Back to skill

Security audit

guaikei·小红书评论舆情分析

Security checks across malware telemetry and agentic risk

Overview

Review before installing: this is a public Xiaohongshu analytics skill, but its top-level description understates broader comment/profile collection and it saves full results locally.

Install only if you are comfortable sending Xiaohongshu keywords or URLs to guaikei.com and retaining the returned public data on disk. Use it for user-directed public-data analysis only, avoid private/login-only data, and periodically delete the generated logs if the results include sensitive business research or user comments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The skill description narrowly frames the skill as recent keyword trend tracking, but the body enables broader collection of note details, comments, creator posts, and multiple sort/time modes. This mismatch can cause users or orchestrators to invoke the skill in situations where they would not have consented to broader data retrieval or external transmission, increasing the risk of over-collection and unintended data sharing.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The package metadata advertises a much broader Xiaohongshu analytics and marketing toolkit than the skill manifest describes, including competitor monitoring, KOL screening, user profiling, and growth/marketing use cases. This capability/description mismatch can mislead reviewers and users about the skill’s true scope, increasing the risk of over-collection, unauthorized use, or invocation for purposes outside the declared hotspot-monitoring behavior.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The declared CLI scripts expose multiple operational modes (search, detail, post, comment), which suggests functionality beyond the manifest’s stated purpose of retrieving recent notes for trend monitoring. Hidden or undeclared entry points expand the accessible attack surface and can enable broader data access or actions than users and reviewers expect.

Description-Behavior Mismatch

High
Confidence
94% confidence
Finding
The README describes a substantially broader Xiaohongshu data-mining capability set than the manifest declares, including competitor monitoring, KOL screening, comment analysis, and large-scale data extraction. This scope mismatch is dangerous because users, reviewers, or downstream agents may trust the narrower manifest while the documentation encourages materially different behavior, increasing the risk of unauthorized scraping, overcollection, and policy bypass through misleading packaging.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The usage examples explicitly instruct users to run note-detail lookup, account monitoring, and comment analysis commands that are outside the manifest’s stated narrow trend-monitoring scope. Operational examples are especially risky because they directly enable broader collection activities, potentially causing an agent or user to invoke functions that were not transparently declared or approved.

Description-Behavior Mismatch

Medium
Confidence
83% confidence
Finding
The README states that all task results are automatically saved to a logs/ directory, but this persistence behavior is not reflected in the manifest’s read-style analytics description. Undisclosed local persistence increases data-handling risk because collected content may be retained longer than expected, exposing potentially sensitive business intelligence or scraped platform data to unintended access on disk.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The changelog documents capabilities beyond the advertised scope of the skill, including comment retrieval, note details, and creator monitoring. This creates a scope-mismatch vulnerability: downstream agents or users may invoke undocumented data-collection behaviors, weakening least-privilege assumptions and increasing the chance of unintended scraping or privacy-impacting use.

Description-Behavior Mismatch

Low
Confidence
81% confidence
Finding
The history shows the skill evolved into a broader 'xiaohongshu-tool' while the current metadata presents a narrower trend-monitoring use case. This inconsistency can mislead reviewers and orchestrators about the actual reachable functionality, which is risky in security-sensitive environments because hidden or residual capabilities may be exposed unintentionally.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The documentation materially expands the skill from a narrow 'recent keyword trend' capability into a general-purpose 4-capability assistant covering search, note detail, creator monitoring, and comment extraction. This creates scope drift between manifest and operator guidance, which can cause the agent to invoke tools or handle data outside the user's expected consent and the platform's declared security review boundary.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The usage guidance promotes sorting modes such as most liked, most commented, and most saved, plus scenarios like content research and爆款 analysis, which exceed a 'latest/recent trend monitoring' skill definition. This mismatch can steer the agent into collecting different datasets and making decisions based on undocumented behavior, undermining least-privilege expectations and increasing the chance of over-collection.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The implementation does not match the skill manifest: it creates and queries blogger published-post tasks, while the skill claims to fetch recent keyword-sorted notes for trend monitoring. This kind of capability mismatch is dangerous because users, reviewers, or orchestrators may grant permissions or rely on outputs under false assumptions, causing unintended data access and misleading results in an agent workflow.

Description-Behavior Mismatch

High
Confidence
91% confidence
Finding
The file implements a CLI that fetches comments for a specific Xiaohongshu note URL, while the declared skill scope is keyword-based recent trend monitoring. This capability mismatch is dangerous because it expands data collection beyond the user-declared purpose, enabling targeted harvesting of note-level discussion data that users and reviewers would not expect from the manifest.

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
Collecting comments from an individual note is broader and more intrusive than the stated trend-monitoring purpose, especially because comments can contain user-generated content that may include personal or sensitive information. In this skill context, the unjustified capability makes the implementation more dangerous because it enables targeted monitoring of a single post rather than aggregate topic analysis.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The implementation clearly operates on a blogger profile URL and retrieves that profile's posts, while the skill manifest says the skill should fetch recent notes under a keyword to monitor trends. This mismatch is dangerous because downstream agents or users may invoke the skill expecting broad keyword-trend data but instead collect profile-specific data, causing silent scope confusion, incorrect decisions, and possible misuse of personal/profile-targeted collection under false pretenses.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The help text and inline documentation repeatedly describe the tool as accepting a Xiaohongshu blogger profile link, which directly contradicts the manifest's stated purpose of keyword-based recent-note trend monitoring. This increases the risk of operational deception and misrouting: both humans and orchestrating agents can be led to use the tool for a different data-collection purpose than advertised.

Context-Inappropriate Capability

Low
Confidence
80% confidence
Finding
The skill persists full search output and the user keyword to a local file without any minimization, retention control, or indication of sensitivity. This can expose user queries and returned platform content to other local users, backup systems, or later unintended reuse, especially in shared or hosted execution environments.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger conditions are written very broadly, including vague phrases like wanting to know 'recent activity' or 'latest movement,' which may match many ordinary user requests. In agent environments, over-broad activation can route unrelated prompts into a data-exfiltrating skill that sends user-provided keywords or links to an external service without sufficiently specific user intent.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
Although the document mentions dependency on a third-party API later, the main functional sections do not prominently disclose that user-supplied links, keywords, and related data are transmitted to guaikei.com. This creates a transparency and privacy risk because operators may treat the skill as a local parser while it actually forwards inputs to an external service.

Missing User Warnings

Low
Confidence
71% confidence
Finding
The CLI persists full output, including request metadata and fetched results, to a local JSON file without user consent or an opt-out. If the returned content includes personal data, sensitive comments, or identifiers, this creates a local data-retention risk and can expose information to other local users, backups, or log collectors.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
Writing query data and full returned content to disk without explicit user notice creates a privacy and data-handling risk. Users may reasonably expect an ephemeral search operation, but the implementation silently creates durable artifacts that can be accessed after execution or collected by monitoring and backup tools.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:17