Back to skill

Security audit

guaikei·小红书看笔记

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to retrieve public Xiaohongshu data as described, but its API token handling and automatic local result storage need review before installation.

Review before installing if you will use a real Guaikei token or handle sensitive research targets. Prefer a low-privilege or disposable API token, avoid shared workspaces, inspect and clean the logs directory after use, and confirm you are allowed to send the selected Xiaohongshu URLs or keywords to guaikei.com.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/api/search.js:20
Finding

API Credential Transmitted in URL Query Strings

Content
View full analysis

Vulnerability Details

File Location: src/api/search.js:20-28, src/api/search.js:49-60, src/api/detail.js:17-25, src/api/detail.js:43-52, src/api/comment.js:17-25, src/api/comment.js:43-52, src/api/post.js:17-25, src/api/post.js:43-52, and src/utils/request.js:85-90
Vulnerability Type: API credential exposure through query parameters
Risk Level: Medium

Vulnerable Code

The search task creation endpoint passes the API credential as a query parameter:

js
async function createSearchTask(token, keyword, type, sort, time, limit) {
  return await withRetry(
    async () => {
      return await postJson(
        "/api/xiaohongshu/note-search/keyword",
        { _: Date.now(), token: token },
        { keyword, type, sort, time, limit },
      );
    },
    constants.CREATE_MAX_ATTEMPTS,
    (attempt, err) => {
      utils.printError(
        `【创建任务重试】 ${attempt + 1}/${constants.CREATE_MAX_ATTEMPTS} 次 - ${err.message}`,
      );
    },
  );
}

The polling endpoint handles the credential in the same manner:

js
const res = await getJson("/api/xiaohongshu/note-search/info", {
  _: Date.now(),
  token: token,
  keyword,
  type,
  sort,
  time,
  limit,
});

Equivalent query-parameter credential handling occurs in the detail, comment, and post API modules:

js
return await postJson(
  "/api/xiaohongshu/detail/url",
  { _: Date.now(), token: token },
  { url: url, limit: limit },
);
js
const res = await getJson("/api/xiaohongshu/comment/info", {
  _: Date.now(),
  token: token,
  url,
  limit,
});
js
const res = await getJson("/api/xiaohongshu/post/info", {
  _: Date.now(),
  token: token,
  url,
  limit,
});

The request utility serializes these parameters directly into the request URL:

js
params.skill_name = skillName();
const fullPath = `${path}?${querystring.stringify
...[truncated 2114 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove token from all query-parameter objects.

  2. Send the credential through a dedicated authorization header, for example:

    js
    headers: {
      "Authorization": `Bearer ${token}`,
      "Content-Type": "application/json",
    }
    
  3. Refactor postJson and getJson to accept authentication separately from ordinary request parameters.

  4. Ensure request logging, error reporting, and telemetry redact Authorization, cookies, tokens, and other secrets.

  5. Configure the API gateway and origin server not to record authentication material.

  6. Rotate credentials that have already been used by this implementation because they may exist in historical logs.

  7. Prefer short-lived, narrowly scoped tokens and enforce rate limits to reduce the impact of credential reuse.

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:25
Finding

Automatic Plaintext Persistence of Complete API Results

Content
View full analysis

Vulnerability Details

File Location: src/xiaohongshu/search-cli.js:207-210, src/xiaohongshu/detail-cli.js:157-160, src/xiaohongshu/comment-cli.js:157-160, src/xiaohongshu/post-cli.js:159-162, and src/utils/log.js:4-35
Vulnerability Type: Insecure local storage and excessive data retention
Risk Level: Low

Vulnerable Code

Each successful command automatically serializes and stores its complete output. For example, the search command performs the following write:

js
await log.taskWrite(
  `${startTime}_${keyword}_${type}_${sort}_${limit}_search.json`,
  JSON.stringify(finalOutput, null, 2),
);

The detail, comment, and post commands behave equivalently:

js
await log.taskWrite(
  `${startTime}_${validator.url2Name(url)}_detail.json`,
  JSON.stringify(finalOutput, null, 2),
);
js
await log.taskWrite(
  `${startTime}_${validator.url2Name(url)}_comment.json`,
  JSON.stringify(finalOutput, null, 2),
);
js
await log.taskWrite(
  `${startTime}_${validator.url2Name(url)}_post.json`,
  JSON.stringify(finalOutput, null, 2),
);

The logging utility creates a project-local logs directory and writes plaintext files using default permissions:

js
const outputFilename = path.join(
  path.dirname(__filename),
  "..",
  "..",
  "logs",
  safeFilename,
);

try {
  await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true });
  await fs.promises.writeFile(outputFilename, content);
  utils.printSuccess(`  → 已保存到 ${outputFilename}`);
} catch (error) {
  utils.printError(`日志写入失败: ${error.message}`);
}

Technical Analysis

Successful API responses are persisted automatically rather than only being returned through standard output. The stored JSON can contain search keywords, source URLs, Xiaohongshu xsec_token values, comments, creator information, note content, and interaction data.

