T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:87- Finding
API Credential Exposed in Request URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its Xiaohongshu public-data purpose, but needs review because it sends its API token in URL query strings and saves fetched datasets locally by default.
Install only if you trust the Guaikei service and are comfortable sending Xiaohongshu keywords, URLs, and your GUAIKEI_API_TOKEN to it. Treat saved logs as potentially sensitive research data, delete them when no longer needed, and prefer an environment where the token and output files are not exposed to other users or automated artifact collection.
src/utils/request.js:87API Credential Exposed in Request URL Query Strings
src/utils/log.js:23Successful API Results Are Automatically Persisted Without Explicit User Opt-In
Based on the supplied code chunk alone, the implementation does not match the declared purpose. The description claims a Xiaohongshu public-data retrieval skill, but the code only exports configuration values and references a different domain, www.guaikei.com. There is no evidence in this chunk of searching Xiaohongshu, parsing note details, collecting comments, or listing a blogger’s posts. While this may be only a partial file, the requested comparison is against the supplied chunk, and that chunk does not substantiate the declared behavior and points to an inconsistent resource.
代码块仅包含 parseArgs、readValueAfterFlag 和 buildHelp 等通用参数处理函数,属于基础支持工具。它不会连接小红书、解析链接、抓取公开笔记或评论,也没有任何网络请求、页面访问、数据提取或平台特定逻辑。由于声明描述的核心能力是小红书公开数据获取与分析,而代码实际功能只是 CLI 参数解析,这构成了明显的描述与行为不一致。
The declared purpose describes a network/data-access skill focused on collecting structured public Xiaohongshu content. The actual code chunk does not interact with Xiaohongshu, perform searches, fetch notes/comments, scrape creator pages, or return structured analytics data. Instead, it provides a supporting logging function that writes arbitrary content to local files under a logs directory. Because the observed behavior is materially different from the declared primary purpose and introduces an undeclared local file write capability, this is a mismatch.
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
node src/xiaohongshu/detail-cli.js --url "<笔记链接>" [--limit N]
The skill declares use of an environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool/permission scope such as allowed tools or permissions. In practice, this creates ambiguous execution boundaries and increases the chance that a host agent exposes secrets or grants broader execution capability than intended when invoking the skill.
The activation text is broad enough to trigger on vague mentions like 'xhs', '红笔记', links, or generic requests for content data, which can cause the agent to invoke this skill outside the user's clear intent. Over-broad routing is risky because the skill sends user-provided keywords or URLs to an external third-party API, potentially causing unintended data disclosure or misuse of credentials.
This code file contains natural-language documentation and runtime messages exclusively in Chinese, such as the module description and retry logs. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless a locale restriction is explicitly justified, which is not present here.
The function sends the provided token as part of an HTTP request, which is a sensitive credential transmission. Although the code has technical docstrings, they describe the parameter generically and do not warn users that their API token will be sent to a remote endpoint.
This JavaScript file contains user-facing and developer-facing natural-language strings exclusively in Chinese, including error messages and generated help text. Per the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the restriction is explicitly justified, which is not present here.
This code emits all user-facing warning and informational messages in Chinese, including operational guidance for obtaining a token. That creates a language/locale policy concern because the skill does not offer user opt-in, fallback language handling, or any documented justification that it is intended only for a Chinese-speaking or region-specific audience.
This code includes user-facing status and error strings in Chinese, which imposes a specific language on all users. The file provides no opt-in, fallback, or indication that the skill is intentionally limited to a Chinese-speaking or region-specific context.
Multiple user-visible error strings in this file are hardcoded in Chinese, including parsing, timeout, and credential-related messages. The policy requires avoiding forced language or locale unless the skill offers user choice or clearly documents a justified locale restriction, which is not present here.
This JavaScript file contains comments and all user-facing error messages exclusively in Chinese, such as at L4-L5 and L8, L13, L17, L21, L25-L26, L54, L59, L64, and L68. Under the stated policy, forcing a specific language without offering a language or locale choice is a natural-language policy violation.
The CLI persists full comment-task output to a local JSON file named from the target URL, but this file gives no explicit notice, consent flow, retention control, or redaction before writing. Because the skill is designed to collect structured Xiaohongshu comment data for analysis, the saved results may include user-generated content and metadata that can persist on disk longer than expected, increasing privacy, compliance, and local data-exposure risk if the host is shared or logs are later exfiltrated.
The code calls detail.createDetailTask and detail.getDetailTask with the user-provided URL and limit, which transmits user input to a remote service. The help text mentions the required API token but does not warn that the supplied URL and related request data will be sent to an external service for processing.
The tool silently stores fetched note details plus request metadata to a local JSON file without an explicit user-facing warning or consent. This can leak research targets, collected comments, and operational context to local disk, shell environments, shared workstations, endpoint monitoring tools, or backup systems, which is a privacy and data-handling risk.
The manifest says the skill can search notes, view note details/comments, get comment data, and fetch a blogger's public works list. In this file, the flag description at L018 says '小红书博主链接', validation at L071-L078 enforces a profile URL, and the API flow at L088-L091 creates/gets a 'post' task for a creator homepage; however the example invocation and positional placeholder at L035-L037 are presented under a generic 'url' argument and the file name 'post-cli' may imply note-level handling. More importantly, this command's effective behavior is specifically profile-post-list retrieval, not arbitrary note retrieval.
Writing fetched results to disk without any user-facing warning or confirmation creates an unexpected data persistence side effect. In the context of a scraping/data-analysis skill, this can expose collected datasets beyond the immediate session, increasing privacy, compliance, and local confidentiality risks even if the source data is public.
The CLI persists full search output to a local JSON file, which can include user-supplied keywords and scraped public-content metadata without any opt-in, minimization, or retention controls. On shared systems or in automated environments, this creates unnecessary data exposure through local artifacts, backups, or later reuse, especially given the skill’s data-collection and monitoring use case.
The example trigger phrases are not tightly constrained to Xiaohongshu-specific contexts, which can contribute to accidental invocation and unnecessary transmission of user input to the third-party service. While lower severity than explicit command injection or secret leakage, ambiguous examples increase the attack surface for prompt-routing mistakes and user surprise.
The package description is entirely in Chinese, which creates a natural-language locale constraint in user-facing metadata. There is no accompanying indication that the skill is intentionally region-specific or that alternative language support is available.
Detected: suspicious.exposed_secret_literal