the API module usage. Although the CLI prints progress messages, it does not clearly disclose that the note URL and token-authenticated request data will be sent to an external service.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a skill for searching/viewing Xiaohongshu public data such as notes, comments, and creator posts. In addition to returning comment data, this file persists the full output to disk via log.taskWrite, which is a separate local storage capability not implied by simple public-data retrieval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI silently writes fetched comments and request metadata to a local JSON file without clearly disclosing that behavior before execution. Even though the source data is public, local persistence can expose browsing targets, collected datasets, and possibly sensitive operator metadata to other local users, backups, or later compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code reads an API token from the environment and then invokes external detail-task API calls using the supplied URL and limit. Although the help text mentions the token requirement, it does not clearly disclose that the skill transmits user-provided input to a remote service, which is the kind of network operation that should have a visible warning in code or documentation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI persists the full fetched result set, including note details and comments, to a local JSON file after completing a read-only retrieval task. This expands the skill's data handling scope from transient display to local storage without clear necessity or user consent, increasing the risk of unintended retention, later disclosure, or collection of scraped content on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill writes detailed fetched content to a local JSON file without clearly informing the user that data will persist on disk. For a tool advertised as viewing public content, silent persistence can surprise users and expose collected note/comment data to other local users, backup systems, or later compromise.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16