The files are: ...[truncated 1703 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make file persistence opt-in through an explicit option such as --output PATH or --save.

  2. Default to standard-output delivery without creating local files.

  3. Clearly disclose when, where, and for how long results are stored.

  4. When persistence is requested, create files with restrictive permissions:

    js
    await fs.promises.writeFile(outputFilename, content, {
      encoding: "utf8",
      mode: 0o600,
    });
    
  5. Create the containing directory with restrictive permissions such as 0o700.

  6. Redact or omit xsec_token values and other unnecessary identifiers before persistence.

  7. Add configurable retention and secure deletion procedures.

  8. Ensure logs/ is excluded from version control, build artifacts, support bundles, and automated uploads.

  9. For sensitive deployments, allow storage in a user-selected protected directory or encrypt persisted output using managed keys.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (53)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的核心能力是面向“博主/账号”层面的公开作品列表抓取,并结合详情与评论做节奏、风格、互动分析;这要求至少具备从博主主页枚举作品的能力。当前代码块只处理单个笔记URL的详情与评论任务创建和结果查询,属于声明中提到的一个子能力,但不足以支撑其主要宣称用途。代码也没有显示登录态或私密数据访问,因此这部分与声明不冲突;主要问题是实际行为比声明显著更窄,且主用途从‘博主账号分析’变成了‘单笔记详情/评论获取’。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明强调的是“博主维度”的竞品分析能力:输入博主主页链接,抓取其公开作品列表,并进一步结合详情和评论进行分析。当前代码片段的核心功能却是调用 /note-search/keyword 和 /note-search/info 接口进行关键词搜索任务创建与结果获取,属于“内容搜索”能力。它只是对搜索结果中的笔记和用户拼接URL,方便访问,并没有展示任何根据博主主页链接枚举其作品、拉取单篇详情、抓取评论或分析发文节奏/互动表现的实现。因此,这段代码的主要行为与声明用途存在实质性不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向小红书博主公开内容抓取与分析的技能,核心能力应包括访问小红书相关资源、获取作品列表/详情/评论并做内容表现分析。但实际代码仅是独立的通用 CLI 参数解析模块,负责读取命令行参数、校验 flag、处理默认值和生成帮助文本。这属于基础支撑工具,而不是所声明的主要业务功能。由于当前代码块的实际行为与声明的核心用途明显不一致,应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个面向小红书公开数据抓取与内容分析的技能,但提供的代码片段实际只负责 TOKEN 管理,并带有商业化/接入提示信息。该代码既没有执行小红书主页、作品、笔记详情或评论抓取,也没有进行内容表现分析。因此其实际行为与声明用途在当前代码片段中明显不一致。虽然 TOKEN 管理可能是配套实现,但此片段本身的直接功能与声明的核心能力相距较大,属于描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书公开数据抓取与竞品分析的技能,但提供的代码片段并未体现任何抓取、解析小红书作品/详情/评论、账号分析或网络访问行为。相反,它执行的是本地日志文件写入,这是与声明主目的明显不同的能力。虽然日志功能可能作为辅助实现存在,但当前片段只展示了日志落盘能力,且该能力未在声明中体现,因此就该代码片段与声明的一致性而言,存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on collecting and analyzing public Xiaohongshu account content. The actual code chunk is a small utility that reads package.json from the local filesystem and returns the package name. That behavior is materially unrelated to the declared primary purpose. While this could be a benign helper within a larger skill, based on the supplied chunk alone, the implemented behavior does not match the stated functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个面向小红书博主/竞品分析的数据抓取与分析技能,核心能力应包括访问博主主页、获取作品列表、抓取笔记详情与评论,并据此做内容表现分析。而提供的代码片段只处理通用“搜索关键词”输入的合法性检查、字符清洗,以及搜索参数取值修正,属于搜索模块的辅助校验逻辑。该代码既没有体现对博主主页链接的处理,也没有任何网络请求、数据抓取、评论读取或分析行为。因此其实际行为与声明的主要用途存在明显不一致,属于实质性功能不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明的核心用途是博主/账号层面的竞品分析,需要抓取博主公开作品列表并结合多篇笔记数据进行还原分析。但该代码片段只处理单条“笔记链接”,调用 detail 接口创建详情任务并获取该笔记及评论,且参数帮助信息和 URL 校验都明确限定为 note URL,不是博主主页 URL。代码没有展示作品列表抓取、博主主页解析、跨多篇笔记汇总分析或节奏统计等账号级能力。因此其实际行为与声明的主要目的存在明显偏差。与此同时,代码访问的是公开笔记数据,并未表现出登录态或私密数据访问,这部分与声明一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

