Back to skill

Security audit

guaikei·小红书看博主

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Xiaohongshu public-data tool, but it handles an API credential and stores retrieved datasets in ways users should review before installing.

Install only if you are comfortable sending Xiaohongshu URLs, keywords, and your GUAIKEI_API_TOKEN to guaikei.com, and treat the generated logs as sensitive. Prefer using a limited or revocable token, avoid running from synced/shared folders, and delete artifact/logs outputs when they are no longer needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/api/comment.js:17
Finding

API Credential Transmitted in URL Query Parameters

Content
View full analysis
{ return await postJson( "/api/xiaohongshu/comment/url", { _: Date.now(), token: token }, { url, limit }, ); }, constants.CREATE_MAX_ATTEMPTS, (attempt, err) => { utils.printError( `【创建任务重试】 ${attempt + 1}/${constants.CREATE_MAX_ATTEMPTS} 次 - ${err.message}`, ); }, ); } ``` ```js // src/api/comment.js:43-51 async function getCommentTask(token, url, limit) { return await withRetry( async () => { const res = await getJson("/api/xiaohongshu/comment/info", { _: Date.now(), token: token, url, limit, }); return res.data; ``` ```js // src/utils/request.js:76-98 async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new Error("path 必须是非空字符串"); } if (!params || typeof params !== "object") { throw new Error("params 必须是对象"); } if (!data || typeof data !== "object") { throw new Error("data 必须是对象"); } params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Content-Length": Buffer.byteLength(jsonData), }, }; return await request(options, jsonData); } ``` ```js // src/utils/request.js:101-119 async function getJson(path, params) { if (!path || typeof path !== "string") { throw n ...[truncated 2813 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/xiaohongshu/comment-cli.js:158
Finding

Automatic Persistence of Retrieved User and Research Data Without Explicit Opt-In

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.substring(0, 200); } if (safeFilename === "") { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outputFilename, content); utils.printSuccess(` → 已保存到 ${outputFilename}`); } catch (error) { utils.printError(`日志写入失败: ${error.message}`); } } ``` ### Technical Analysis Every successful CLI operation writes the complete structured response into the project-level `logs/` directory. This occurs automatically rather than through an explicit output option or user consent. Depending on the command, retained records can include: - Commen ...[truncated 2322 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (37)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
node src/xiaohongshu/detail-cli.js --url "<笔记链接>" [--limit N]

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says the skill should be used even when the user did not explicitly request comment analysis, as long as they provided a note link and care about audience feedback. This creates an overly broad implicit trigger that can cause the agent to invoke external data collection unexpectedly, increasing the risk of unintended third-party data transfer and user-surprising behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The documented trigger phrases are broad conversational language like '大家怎么说这篇' and '拉一下这篇笔记的评论' without strong exclusion boundaries. In an agent setting, such broad phrasing can over-match adjacent requests and cause the tool to be selected when the user may have wanted only high-level discussion rather than external retrieval of comment data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description and keywords are entirely in Chinese and target the Xiaohongshu platform, which effectively constrains the skill's language/locale context without any opt-in or explicit justification in this file. Under the policy, language or locale restrictions should either be user-selectable or clearly documented as intentionally region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that all task results are automatically saved under a local logs/ directory, but it does not prominently warn users that exported results may contain sensitive business intelligence such as monitored accounts, keywords, URLs, comments, and analysis outputs. This creates a real data-handling risk because users may unknowingly persist scraped content on shared workstations, synced folders, or insecure disks, increasing exposure through local compromise or accidental disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file documents capabilities that retrieve public note details, comments, and account post history for analysis, but it does not warn users that executing these workflows may process third-party content and profile data. Under the markdown-specific warning rule, behaviors that could affect privacy should be disclosed in the skill description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The markdown explicitly requires configuring the environment variable GUAIKEI_API_TOKEN, which is credential material, but does not include any warning not to expose, log, or share the token. For markdown files, omission of warnings around privacy or system-integrity-relevant behavior is in scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The function sends an API token and a user-provided note URL to a remote endpoint via postJson, which is a privacy-relevant network operation. Although the JSDoc describes parameters, there is no user-facing confirmation, warning, or disclosure in the code indicating that these values will be transmitted externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This request to /api/xiaohongshu/comment/info transmits the API token, URL, and limit to an external service. The code includes retry logging for failures, but it does not provide any user-facing warning that potentially sensitive inputs are being sent over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function sends the API token and note URL in an HTTP request body/query via postJson, but this file only contains technical parameter docstrings and retry error logging. There is no user-facing warning, confirmation, or explicit disclosure here that user-provided links and credentials are transmitted to a remote API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This function performs an HTTP GET request carrying the API token, URL, and limit values to an external endpoint. While retries are logged, the file does not provide a user-facing warning that these inputs and credentials are sent over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code presents user-facing status and recovery messages only in Chinese, including the warning and follow-up instructions. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not shown here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits user-visible error text in Chinese (e.g. at L07 and L11), which imposes a specific language on users without any opt-in or indication that the skill is region-specific. That matches the language/locale policy violation criteria for natural-language policy issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file hardcodes end-user-facing error strings in Chinese, including token and request failure messages, with no indication that the user can choose locale or language. This can violate language/locale policy when the skill is used in broader contexts where language should be user-selectable or explicitly documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JavaScript file contains natural-language comments and error messages exclusively in Chinese, including all validation feedback shown to users. Under the policy for language/locale handling, forcing a specific language without offering user choice or documenting a justified locale constraint is a violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code reads the GUAIKEI_API_TOKEN from the environment and sends the user-supplied note URL and limit into createCommentTask/getCommentTask, which implies external API transmission. While the help text mentions that the token must be configured, it does not clearly warn the user that their requested URL and associated metadata will be sent to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The command persists the full finalOutput, including request metadata and results, to a file via log.taskWrite, but there is no visible disclosure in comments, help text, or runtime output that local data will be written. Because this creates a lasting copy of retrieved content on disk, users should be warned before or during execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file contains multiple user-facing descriptions and help text in Chinese, including argument descriptions and usage notes. Because the skill does not offer language selection or state that it is intentionally limited to a Chinese-speaking or region-specific context, it creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

No manifest is available, so the skill's purpose is unknown and there is no declared justification for accessing credentials from the environment. The code explicitly requires and consumes GUAIKEI_API_TOKEN, which is a sensitive capability beyond what can be inferred from this file's minimal CLI behavior alone.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI writes the full fetched results to a local JSON file using a filename derived from the target URL. If the returned detail data includes personal data, comments, identifiers, or other sensitive content, this creates undeclared local data retention that can expose data to other local users, backups, or later unintended reuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The CLI help text, validation errors, status messages, and output messages are written entirely in Chinese with no option to select another language. This is a natural-language policy concern because it forces a specific locale on all users rather than offering language choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16