Back to skill

Security audit

xhs-campaign-monitor

Security checks for vulnerabilities and agentic risk

Overview

This skill appears purpose-built for Xiaohongshu public-data analysis, but it handles API tokens and saved result data in ways users should review before installing.

Review whether you are comfortable sending Xiaohongshu URLs, keywords, and your GUAIKEI API token to guaikei.com. Treat generated logs as sensitive, delete them when no longer needed, and avoid running this in shared or synced directories unless tokenized URLs and collected comments are acceptable to persist there.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:86
Finding

API Credential Transmitted in URL Query Strings

Content
View full analysis
{ return await postJson( "/api/xiaohongshu/detail/url", { _: Date.now(), token: token }, { url: url, limit: limit }, ); }, ``` The request utility serializes that object directly into the request URL: ```js async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new Error("path must be a non-empty string"); } if (!params || typeof params !== "object") { throw new Error("params must be an object"); } if (!data || typeof data !== "object") { throw new Error("data must be an object"); } params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Content-Length": Buffer.byteLength(jsonData), }, }; return await request(options, jsonData); } ``` Polling requests use the same construction: ```js async function getJson(path, params) { if (!path || typeof path !== "string") { throw new Error("path must be a non-empty string"); } if (!params || typeof params !== "object") { throw new Error("params must be an object"); } params._ = Date.now(); const fullPath = `${path}?${querystring.string ...[truncated 2367 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/xiaohongshu/detail-cli.js:138
Finding

Tokenized URLs and Retrieved Data Automatically Persisted in Plaintext Logs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (40)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

该代码片段只是一个通用参数解析模块(parseArgs/readValueAfterFlag/buildHelp),用于处理命令行输入和帮助文本生成。这属于支持性基础组件,但就当前提供的代码块本身而言,其行为与声明的核心用途——小红书公开内容搜索、详情/评论获取、博主作品抓取和运营分析——没有直接对应关系。由于评估的是描述与所供代码块实际行为是否一致,当前代码块的实际功能是通用 CLI 工具,而不是小红书运营数据处理,因此存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向小红书公开内容抓取与分析的数据工具,应体现搜索/抓取笔记、评论或博主作品等能力。但提供的代码片段只是在本地文件系统中创建目录并写入日志文件,没有任何与小红书数据访问、搜索、抓取、评论读取或分析相关的实现。虽然日志功能可能是辅助性实现,但当前片段本身的实际行为与声明目的没有直接对应关系,且包含未声明的本地文件写入能力。因此可判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书公开内容采集与分析的运营数据工具,但提供的代码片段仅实现了一个读取本地 package.json 并返回包名的辅助函数。该行为与声明的核心用途没有直接关系,也没有体现任何小红书数据访问、搜索、评论获取、作品列表抓取或分析逻辑。虽然这可能是项目中的辅助实现细节,但就该代码片段本身而言,其实际行为与声明用途明显不一致,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 260)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 271)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 283)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description and the full skill documentation require Chinese comprehension, but nowhere indicate that the skill is Chinese-only or provide an alternative language option. This can violate a language/locale policy when users or agents are expected to support multiple languages unless a locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not warn users that scraped note details, comments, URLs, keywords, or account targets may persist on disk. In a data-collection tool, this creates a real confidentiality and retention risk because sensitive business intelligence or personal data from public comments can be stored longer than intended and exposed through backups, shared workstations, or source bundle uploads.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This is a markdown file, so SQP-2 applies to omissions in user-facing safety disclosures. The document instructs users to retrieve public note details, comments, and account content for analysis, but it does not warn about privacy considerations, responsible use of third-party data, or the need to ensure authorization/compliance when analyzing user-generated content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This file uses Chinese-only natural-language comments and runtime error/log strings for the module interface and retry messages, but does not indicate that the skill is region-specific or that users can opt into this locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code sends the provided API token as part of HTTP request parameters/body when creating a task, which is a sensitive credential-handling operation. While the function has technical docstrings, there is no user-facing warning, confirmation, or disclosure here that credentials will be transmitted to a remote API.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JavaScript file contains natural-language comments and user-facing CLI messages entirely in Chinese, including thrown errors and help text. Under the policy rule, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Multiple error strings are hardcoded in Chinese, including operational guidance and support instructions, with no indication that the user can choose another language or locale. The policy for all file types says to flag language/locale constraints that force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code constructs and sends HTTPS GET/POST requests using caller-supplied params and data, which may include user or system data, but there is no confirmation prompt, visible logging, or explanatory comment/docstring disclosing that transmission. For code files, network calls that transmit data should have some form of user disclosure unless clearly covered elsewhere; this file itself provides none.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JavaScript file contains multiple user-facing validation errors in Chinese string literals, such as at L08, L13, L17, L21, L24-L26, L54, L59, L64, and L68. Because the skill forces a specific language in its interactions without any visible opt-in or documented locale limitation in this file, it creates a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code creates and fetches a remote comment task using the user-supplied Xiaohongshu URL, which implies transmitting user-provided data to an external service. Although the CLI prints status messages, it does not clearly disclose that note data is being sent to a remote API, nor that results are later persisted locally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.