声明描述的是一个较完整的竞品分析型技能:不仅抓取公开作品列表,还要配合笔记详情与评论来还原内容与互动表现。而这段代码实际只是 post CLI 入口,接受主页 URL 和数量限制,调用 createPostTask/getPostTask 获取“主页笔记”结果并输出 JSON、记录日志。就该代码可见行为而言,它主要完成的是公开主页笔记列表任务的提交与结果获取,没有看到评论、详情抓取或任何分析逻辑。因此其实际能力明显比声明更窄,属于描述与代码行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明的核心能力是‘博主账号分析’,输入应围绕博主主页链接或博主身份,输出应包含作品列表、详情、评论及分析指标。而代码实际是一个 search-cli,仅接受 keyword/type/sort/time/limit 等搜索参数,调用 search.createSearchTask 和 search.getSearchTask 执行关键词搜索,并返回搜索结果。代码没有任何博主主页解析、作者作品枚举、详情抓取、评论抓取或分析逻辑。因此其主要用途与声明存在实质性不符。日志写入和 token 使用属于实现细节,不构成额外问题;真正的 mismatch 在于技能被描述为‘博主竞品分析’,但代码只是‘关键词搜索’。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
node src/xiaohongshu/detail-cli.js --url "<笔记链接>" [--limit N]

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

清单描述将技能定位为针对给定小红书博主主页链接,抓取其公开作品列表并结合详情与评论进行竞品账号/博主内容表现分析。但该文件暴露的主能力是通过 --keyword 执行通用关键词搜索,按内容类型、排序、发布时间和数量检索结果,并未围绕博主主页链接或单一博主作品列表展开,语义上超出了声明的账号分析范围。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description permits invocation based on broad contextual cues rather than a clear, explicit user request, including competitor-monitoring of a blogger homepage. In an agent setting, this increases the risk of over-collection and sending third-party profile URLs and analysis targets to an external API without sufficiently specific user intent or informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger phrases are very broad everyday language, which can cause the skill to activate in ambiguous contexts and perform external data retrieval beyond what the user specifically requested. In an agent ecosystem, overly permissive routing increases the chance of unnecessary third-party data access and unintended reconnaissance-style use against competitor accounts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The package description and keywords are entirely in Chinese and narrowly target the Xiaohongshu platform, which indicates a fixed language/locale presentation in natural-language metadata. The file does not offer any language choice or document a justified region-specific constraint, so this appears to violate the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest scope is focused on抓取博主公开作品列表并结合笔记详情与评论,还原发文节奏、内容风格与互动表现, i.e. competitor-account/post monitoring from a creator profile link. The README instead presents the skill as a general 小红书数据挖掘 tool supporting keyword search, trend prediction, hot-topic monitoring, and KOL筛选, which materially exceeds the stated purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation advertises four data-collection capabilities, including keyword search, note-detail retrieval, and comment harvesting, while the declared skill scope is limited to blogger public-post analysis. This mismatch expands operational scope without corresponding user expectations, review coverage, or policy guardrails, increasing the chance the agent is invoked for broader scraping and analysis than intended.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The keyword-search section enables collection of public content outside the stated use case of competitor-account or blogger monitoring. That creates an undocumented broad-search surface that can be used for generalized scraping, topic surveillance, or bulk content collection beyond what users and reviewers would infer from the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document encourages scraping and processing third-party public posts, note details, and comments but provides no warning about privacy expectations, platform terms, lawful basis, retention, or downstream handling of collected data. Even when content is public, large-scale aggregation, competitor monitoring, and comment analysis can create compliance, misuse, and reputational risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This function sends an API token and note URL to a remote endpoint via postJson, but the code only contains developer-facing parameter docs and retry error logging. There is no confirmation prompt, user-facing notice, or explicit warning in this file that user or system data will be transmitted externally.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16