Back to skill

Security audit

guaikei·小红书搜索

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to do what it claims, but it handles API credentials and saved Xiaohongshu result data in ways users should review before installing.

Install only if you trust Guaikei with your Xiaohongshu research targets and API token. Avoid using sensitive URLs or tokens in shared workspaces, rotate the Guaikei token if exposure is suspected, and regularly delete or protect the generated logs directory because it may contain full URLs, xsec_token values, keywords, comments, and profile data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:84
Finding

API Credential Exposed in URL Query Parameters

Content
View full analysis
{ return await postJson( "/api/xiaohongshu/note-search/keyword", { _: Date.now(), token: token }, { keyword, type, sort, time, limit }, ); }, ``` ```js async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new Error("path 必须是非空字符串"); } if (!params || typeof params !== "object") { throw new Error("params 必须是对象"); } if (!data || typeof data !== "object") { throw new Error("data 必须是对象"); } params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Content-Length": Buffer.byteLength(jsonData), }, }; return await request(options, jsonData); } ``` ```js async function getJson(path, params) { if (!path || typeof path !== "string") { throw new Error("path 必须是非空字符串"); } if (!params || typeof params !== "object") { throw new Error("params 必须是对象"); } params._ = Date.now(); const fullPath = `${path}?${querystring.stringify(params)}`; const options = { host: constants.BASE_URL, path: fullPath, method: "GET", headers: { "Content-Type": "application/json", }, }; return await request(options); } ``` ### Technical Analysis The `GUAIKEI_API_TOKEN` is included in the `params` object and serialized directly into the reque ...[truncated 1858 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/xiaohongshu/detail-cli.js:132
Finding

Automatic Plaintext Persistence of Full URLs and Retrieved Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (43)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This code chunk does not implement the declared Xiaohongshu data-retrieval functionality. Instead, it only contains generic configuration values, and the only concrete external resource mentioned is www.guaikei.com, which does not match the declared Xiaohongshu/xiaohongshu.com/xhslink.com focus. While config alone can be a supporting detail, the visible behavior/resource targeting here is inconsistent with the description, and there is no evidence of the core advertised capabilities in the supplied code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书公开内容采集与分析的技能,但给出的代码片段仅实现了通用参数解析和帮助文本生成功能。这种代码属于基础支撑组件,而不是所声明的核心业务行为。依据评估标准,若代码的主要目的与声明 materially different,应判定为不匹配。尽管这可能是项目中的一个辅助文件,但就“所 supplied code chunk 实际做什么”而言,它并未体现声明中的任何小红书数据访问或分析能力,因此应标记为描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个面向小红书公开内容采集与分析的技能,而实际代码仅是一个通用的本地日志写入辅助模块。它访问的是本地文件系统(创建目录、写文件),没有体现任何与小红书、网页抓取、内容搜索、评论拉取、博主作品获取或结构化数据返回相关的行为。虽然日志模块可能作为辅助实现存在,但就该代码片段本身而言,其功能与声明的核心目的明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
node src/xiaohongshu/detail-cli.js --url "<笔记链接>" [--limit N]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares use of an environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool scope such as allowed tools or permissions. That weakens containment and reviewability, making it easier for a runtime or future implementation to access secrets or capabilities beyond what users and reviewers expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation criteria are broad enough to match generic research and analysis requests, including indirect references like 'rednote' or URLs, which can cause the skill to trigger in situations where users did not intend third-party data retrieval. Over-broad routing increases the chance of unnecessary data disclosure to the external API and user confusion about what tool is being invoked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends user-supplied keywords, links, and retrieved content to a third-party API (guaikei.com), but that disclosure is mentioned only later under compliance notes rather than prominently in the main workflow. This is dangerous because users may share sensitive research targets, proprietary monitoring interests, or private-but-public URLs without realizing their inputs are being forwarded off-platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to supply note and profile URLs containing query parameters such as xsec_token, and to obtain a third-party API token, but it does not clearly disclose that these full URLs and parameters will be transmitted to an external service. This creates a transparency and privacy risk because users may unknowingly send tracking or access-related parameters to a vendor-controlled backend, which could expose browsing targets, tokens, or business-sensitive research activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document instructs operators to configure an API token and use the skill to fetch public Xiaohongshu notes, posts, and comments, but it does not clearly disclose that user-supplied URLs/keywords and retrieved content will be transmitted to an external service. Even when content is public, comments, profile links, and analysis targets may still create privacy, compliance, or data-handling concerns if users are not informed before use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This file contains natural-language comments and status/error strings in Chinese, starting with the module description and continuing through retry messages. Under the policy, forcing a specific language without user opt-in or justification can be a locale-policy violation, and this file does not indicate that the skill is intentionally limited to Chinese-language users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code sends a sensitive API token in HTTP requests when creating the search task, but this file only documents parameters for developers and includes no user-facing warning, confirmation, or disclosure about transmitting credentials to a remote API. For code files, outbound network transmission of sensitive data should have some visible disclosure unless clearly covered elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The function performs an HTTP GET request that transmits the API token together with the user's keyword and query options, but there is no visible user-facing warning, confirmation, or disclosure in the file. This is a safety-relevant network/data transmission operation under the code-file criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code emits user-facing error messages in Chinese only (for example at L07 and L11), and later success/error output also remains Chinese. The file provides no opt-in, language selection, or documented region-specific justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The success and failure messages at L35-L37 are also hardcoded in Chinese, reinforcing a mandatory single-language experience. Because no opt-in or explicit region-specific limitation is present in this file, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple hardcoded user-facing error strings are written only in Chinese, including request failures, timeout messages, and validation errors. The file does not offer language selection or document a justified locale restriction, which violates the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code constructs and sends HTTPS requests containing serialized parameters and request data to an external host, but the file provides no confirmation prompt, user-facing log/print, or explanatory comment/docstring warning that user or system data may be transmitted. Because network transmission is a safety-relevant operation under the rule, the lack of disclosure is a reportable issue in code files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The getJson function appends params to the URL query string and sends them over HTTPS to a remote host, which may expose user-provided or system-derived data. The file contains no user-facing warning, prompt, or explanatory comment indicating that such data is transmitted externally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language comments and error messages exclusively in Chinese, such as the function descriptions and validation errors. Under the language/locale policy, forcing a specific language without offering user choice or documenting a justified locale restriction can be a policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script reads GUAIKEI_API_TOKEN and sends the note URL and limit to external comment-task APIs through createCommentTask and getCommentTask. The help text mentions that the environment variable must be configured, but it does not explicitly warn users that their input URL and token-backed request data will be transmitted to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code persists the full task output, including request metadata and returned comment data, to a local file via log.taskWrite(...). Although the file prints progress messages, there is no explicit disclosure here that data will be saved to disk, which matters for a code path that writes potentially sensitive or privacy-relevant content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI persists fetched note details and comments to a local JSON file automatically, but the tool’s user-facing flow does not clearly warn that retrieved third-party content will be stored on disk. In this skill’s context, returned data may include user-generated comments, profile/work metadata, and research targets, so silent persistence can create unintended local data retention, privacy exposure, and compliance issues if the host environment is shared or logs/artifacts are collected.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16