T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Credential Exposed in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly does what it says, but it needs Review because it sends an API token and target data to a third-party service in URL query strings and automatically saves retrieved results locally.
Install only if you are comfortable sending your GUAIKEI API token, Xiaohongshu URLs, keywords, and fetched public-content data to www.guaikei.com. Use a scoped/rotatable token if possible, avoid sensitive research targets, and check or delete the generated logs directory after use because successful results are saved automatically.
src/utils/request.js:76API Credential Exposed in URL Query Strings
声明描述的是一个面向小红书公开数据采集与分析的技能,但给出的代码片段仅实现了通用参数解析与帮助文本生成。这类代码可以作为配套基础设施,但当前片段本身不执行任何与小红书相关的核心功能,也不访问网络、解析页面、抓取评论或处理笔记数据。因此,就‘所 supplied code chunk 实际做什么’而言,与声明的主要用途存在明显不一致,应判定为 mismatch。
声明描述的是面向小红书公开内容的数据获取与分析能力,而这段代码实际仅实现了本地日志写入功能,没有体现搜索小红书、抓取笔记/评论/博主作品或返回结构化内容数据的行为。尽管日志功能可能属于辅助实现细节,但当前提供的代码块本身的主要行为是文件系统写入,这是一种声明中未提及的能力,并且与所述核心用途明显不一致。因此应判定为描述与代码行为不匹配。
The declared description presents a network/data collection skill focused on Xiaohongshu public content analysis. However, the supplied code chunk contains only a helper that accesses the local filesystem to read package.json and return the package name. This behavior does not implement or directly reflect the declared end-user functionality. While utility code can be a supporting detail, this specific chunk is unrelated to the stated purpose and instead performs a different, undeclared local file access operation.
Referenced artifact was not completely inspected
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |
Referenced artifact was not completely inspected
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |
Referenced artifact was not completely inspected
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |
The skill declares use of a sensitive environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool/permission scope such as allowed tools or permission boundaries. In an agent setting, missing scope declarations can let the skill access secrets or execution capabilities without clear user-visible constraints, increasing the chance of unintended secret use or command execution.
The skill explicitly states that Xiaohongshu links, keywords, and retrieved content are processed through a third-party API, but this disclosure appears only late in the document rather than in the main trigger/usage sections. Users may therefore provide potentially sensitive research targets, URLs, or content without realizing that data is being exfiltrated to an external service.
The README presents all user-facing instructions and operational guidance exclusively in Chinese. This can violate a language/locale policy when the skill forces a specific language without giving users an explicit choice or documenting that the skill is region-specific.
The title and throughout the document, the skill is presented entirely in Chinese with no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.
This code sends the provided API token as part of an HTTP request when creating a detail task. Although the function has technical docstrings, there is no user-facing warning, confirmation, or explicit disclosure here that credentials are being transmitted to a remote API.
The result-query function performs an HTTP GET containing the token, note URL, and limit parameters, which may expose user-provided or sensitive data to a remote service. The code includes retry error logging, but no user-facing notice that this transmission occurs.
This code sends the provided API token to a remote endpoint as part of the request parameters/body, which is a privacy- and credential-sensitive network operation. Although the functions have technical docstrings, there is no confirmation prompt, warning comment, or user-facing log indicating that the token will be transmitted.
The function performs a network call that includes both the API token and the target blogger URL in request parameters. This is a safety-relevant data transmission, but the file only contains internal comments and retry error logs, not a user-facing disclosure that these values are sent externally.
The user-facing strings are entirely in Chinese and the file provides no indication that language selection is configurable or based on user preference. This can violate language/locale policy when the skill is used in broader environments that have not explicitly opted into Chinese-only output.
The code emits user-facing status and error messages in Chinese only, such as the validation errors on these lines. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.
The 401/403 error path explicitly refers to GUAIKEI_API_TOKEN, indicating the skill depends on a sensitive credential, but this file does not include any warning, comment, or docstring about credential use or handling. Access to or reliance on sensitive credentials is in scope for missing-warning review when there is no visible disclosure.
The postJson and getJson helpers assemble request parameters and JSON bodies, then send them over HTTPS via request(), but the file contains no confirmation prompt, logging, comment, or docstring warning that user/system data may be transmitted to an external service. Because these helpers are generic and can carry arbitrary params/data, this is a safety-relevant network operation lacking visible disclosure in the code.
This code emits validation and error messages only in Chinese across the file, which enforces a specific language for user-facing interaction. The policy allows locale constraints only when users are given a choice or the restriction is clearly documented and justified, neither of which is present here.
The CLI persists fetched comment data to a local JSON file automatically after successful execution, but does not clearly disclose this behavior to the user or offer a way to disable it. Because comment results may contain usernames, profile references, and large volumes of scraped public content, silent local retention increases privacy, compliance, and data-handling risk on shared systems or in automated environments.
The CLI persists the full fetched note detail output to a local JSON file via log.taskWrite, but the skill description only promises returning structured data for analysis and does not disclose local retention. Because note details and comments may contain personal or sensitive user-generated content, silently writing them to disk increases data exposure, retention, and reuse risk on shared systems or in automated environments.
The code writes fetched detail results to a local JSON file without explicit notice or consent, creating hidden persistence of potentially sensitive comments, profile-linked content, or operational metadata. In agent or CI contexts, this can leave recoverable artifacts on disk long after the command finishes, broadening the attack surface beyond the immediate API response.
Detected: suspicious.exposed_secret_literal