Back to skill

Security audit

guaikei·小红书爆款挖掘

Security checks for vulnerabilities and agentic risk

Overview

This Xiaohongshu data skill appears purpose-aligned, but it needs review because it sends an API token in URL query strings and automatically stores collected results locally in plaintext logs.

Review this before installing if you will use real business research, monitored creator links, or paid API tokens. Prefer a version that sends the API token in an Authorization header, supports disabling logs, redacts xsec_token and token fields, and clearly limits when profile/comment collection is invoked.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credential Exposed in URL Query Strings

Content
View full analysis
{ return await postJson( "/api/xiaohongshu/note-search/keyword", { _: Date.now(), token: token }, { keyword, type, sort, time, limit }, ); }, ``` Polling requests expose the same credential: ```js const res = await getJson("/api/xiaohongshu/note-search/info", { _: Date.now(), token: token, keyword, type, sort, time, limit, }); ``` ### Technical Analysis The `GUAIKEI_API_TOKEN` is serialized into the query string for task creation and polling requests. Although the connection uses HTTPS, HTTPS only protects the request from passive network interception. It does not prevent the URL from being recorded af ...[truncated 1716 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:11
Finding

Automatic Plaintext Persistence of Retrieved Data and URL Access Tokens

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.substring(0, 200); } if (safeFilename === "") { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outputFilename, content); ``` API responses can be augmented with URLs containing `xsec_token` before being persisted: ```js if (item.id && item.xsec_token) { res.data[i].url = "https://www.xiaohongshu.com/explore/" + item.id + "?xsec_token=" + item.xsec_token; } if (item.user && item.user.user_id && item.user.xsec_token) { res.data[i].user.url = "https://www.xiaohongshu.com/user/profile/" + item.user.user_id + "?xsec_token=" + item.user.xsec_token; } ``` ### Technical Analysis Every successful CLI operation writes the complete `finalOutput` object under the project-level `logs/` directory. Depending on the command and response, the file can contain: - Search keywords and filter choices - User-supplied Xiaoh ...[truncated 1891 chars]
Remediation
View remediation
` rather than writing every successful result automatically. 2. Provide a `--no-log` mode and use it by default for Agent-driven execution. 3. Recursively redact sensitive query parameters before serialization, including: - `xsec_token` - `token` - `access_token` - Other API or session credentials 4. Create the directory and files with restrictive permissions: ```js await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, sanitizedContent, { mode: 0o600, flag: "wx", }); ``` 5. Use an operating-system-specific private application-data directory rather than the project tree. 6. Implement configurable retention and automatic deletion of expired output files. 7. Document exactly which data is stored, where it is stored, and how users can remove it. 8. Add `logs/` to `.gitignore` and package exclusion rules to reduce accidental publication. 9. Avoid embedding access-related tokens in returned URLs unless strictly required; otherwise expose them in a separately classified sensitive field that is excluded from logs. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (61)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill also supports creator-homepage URL handling and post retrieval, which is broader than the stated topic/keyword search purpose. In context, that makes the skill more dangerous because it enables ongoing creator/KOL monitoring workflows under the banner of simple content discovery.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill also supports creator-homepage URL handling and post retrieval, which is broader than the stated topic/keyword search purpose. In context, that makes the skill more dangerous because it enables ongoing creator/KOL monitoring workflows under the banner of simple content discovery.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill also supports creator-homepage URL handling and post retrieval, which is broader than the stated topic/keyword search purpose. In context, that makes the skill more dangerous because it enables ongoing creator/KOL monitoring workflows under the banner of simple content discovery.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill also supports creator-homepage URL handling and post retrieval, which is broader than the stated topic/keyword search purpose. In context, that makes the skill more dangerous because it enables ongoing creator/KOL monitoring workflows under the banner of simple content discovery.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill also supports creator-homepage URL handling and post retrieval, which is broader than the stated topic/keyword search purpose. In context, that makes the skill more dangerous because it enables ongoing creator/KOL monitoring workflows under the banner of simple content discovery.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill also supports creator-homepage URL handling and post retrieval, which is broader than the stated topic/keyword search purpose. In context, that makes the skill more dangerous because it enables ongoing creator/KOL monitoring workflows under the banner of simple content discovery.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill also supports creator-homepage URL handling and post retrieval, which is broader than the stated topic/keyword search purpose. In context, that makes the skill more dangerous because it enables ongoing creator/KOL monitoring workflows under the banner of simple content discovery.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill also supports creator-homepage URL handling and post retrieval, which is broader than the stated topic/keyword search purpose. In context, that makes the skill more dangerous because it enables ongoing creator/KOL monitoring workflows under the banner of simple content discovery.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill also supports creator-homepage URL handling and post retrieval, which is broader than the stated topic/keyword search purpose. In context, that makes the skill more dangerous because it enables ongoing creator/KOL monitoring workflows under the banner of simple content discovery.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The CLI exposes comment-retrieval functionality even though the skill metadata describes a read-only search-and-summary capability for public notes. This creates a scope mismatch: a caller or platform may grant or trust the skill based on a narrower manifest, while the code can access richer user-generated content than disclosed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The CLI behavior materially differs from the declared skill purpose: instead of keyword-based discovery of public Xiaohongshu notes, it accepts a creator profile URL and fetches that account's posts. This kind of scope drift is dangerous because users, reviewers, and upstream agents may authorize the skill under one data-access model while the code performs another, enabling unintended collection of creator-level content and metadata.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says the skill may be used even when the user did not mention Xiaohongshu, as long as the intent is to understand a term's performance on social media. This broad activation condition can cause the agent to inappropriately route generic social-media requests to this skill, resulting in data collection from an unintended platform-specific tool and surprising users.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest context for this skill limits it to searching Xiaohongshu public notes by keyword and returning note metadata for social-media content discovery, explicitly not serving as an SEO or ad-targeting tool. In contrast, the package description and keywords advertise competitor monitoring, KOL screening, precise marketing, traffic growth, and user profiling, which materially exceed simple public-note search.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README presents substantially broader capabilities—competitor monitoring, trend prediction, KOL screening, and comment analysis—than the manifest’s narrower keyword-based Xiaohongshu search purpose. This creates a scope mismatch that can mislead users and reviewers about what the skill actually does, weakening informed consent and increasing the chance of unexpected data collection or use beyond the declared function.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented commands for note detail lookup, profile monitoring, and comment analysis go beyond the manifest description of keyword-based public-note search. In a skill context, undocumented expansion of operational scope is dangerous because users may invoke or authorize capabilities they did not expect, including collection of richer public profile and comment data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README states that all task results are automatically saved to logs/ but does not clearly warn that queried keywords, profile/note links, and collected public-platform data will be written to local files. This is dangerous because operators may run the tool on shared machines or in synced environments, unintentionally persisting sensitive business research, monitored accounts, or scraped content beyond the immediate session.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The changelog claims support for fetching Xiaohongshu comment information, which exceeds the user-facing description that only promises search results such as titles, summaries, authors, engagement metrics, and links. Undisclosed data-access expansion can lead to privacy, consent, and policy issues because downstream systems may invoke the skill expecting lower-sensitivity search behavior while it may retrieve additional user-generated content.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The changelog states that the skill added '博主作品监控' capability, which expands the operational scope beyond the metadata description focused on keyword-based Xiaohongshu note search. This kind of scope drift is dangerous because users, reviewers, or orchestrators may authorize the skill under a narrower trust model while the implementation or docs suggest broader collection and monitoring behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16