Back to skill

Security audit

xhs-dashboard-build

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it advertises, but it handles API credentials and saved results in ways users should review before installing.

Review this before installing if the GuaiKei token is valuable or used for paid quota. Use a dedicated low-privilege token, avoid running it in shared workspaces, delete or protect the logs directory, and be aware that queried Xiaohongshu URLs and returned datasets are sent to www.guaikei.com and saved locally.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:82
Finding

API Credential Exposed in URL Query Strings

Content
View full analysis
``` TLS protects the complete request path while it is in transit, but URL query strings are frequently recorded by destination servers, reverse proxies, web application firewalls, observability systems, access logs, debugging tools, and error-reporting platforms. Consequently, the credential can be exposed to more systems and operators than necessary. The query APIs can retry up to 20 times, which may cause the credential-bearing URL to be processed and recorded repeatedly. The token is not printed in normal CLI output, but placing it in the URL remains an insecure credential transport mechanism. ### Attack Path 1. A user config ...[truncated 1190 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:27
Finding

Automatic Plaintext Retention of Retrieved Data and Tokenized URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (42)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for a Xiaohongshu data collection and analysis tool. However, the provided code does not perform any Xiaohongshu-related operations, network access, scraping, searching, comment retrieval, or analytics. It is only a reusable utility for parsing CLI arguments and generating help text. While such a parser could support a larger Xiaohongshu tool, this chunk's actual behavior is purely generic infrastructure and does not match the declared functional purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是面向小红书公开内容抓取与分析的数据工具,但给出的代码片段实际只实现了本地日志文件写入功能,没有任何与小红书搜索、笔记详情、评论获取、博主作品抓取或数据分析相关的逻辑。虽然日志记录可能是辅助功能,但当前片段本身体现的主要行为与声明的核心用途无直接对应;同时它涉及本地文件系统写入这一声明中未体现的能力。因此该代码片段与技能描述存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书公开内容检索与分析的完整数据工具,但给出的代码片段仅包含一个读取本地 package.json 文件并返回包名的辅助函数。该代码既没有体现任何对小红书数据的访问、抓取、搜索或分析逻辑,也没有与声明用途直接相关的网络请求、解析、查询或评论处理行为。虽然读取 package.json 可能只是内部辅助实现,但就当前代码片段可见行为而言,其实际功能与声明的核心用途明显不一致,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding

The skill declares access to a sensitive environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege guarantees and can let the skill consume secrets without a clearly bounded execution policy, which is risky for a third-party integration skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states that all task results are automatically saved to the local logs/ directory, but it does not clearly warn users what data will be persisted, how long it will be retained, or whether scraped note/comment data, URLs, and keywords may contain sensitive business intelligence. In the context of competitor monitoring and comment analysis, automatic persistence increases the chance of unintended local data exposure, over-retention, and accidental sharing of harvested datasets.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents its content entirely in Chinese starting with the title '技能更新日志', with no indication that other languages are available or that the locale restriction is intentional. Under the language/locale policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation tells the operator to configure GUAIKEI_API_TOKEN but does not clearly disclose that the skill will read this credential and use it in outbound requests to a third-party service. This creates a transparency and consent issue: users may supply a secret without understanding its scope, where it is sent, or how it is handled, increasing the risk of unintended credential exposure or trust abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code sends an API token and note URL to a remote endpoint via postJson, which is a network operation involving potentially sensitive user or system data. Although the function has developer-facing docstrings and retry logging, there is no user-facing warning, confirmation, or disclosure in this file that the token and URL will be transmitted externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code performs a GET request that includes the API token, URL, and limit as request parameters to a remote endpoint. The comments describe parameters for developers, but they do not provide end-user disclosure that this data will be sent over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JavaScript file contains natural-language documentation exclusively in Chinese, including the module description and parameter documentation, without any indication that the skill is region-specific or that users can choose another language. Under the policy rule, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JavaScript file uses Chinese-only natural-language documentation and runtime messages, including module descriptions and retry/error text, with no indication that the skill is region-specific or that users can opt into another language. Under the policy, a skill that forces a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Multiple user-visible error messages in this file are hardcoded in Chinese, including credential and network failure text, with no indication that the skill is region-specific or that users can opt into another language. This creates a language/locale policy issue because the skill forces a specific language in its natural-language outputs without documented justification or user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The postJson and getJson helpers build HTTPS requests from caller-supplied params and data and send them to a remote host via request(), but the file contains no confirmation prompt, logging, or comment/docstring disclosing that user or system data may be transmitted off-box. Because this is a code file with network transmission behavior, the lack of any visible warning meets the missing-user-warning criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits all validation and error messages in Chinese, which imposes a specific language on users. The file does not indicate that the skill is region-specific or provide any opt-in or alternative locale handling, so it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.