T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Credential Transmitted in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to do the Xiaohongshu research it advertises, but it handles API tokens and saved result data in ways users should review before installing.
Install only if you are comfortable sending Xiaohongshu links, search terms, and a Guaikei API token to the Guaikei service. Treat generated logs as sensitive: they may contain research targets, comments, profile data, and xsec_token URLs, so delete or protect them and avoid committing logs to source control. Prefer a version that moves the API token out of query strings and supports opt-in or redacted logging.
src/utils/request.js:76API Credential Transmitted in URL Query Strings
src/xiaohongshu/detail-cli.js:137Automatic Plaintext Persistence of Results and Access-Bearing URLs
The declared purpose centers on accessing public Xiaohongshu content and analyzing it. However, the supplied code chunk is only a constants file and sets BASE_URL to www.guaikei.com, which is not one of the declared Xiaohongshu-related domains (xiaohongshu.com/xhslink.com). While configuration code alone can be supportive, this chunk provides no evidence of the promised Xiaohongshu functionality and instead references an apparently different resource, which is inconsistent with the description. Therefore, this is best flagged as a mismatch based on the inconsistent target resource and absence of matching behavior in the provided code.
声明描述的是一个面向小红书公开内容采集与分析的技能,而给出的代码片段仅是与业务无关的基础工具模块,用于解析命令行参数和生成帮助文本。虽然这类工具可能作为更大系统的辅助组件存在,但就该代码块本身而言,没有任何证据表明其执行或支持所声明的核心能力(小红书搜索、抓取、查看、评论获取、博主作品分析等)。因此,代码实际行为与声明用途存在明显且实质性的偏差。
The declared purpose is a Xiaohongshu data retrieval/analysis skill. The supplied code does not perform any network access, scraping, content search, comment retrieval, or structured data extraction from Xiaohongshu. Instead, it writes content to local log files using the filesystem. While logging can be a supporting detail, this chunk explicitly exercises undeclared local filesystem write capability, which is not mentioned in the description or permissions. Therefore this code chunk does not accurately represent the declared behavior and should be flagged as a mismatch.
Referenced artifact was not completely inspected
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |
Referenced artifact was not completely inspected
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |
Referenced artifact was not completely inspected
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |
Referenced artifact was not completely inspected
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |
The skill declares access to a sensitive environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool or permission scope. That increases the risk of overbroad execution privileges and makes it harder for a host agent to enforce least privilege or audit what the skill is allowed to access.
The trigger conditions are intentionally broad enough to invoke the skill even when the user does not explicitly request Xiaohongshu data retrieval. Overbroad activation can cause unintended third-party data transmission, unnecessary token use, and surprising execution in contexts where the user only wanted general content help rather than external lookup.
The skill states only near the end that data is relayed through a third-party API, but it lacks a clear user-facing warning at or before invocation guidance. This can lead to undisclosed sharing of user-provided links, keywords, and potentially sensitive research targets with an external service, undermining informed consent and organizational data-handling requirements.
The package description and keywords are entirely in Chinese and narrowly target the Xiaohongshu platform, which can constitute a language/locale constraint in natural-language metadata. The file does not offer any language choice or explain that the skill is intentionally region-specific, so the locale restriction is not clearly documented per policy.
The README states that all task results are automatically saved to the logs/ directory, but it does not clearly warn users that searched keywords, queried Xiaohongshu links, scraped comments, and other collected public data may be persisted locally. This creates a real data-handling risk because operators may unintentionally retain sensitive research targets, campaign topics, or personal data from scraped content on disk, increasing exposure through local compromise, backups, or accidental sharing.
This code sends an API token and note URL to a remote endpoint via postJson, but the file provides only developer-oriented parameter comments and retry error logging. There is no confirmation prompt, user-facing disclosure, or warning comment explaining that user-provided data and credentials are transmitted over the network.
The getJson call sends the API token, URL, and limit to a remote API endpoint, which is a network operation involving credential and user data transmission. The file lacks any visible user-facing warning, confirmation, or explanatory comment beyond internal API parameter documentation.
This code sends a token and user-provided URL to a remote API via postJson, which is a privacy- and security-relevant network operation. Although the function has technical docstrings, there is no user-facing warning, confirmation, or disclosure in this file that these values will be transmitted externally.
The getDetailTask function performs a network call that includes the API token and requested resource URL in the request parameters. The file contains no user-facing disclosure or warning that sensitive credentials and user-supplied targets are transmitted to an external API.
The code sends the provided token in HTTP request parameters when creating a search task, but the file contains no user-facing warning, confirmation, or explicit disclosure that a credential will be transmitted to an external API. Although there are retry error logs, they do not inform the user about the sensitive outbound action itself.
This function performs an HTTP request that transmits the user's token and search keyword to a remote endpoint, but there is no visible warning, prompt, or user-oriented documentation in the file explaining that user data and credentials are being sent externally. The existing retry logging only reports failures and does not satisfy disclosure of the operation.
This code emits all user-facing warning and informational text in Chinese only. The file provides no indication that the skill is region-specific or that users can choose another language, which creates a language/locale policy violation under the stated rules.
This code emits user-facing error text in Chinese only (for example at L07 and L11), and additional success/error messages later in the file follow the same pattern. The policy for this category flags language or locale constraints when a skill forces a specific language without offering user choice or documenting a justified region-specific scope.
Several user-facing error strings are written only in Chinese, including operational guidance and support instructions. If the organization requires language choice or avoids forcing a locale, this can be a policy violation because the code provides no user opt-in or fallback language.
This code builds and sends outbound HTTPS GET and POST requests using caller-supplied params and data, which may include user or system data. There is no confirmation prompt, logging, comment, or docstring in this file disclosing that the skill sends data to a remote service.
This JavaScript file contains natural-language comments and error messages exclusively in Chinese, including validation feedback shown to users. Because the skill forces a specific language without any opt-in, fallback, or documented region-specific justification in this file, it violates the language/locale policy criteria.
Detected: suspicious.exposed_secret_literal