Back to skill

Security audit

guaikei·小红书趋势表

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform the Xiaohongshu public-data lookup it advertises, but it should be reviewed because it sends credentials and target URLs to a third-party API and saves full results locally by default.

Install only if you are comfortable sending Xiaohongshu keywords, links, and retrieved public content to Guaikei's API. Treat GUAIKEI_API_TOKEN as a secret, avoid sharing tokenized Xiaohongshu URLs unless needed, and regularly delete or protect the generated logs directory because it can contain research history and full collected datasets.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Token Exposed in HTTP URL Query Strings

Content
View full analysis
{ return await postJson( "/api/xiaohongshu/note-search/keyword", { _: Date.now(), token: token }, { keyword, type, sort, time, limit }, ); }, constants.CREATE_MAX_ATTEMPTS, (attempt, err) => { utils.printError( `【创建任务重试】 ${attempt + 1}/${constants.CREATE_MAX_ATTEMPTS} 次 - ${err.message}`, ); }, ); } ``` The shared request utility serializes those parameters directly into the request URL: ```js async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new Error("path 必须是非空字符串"); } if (!params || typeof params !== "object") { throw new Error("params 必须是对象"); } if (!data || typeof data !== "object") { throw new Error("data 必须是对象"); } params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Content-Length": Buffer.byteLength(jsonData), }, }; return await request(options, jsonData); } async function getJson(path, params) { if (!path || typeof path !== "string") { throw new Error("path 必须是非空字符串"); } if (!params || typeof params !== "object") { throw new Error("params 必须是对象"); } params._ = Date.now(); const fullPath = `${path}?${qu ...[truncated 2300 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/xiaohongshu/detail-cli.js:138
Finding

Automatic Plaintext Persistence of Tokenized URLs and Collected Data

Content
View full analysis
Remediation
View remediation
` or `--save`. 2. Redact sensitive URL parameters before printing or saving: ```js function redactSensitiveUrl(rawUrl) { const parsed = new URL(rawUrl); for (const key of ["xsec_token", "token", "access_token"]) { if (parsed.searchParams.has(key)) { parsed.searchParams.set(key, "[REDACTED]"); } } return parsed.toString(); } ``` 3. Do not retain the complete request URL when only a note or profile identifier is required. 4. Minimize stored response fields and allow users to select what data should be persisted. 5. Create files with restrictive permissions: ```js await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, flag: "wx", }); ``` 6. Ensure the log directory itself has restrictive permissions, such as `0o700`, where supported. 7. Add configurable retention and automatic cleanup, including maximum age and storage-size limits. 8. Exclude `logs/` from version control, package publication, build artifacts, and automatic support bundles. 9. Document that generated files can contain tokenized URLs and social-media datasets, not merely operational logs. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (43)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

该代码片段仅实现了通用参数解析器(parseArgs、readValueAfterFlag、buildHelp),用于处理命令行输入和帮助文本生成。它没有网络请求、没有与小红书相关的域名/接口交互、没有抓取公开笔记或评论、也没有任何结构化内容提取或分析逻辑。因此,就当前提供的代码片段而言,其实际行为与声明的技能目的存在明显不匹配。虽然这类工具代码可能作为更大项目的辅助模块存在,但按本片段单独评估,主行为与声明功能并不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个面向小红书公开内容检索与分析的数据抓取技能,而提供的代码片段实际只是在本地文件系统中写日志。虽然日志记录可能是辅助实现细节,但该代码本身未体现任何小红书搜索、抓取、解析、评论获取、博主作品监控或结构化数据返回逻辑,反而执行了声明中未提及的本地文件写入能力。因此该代码片段与声明用途存在明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a network/data-scraping skill focused on Xiaohongshu public content and analytics. However, the supplied code chunk does not implement any of those behaviors. It merely uses fs and path to locate and read package.json from the local filesystem and returns the package name. While utility code can be supportive, this specific chunk shows only unrelated metadata access and none of the declared XHS capabilities. Based on the supplied code alone, the description does not accurately represent the observed behavior.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "拉这条笔记的评论做观点聚类: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
- "拉这条笔记的评论做观点聚类: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
- "拉这条笔记的评论做观点聚类: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill declares use of an environment secret (GUAIKEI_API_TOKEN) but does not define an explicit tool scope such as permissions or allowed-tools. That makes the execution boundary unclear and increases the risk of over-broad runtime access or accidental secret exposure when the skill is invoked or extended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation criteria are very broad, including shorthand terms like xhs, rednote, or any linked domain mention, even when the user did not clearly request third-party data retrieval. This can cause the skill to trigger unexpectedly, sending user-provided links or keywords to an external service and expanding data exposure beyond user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill relies on a third-party API service, but the user-facing description does not prominently warn up front that submitted keywords, links, and retrieved content may be sent off-platform. This creates a data handling transparency issue and may lead users to unknowingly transmit sensitive research targets, URLs, or content to an external provider.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This is a markdown file, so SQP-2 applies to omissions in user-facing warnings. The document explains how to retrieve public note details, comments, and creator post lists, but it does not warn users that these actions may process third-party content, potentially sensitive comment data, or trigger external platform requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file explicitly requires the environment variable GUAIKEI_API_TOKEN, which indicates credential use. Under SQP-2 for markdown files, user-facing documentation should warn about behaviors affecting privacy or system integrity; here there is no caution to keep the token secret, avoid exposing it in logs, or use secure environment configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The function sends a token to a remote API via postJson, which is a safety-relevant network operation involving credentials. While the code has developer-facing docstrings, there is no user-facing warning, confirmation, or disclosure that the provided API token and URL will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code performs an HTTP GET request that includes the API token, note URL, and limit parameters, which may expose credential and user-supplied data to a remote service. The surrounding comments describe parameters for developers but do not provide a user-facing warning or confirmation about this transmission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains natural-language comments and likely user-visible strings such as error messages and help text entirely in Chinese. That imposes a specific language on users without any opt-in, fallback, or indication that the tool is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Several error strings are hardcoded in Chinese, including operational guidance, with no indication that the user can choose another language or locale. This can violate language/locale policy where skills must not force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JavaScript file contains multiple natural-language error strings in Chinese, such as at L08, L13, L17, L21, L24-L26, L54, L59, L64, and L68. Because the skill forces a specific language for user-facing output without any opt-in, fallback, or documented regional justification in this file, it conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The CLI persists fetched comment data to a local file without any user-facing warning or opt-in at the point of use. Because comment content may contain personal or sensitive information, silent local retention increases exposure through shared machines, backups, or unintended secondary use, especially since the skill description does not mention local storage.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI persists the full fetched output, including note details and comments, to a local JSON file without this storage behavior being disclosed in the skill description. Even though the data is from public Xiaohongshu content, comments and extracted datasets may still contain personal data or sensitive research material, and silent local retention increases privacy, compliance, and unintended data exposure risk on shared systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code sends the user-supplied profile URL and limit to external API functions, using an API token, without clearly disclosing that the provided data will be transmitted to a remote service. In this skill context, users may reasonably expect scraping behavior, but silent third-party transmission still creates privacy, compliance, and trust risks, especially when URLs can contain query parameters such as xsec_token.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The CLI persists scraped results to a local JSON file automatically after successful execution, but this file does not warn the user that the returned data will be stored on disk. Scraped profile content and comments may contain personal or sensitive business information, so silent local retention increases the risk of unintended disclosure through shared machines, backups, or later exfiltration.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:17