Back to skill

Security audit

guaikei·小红书找笔记

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Xiaohongshu public-data purpose, but needs review because it sends its API token in URL query strings and saves fetched datasets locally by default.

Install only if you trust the Guaikei service and are comfortable sending Xiaohongshu keywords, URLs, and your GUAIKEI_API_TOKEN to it. Treat saved logs as potentially sensitive research data, delete them when no longer needed, and prefer an environment where the token and output files are not exposed to other users or automated artifact collection.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:87
Finding

API Credential Exposed in Request URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:23
Finding

Successful API Results Are Automatically Persisted Without Explicit User Opt-In

Content
View full analysis
Remediation
View remediation
` or `--save`. 2. If local storage is required, create files with owner-only permissions: ```javascript await fs.promises.writeFile(outputFilename, content, { mode: 0o600 }); ``` 3. Create the `logs` directory with restrictive permissions, such as `0700`. 4. Avoid placing search keywords or other user data in filenames; use a random identifier or timestamp instead. 5. Define and document a retention period, and provide automatic cleanup or a deletion command. 6. Exclude the logs directory from source-control commits, build artifacts, support bundles, and automated uploads. 7. Warn users before saving returned datasets and clearly identify the destination. 8. Consider field-level redaction for platform tokens, URLs, identifiers, or other data not required in stored output. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Based on the supplied code chunk alone, the implementation does not match the declared purpose. The description claims a Xiaohongshu public-data retrieval skill, but the code only exports configuration values and references a different domain, www.guaikei.com. There is no evidence in this chunk of searching Xiaohongshu, parsing note details, collecting comments, or listing a blogger’s posts. While this may be only a partial file, the requested comparison is against the supplied chunk, and that chunk does not substantiate the declared behavior and points to an inconsistent resource.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码块仅包含 parseArgs、readValueAfterFlag 和 buildHelp 等通用参数处理函数,属于基础支持工具。它不会连接小红书、解析链接、抓取公开笔记或评论,也没有任何网络请求、页面访问、数据提取或平台特定逻辑。由于声明描述的核心能力是小红书公开数据获取与分析,而代码实际功能只是 CLI 参数解析,这构成了明显的描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose describes a network/data-access skill focused on collecting structured public Xiaohongshu content. The actual code chunk does not interact with Xiaohongshu, perform searches, fetch notes/comments, scrape creator pages, or return structured analytics data. Instead, it provides a supporting logging function that writes arbitrary content to local files under a logs directory. Because the observed behavior is materially different from the declared primary purpose and introduces an undeclared local file write capability, this is a mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
node src/xiaohongshu/detail-cli.js --url "<笔记链接>" [--limit N]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares use of an environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool/permission scope such as allowed tools or permissions. In practice, this creates ambiguous execution boundaries and increases the chance that a host agent exposes secrets or grants broader execution capability than intended when invoking the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation text is broad enough to trigger on vague mentions like 'xhs', '红笔记', links, or generic requests for content data, which can cause the agent to invoke this skill outside the user's clear intent. Over-broad routing is risky because the skill sends user-provided keywords or URLs to an external third-party API, potentially causing unintended data disclosure or misuse of credentials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language documentation and runtime messages exclusively in Chinese, such as the module description and retry logs. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless a locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function sends the provided token as part of an HTTP request, which is a sensitive credential transmission. Although the code has technical docstrings, they describe the parameter generically and do not warn users that their API token will be sent to a remote endpoint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JavaScript file contains user-facing and developer-facing natural-language strings exclusively in Chinese, including error messages and generated help text. Per the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits all user-facing warning and informational messages in Chinese, including operational guidance for obtaining a token. That creates a language/locale policy concern because the skill does not offer user opt-in, fallback language handling, or any documented justification that it is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code includes user-facing status and error strings in Chinese, which imposes a specific language on all users. The file provides no opt-in, fallback, or indication that the skill is intentionally limited to a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Multiple user-visible error strings in this file are hardcoded in Chinese, including parsing, timeout, and credential-related messages. The policy requires avoiding forced language or locale unless the skill offers user choice or clearly documents a justified locale restriction, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JavaScript file contains comments and all user-facing error messages exclusively in Chinese, such as at L4-L5 and L8, L13, L17, L21, L25-L26, L54, L59, L64, and L68. Under the stated policy, forcing a specific language without offering a language or locale choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI persists full comment-task output to a local JSON file named from the target URL, but this file gives no explicit notice, consent flow, retention control, or redaction before writing. Because the skill is designed to collect structured Xiaohongshu comment data for analysis, the saved results may include user-generated content and metadata that can persist on disk longer than expected, increasing privacy, compliance, and local data-exposure risk if the host is shared or logs are later exfiltrated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code calls detail.createDetailTask and detail.getDetailTask with the user-provided URL and limit, which transmits user input to a remote service. The help text mentions the required API token but does not warn that the supplied URL and related request data will be sent to an external service for processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The tool silently stores fetched note details plus request metadata to a local JSON file without an explicit user-facing warning or consent. This can leak research targets, collected comments, and operational context to local disk, shell environments, shared workstations, endpoint monitoring tools, or backup systems, which is a privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says the skill can search notes, view note details/comments, get comment data, and fetch a blogger's public works list. In this file, the flag description at L018 says '小红书博主链接', validation at L071-L078 enforces a profile URL, and the API flow at L088-L091 creates/gets a 'post' task for a creator homepage; however the example invocation and positional placeholder at L035-L037 are presented under a generic 'url' argument and the file name 'post-cli' may imply note-level handling. More importantly, this command's effective behavior is specifically profile-post-list retrieval, not arbitrary note retrieval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Writing fetched results to disk without any user-facing warning or confirmation creates an unexpected data persistence side effect. In the context of a scraping/data-analysis skill, this can expose collected datasets beyond the immediate session, increasing privacy, compliance, and local confidentiality risks even if the source data is public.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI persists full search output to a local JSON file, which can include user-supplied keywords and scraped public-content metadata without any opt-in, minimization, or retention controls. On shared systems or in automated environments, this creates unnecessary data exposure through local artifacts, backups, or later reuse, especially given the skill’s data-collection and monitoring use case.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example trigger phrases are not tightly constrained to Xiaohongshu-specific contexts, which can contribute to accidental invocation and unnecessary transmission of user input to the third-party service. While lower severity than explicit command injection or secret leakage, ambiguous examples increase the attack surface for prompt-routing mistakes and user surprise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The package description is entirely in Chinese, which creates a natural-language locale constraint in user-facing metadata. There is no accompanying indication that the skill is intentionally region-specific or that alternative language support is available.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16