Back to skill

Security audit

guaikei·小红书竞品监控

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Xiaohongshu data tool, but it needs review because it sends credentials and target links to a third-party API and saves unredacted results locally.

Install only if you are comfortable sending Xiaohongshu keywords, links, and token-backed requests to guaikei.com. Keep GUAIKEI_API_TOKEN out of chats and shared logs, avoid running this in shared or CI workspaces, periodically delete the generated logs directory, and rotate the token if it may have been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:88
Finding

API Credential Exposed in HTTP Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/xiaohongshu/detail-cli.js:139
Finding

Automatic Plaintext Persistence of Access-Bearing URLs and Retrieved Content

Content
View full analysis
Remediation
View remediation
` or `--save`. 2. Do not automatically write successful responses when no output option is supplied. 3. Redact sensitive query parameters before console output or file persistence. At minimum, remove or replace: - `xsec_token` - `token` - `api_key` - Other authentication or session parameters returned by upstream services 4. Use the standard `URL` API to perform structured redaction rather than string replacement: ```js function redactUrl(value) { const parsed = new URL(value); for (const name of ["xsec_token", "token", "api_key"]) { if (parsed.searchParams.has(name)) { parsed.searchParams.set(name, "[REDACTED]"); } } return parsed.toString(); } ``` 5. Recursively sanitize result objects before serialization because token-bearing URLs may occur in nested result fields. 6. If files must be retained, create the directory and files with restrictive permissions: ```js await fs.promises.mkdir(logDirectory, { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, content, { mode: 0o600, flag: "wx", }); ``` 7. Document retention periods and provide a cleanup command or automatic expiration policy. 8. Exclude `logs/` from version control, package publication, CI artifact collection, and cloud synchronization by default. 9. Warn users before saving comment datasets or other potentially sensitive research outputs to shared environments. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (62)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation states a profile-based creator-listing skill, yet it also includes keyword-driven content search with sort/time/type filters. This can bypass expectations about targeting a known creator and turns the skill into a general content discovery tool, increasing data-handling scope beyond what is declared.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This module implements comment-task creation and retrieval, which goes beyond the stated skill scope of listing a creator’s public works and optionally checking single-note performance. Scope expansion is dangerous because it enables collection of additional user-generated content not disclosed in the manifest, increasing privacy, compliance, and misuse risk if the skill is invoked under narrower user expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This script implements comment retrieval for a Xiaohongshu note, which exceeds the stated skill purpose of listing a creator's public works and identifying posting frequency or popular posts. Scope expansion matters because comments can contain third-party user content and potentially personal or sensitive data, so collecting them increases privacy, compliance, and misuse risk beyond the declared user expectation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language instructions, usage guidance, and examples are presented only in Chinese, which effectively forces a specific language for users and AI operators. Under the stated policy, language constraints should be optional, user-selectable, or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill manifest says this skill is for retrieving a Xiaohongshu creator’s public post list and explicitly says it is not for fan profiling or backend data. However, the package description and keywords advertise broader functions such as爆款笔记挖掘, 筛选高价值KOL, 精准营销, and 用户画像, which materially exceed the declared limited purpose of viewing a creator’s public works.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README presents all user-facing instructions and usage guidance exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not stated here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises substantially broader capabilities than the manifest description, including keyword search, note details, comment analysis, trend prediction, and KOL screening, while the declared skill scope is limited to retrieving a creator's public post list. This mismatch can cause an agent or user to invoke the skill for unintended data collection or analysis paths, weakening least-privilege expectations and increasing the chance of misuse or policy bypass.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The usage examples document multiple CLI operations beyond the manifest's single-purpose behavior, such as search, detail retrieval, and comment analysis. In an agent setting, contradictory operational instructions can lead to overbroad execution, accidental collection of extra public data, and user deception about what the installed skill is actually supposed to do.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The changelog states the skill now supports comment retrieval, keyword search, and note-detail capabilities, which materially exceed the published metadata claiming the skill is only for fetching a creator's public post list. This kind of scope mismatch can cause downstream agents or reviewers to authorize or invoke the skill under false assumptions, weakening security and compliance controls around what data the skill may access or process.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16