T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:82- Finding
API Credential Transmitted in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears purpose-built for public Xiaohongshu research, but it needs review because it passes an API credential in request URLs and saves collected results locally by default.
Review before installing if the API token has paid quota or broad account privileges. Use a dedicated low-privilege Guaikei token, avoid submitting sensitive research terms or private tracking URLs, and periodically delete or protect the generated logs directory because fetched content and target URLs are saved there automatically.
src/utils/request.js:82API Credential Transmitted in URL Query Strings
src/xiaohongshu/detail-cli.js:145Automatic Plaintext Persistence of Sensitive URLs and Retrieved Data
This code snippet is only a constants/config file, so by itself it does not implement the declared Xiaohongshu public-data features. More importantly, the configured base URL is 'www.guaikei.com', which is inconsistent with a skill whose purpose is specifically to access Xiaohongshu public content. That suggests a resource mismatch. Timeout/retry/version constants are normal supporting details, but the non-Xiaohongshu base domain materially conflicts with the declared purpose.
This code chunk does not match the declared functional purpose. The description claims the skill is for accessing Xiaohongshu public data, but the supplied code only provides reusable command-line argument parsing utilities. While such utilities could be a supporting component of a larger Xiaohongshu tool, this chunk by itself does not implement any of the declared end-user capabilities or interact with the stated resource (Xiaohongshu public notes/comments/creator posts). Therefore, based on the supplied code chunk alone, there is a clear description-behavior mismatch.
Referenced artifact was not completely inspected
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |
Referenced artifact was not completely inspected
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |
Referenced artifact was not completely inspected
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |
The skill requires a sensitive environment variable (GUAIKEI_API_TOKEN) and instructs the agent to execute external Node scripts, but it declares no explicit tool/permission scope. That creates an authorization gap: an orchestrator or reviewer cannot clearly constrain environment access or understand what capabilities the skill needs before execution.
The skill states only near the end that data is routed through a third-party API, but it does not provide a prominent pre-execution warning that user queries and supplied Xiaohongshu URLs will be transmitted externally. Users may share sensitive research terms, private business monitoring targets, or tracking URLs without informed consent, creating data leakage and compliance risk.
The README states that all task results are automatically saved to a local logs directory, but it does not clearly warn that fetched note details, comments, and creator post data may contain sensitive or regulated personal data and will persist on disk. In a data-scraping skill focused on competitor monitoring and comment analysis, silent local retention increases the risk of unintended disclosure, over-collection, and mishandling of public-but-still-sensitive data.
This code sends a token plus a user-supplied Xiaohongshu note URL to a remote API via postJson, but the file provides no confirmation prompt or explicit user-facing warning about that data transmission. Although there are function docstrings, they describe parameters technically and do not disclose the privacy-relevant behavior to users.
The getCommentTask function performs a network request containing the API token, note URL, and limit, but there is no confirmation prompt or user-facing disclosure that these values are sent to an external service. The existing comments are developer-oriented and do not warn about privacy or data-sharing implications.
This file uses Chinese-only natural language in module comments, parameter documentation, and runtime error/log strings, which indicates a fixed language choice. Under the policy, language constraints should offer user opt-in or be clearly justified as region-specific; that justification is not present in this file.
This JavaScript file contains natural-language comments and user-facing error/help text entirely in Chinese, including thrown error messages and generated CLI help output. Because the file provides user-visible text but does not offer a language choice or document a justified locale restriction, it creates a language/locale policy concern under the stated rule.
The user-facing strings at L22-L25 are entirely in Chinese and provide no alternative language option or opt-in. This creates a locale/language policy issue because the skill imposes a specific language on users without indicating that the skill is intentionally China/Chinese-only.
Several error messages are hardcoded in Chinese, including instructions to check an environment variable and contact a WeChat number. This imposes a specific language/locale on all users without opt-in or justification, which matches the language-policy violation criteria.
This code builds GET and POST requests to an external host and sends caller-provided params and JSON data, which may include user or system data. There is no confirmation prompt, logging, comment, or docstring warning users that data will be transmitted off-box, so the network behavior is not disclosed in this file.
This JavaScript file contains natural-language comments and error messages exclusively in Chinese, such as the function comment at L04 and multiple user-facing errors from L08 through L68. Per the policy, forcing a specific language without offering user choice or documenting a justified locale constraint is a natural-language policy violation.
The code reads GUAIKEI_API_TOKEN from the environment and uses it in createCommentTask and getCommentTask, which are network/API operations implied by the API module usage. Although the CLI prints progress messages, it does not clearly disclose that the note URL and token-authenticated request data will be sent to an external service.
The manifest describes a skill for searching/viewing Xiaohongshu public data such as notes, comments, and creator posts. In addition to returning comment data, this file persists the full output to disk via log.taskWrite, which is a separate local storage capability not implied by simple public-data retrieval.
The CLI silently writes fetched comments and request metadata to a local JSON file without clearly disclosing that behavior before execution. Even though the source data is public, local persistence can expose browsing targets, collected datasets, and possibly sensitive operator metadata to other local users, backups, or later compromise.
This code reads an API token from the environment and then invokes external detail-task API calls using the supplied URL and limit. Although the help text mentions the token requirement, it does not clearly disclose that the skill transmits user-provided input to a remote service, which is the kind of network operation that should have a visible warning in code or documentation.
The CLI persists the full fetched result set, including note details and comments, to a local JSON file after completing a read-only retrieval task. This expands the skill's data handling scope from transient display to local storage without clear necessity or user consent, increasing the risk of unintended retention, later disclosure, or collection of scraped content on disk.
The skill writes detailed fetched content to a local JSON file without clearly informing the user that data will persist on disk. For a tool advertised as viewing public content, silent persistence can surprise users and expose collected note/comment data to other local users, backup systems, or later compromise.
Detected: suspicious.exposed_secret_literal