T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:88- Finding
API Credential Exposed in HTTP Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real Xiaohongshu data tool, but it needs review because it sends credentials and target links to a third-party API and saves unredacted results locally.
Install only if you are comfortable sending Xiaohongshu keywords, links, and token-backed requests to guaikei.com. Keep GUAIKEI_API_TOKEN out of chats and shared logs, avoid running this in shared or CI workspaces, periodically delete the generated logs directory, and rotate the token if it may have been exposed.
src/utils/request.js:88API Credential Exposed in HTTP Query Strings
src/xiaohongshu/detail-cli.js:139Automatic Plaintext Persistence of Access-Bearing URLs and Retrieved Content
The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.
The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.
The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.
The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.
The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.
The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.
The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.
The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.
The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.
The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.
Referenced artifact was not completely inspected
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |
Referenced artifact was not completely inspected
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |
Referenced artifact was not completely inspected
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |
This module implements comment-task creation and retrieval, which goes beyond the stated skill scope of listing a creator’s public works and optionally checking single-note performance. Scope expansion is dangerous because it enables collection of additional user-generated content not disclosed in the manifest, increasing privacy, compliance, and misuse risk if the skill is invoked under narrower user expectations.
This script implements comment retrieval for a Xiaohongshu note, which exceeds the stated skill purpose of listing a creator's public works and identifying posting frequency or popular posts. Scope expansion matters because comments can contain third-party user content and potentially personal or sensitive data, so collecting them increases privacy, compliance, and misuse risk beyond the declared user expectation.
Without declared permissions the skill's intent is opaque and cannot be validated.
The natural-language instructions, usage guidance, and examples are presented only in Chinese, which effectively forces a specific language for users and AI operators. Under the stated policy, language constraints should be optional, user-selectable, or clearly justified as region-specific.
The skill manifest says this skill is for retrieving a Xiaohongshu creator’s public post list and explicitly says it is not for fan profiling or backend data. However, the package description and keywords advertise broader functions such as爆款笔记挖掘, 筛选高价值KOL, 精准营销, and 用户画像, which materially exceed the declared limited purpose of viewing a creator’s public works.
The README presents all user-facing instructions and usage guidance exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not stated here.
The README advertises substantially broader capabilities than the manifest description, including keyword search, note details, comment analysis, trend prediction, and KOL screening, while the declared skill scope is limited to retrieving a creator's public post list. This mismatch can cause an agent or user to invoke the skill for unintended data collection or analysis paths, weakening least-privilege expectations and increasing the chance of misuse or policy bypass.
The usage examples document multiple CLI operations beyond the manifest's single-purpose behavior, such as search, detail retrieval, and comment analysis. In an agent setting, contradictory operational instructions can lead to overbroad execution, accidental collection of extra public data, and user deception about what the installed skill is actually supposed to do.
The changelog states the skill now supports comment retrieval, keyword search, and note-detail capabilities, which materially exceed the published metadata claiming the skill is only for fetching a creator's public post list. This kind of scope mismatch can cause downstream agents or reviewers to authorize or invoke the skill under false assumptions, weakening security and compliance controls around what data the skill may access or process.
Detected: suspicious.exposed_secret_literal