Back to skill

Security audit

xhs-competitor-watch

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Xiaohongshu public-data research tool that calls a third-party API and saves local result logs, with no evidence of hidden or destructive behavior.

Install only if you are comfortable sending Xiaohongshu keywords or links, the API token, and returned public-data results to guaikei.com, and with saved result files remaining in the skill's local logs directory until you delete them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding
The documented purpose does not fully match the described behavior: the skill fetches note details/comments, writes results to local logs, and does less analysis than advertised. This matters because undocumented data collection and local persistence can expose sensitive or regulated content, surprise operators about third-party data egress and retention, and reduce informed consent when enabling the skill.

Description-Behavior Mismatch

Medium
Confidence
79% confidence
Finding
This module adds functionality to retrieve full note details and comments, including note/user identifiers and reconstructed profile URLs, which goes beyond the stated competitor-monitoring scope centered on search, creator post lists, and comparative analytics. In a data-collection skill, this scope expansion increases privacy and data-minimization risk because it enables collection of richer content and user-linked data than users may reasonably expect from the manifest.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The CLI sends user-supplied profile URLs and fetched results to an external API and also persists the returned data locally via log.taskWrite, but it does not provide a clear user-facing disclosure or consent prompt about transmission and storage. In a competitor-monitoring context, this can unintentionally expose monitored account data, query parameters, or business research artifacts to third-party services and local disk where they may be retained longer than expected.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The CLI writes full search results to a local JSON file using a filename derived in part from user input, but does not clearly disclose this persistence behavior to the user at execution time. In a competitor-monitoring context, the saved results may contain sensitive business intelligence, queried keywords, and usage metadata that can remain on disk longer than intended and be exposed to other local users, backups, or later collection by unrelated processes.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.