Back to skill

Security audit

guaikei·小红书洞察

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do the Xiaohongshu research it advertises, but it handles API tokens and saved result data in ways users should review before installing.

Install only if you are comfortable sending Xiaohongshu links, search terms, and a Guaikei API token to the Guaikei service. Treat generated logs as sensitive: they may contain research targets, comments, profile data, and xsec_token URLs, so delete or protect them and avoid committing logs to source control. Prefer a version that moves the API token out of query strings and supports opt-in or redacted logging.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credential Transmitted in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/xiaohongshu/detail-cli.js:137
Finding

Automatic Plaintext Persistence of Results and Access-Bearing URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (47)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose centers on accessing public Xiaohongshu content and analyzing it. However, the supplied code chunk is only a constants file and sets BASE_URL to www.guaikei.com, which is not one of the declared Xiaohongshu-related domains (xiaohongshu.com/xhslink.com). While configuration code alone can be supportive, this chunk provides no evidence of the promised Xiaohongshu functionality and instead references an apparently different resource, which is inconsistent with the description. Therefore, this is best flagged as a mismatch based on the inconsistent target resource and absence of matching behavior in the provided code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书公开内容采集与分析的技能,而给出的代码片段仅是与业务无关的基础工具模块,用于解析命令行参数和生成帮助文本。虽然这类工具可能作为更大系统的辅助组件存在,但就该代码块本身而言,没有任何证据表明其执行或支持所声明的核心能力(小红书搜索、抓取、查看、评论获取、博主作品分析等)。因此,代码实际行为与声明用途存在明显且实质性的偏差。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose is a Xiaohongshu data retrieval/analysis skill. The supplied code does not perform any network access, scraping, content search, comment retrieval, or structured data extraction from Xiaohongshu. Instead, it writes content to local log files using the filesystem. While logging can be a supporting detail, this chunk explicitly exercises undeclared local filesystem write capability, which is not mentioned in the description or permissions. Therefore this code chunk does not accurately represent the declared behavior and should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
| 笔记链接 | 看这篇笔记的正文与互动 | 笔记详情 | `detail-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
| 笔记链接 | 只拉这篇的评论区 | 评论获取 | `comment-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
| 博主主页链接 | 看他发了什么 | 博主作品 | `post-cli.js` |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares access to a sensitive environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool or permission scope. That increases the risk of overbroad execution privileges and makes it harder for a host agent to enforce least privilege or audit what the skill is allowed to access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions are intentionally broad enough to invoke the skill even when the user does not explicitly request Xiaohongshu data retrieval. Overbroad activation can cause unintended third-party data transmission, unnecessary token use, and surprising execution in contexts where the user only wanted general content help rather than external lookup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states only near the end that data is relayed through a third-party API, but it lacks a clear user-facing warning at or before invocation guidance. This can lead to undisclosed sharing of user-provided links, keywords, and potentially sensitive research targets with an external service, undermining informed consent and organizational data-handling requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The package description and keywords are entirely in Chinese and narrowly target the Xiaohongshu platform, which can constitute a language/locale constraint in natural-language metadata. The file does not offer any language choice or explain that the skill is intentionally region-specific, so the locale restriction is not clearly documented per policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not clearly warn users that searched keywords, queried Xiaohongshu links, scraped comments, and other collected public data may be persisted locally. This creates a real data-handling risk because operators may unintentionally retain sensitive research targets, campaign topics, or personal data from scraped content on disk, increasing exposure through local compromise, backups, or accidental sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code sends an API token and note URL to a remote endpoint via postJson, but the file provides only developer-oriented parameter comments and retry error logging. There is no confirmation prompt, user-facing disclosure, or warning comment explaining that user-provided data and credentials are transmitted over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The getJson call sends the API token, URL, and limit to a remote API endpoint, which is a network operation involving credential and user data transmission. The file lacks any visible user-facing warning, confirmation, or explanatory comment beyond internal API parameter documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code sends a token and user-provided URL to a remote API via postJson, which is a privacy- and security-relevant network operation. Although the function has technical docstrings, there is no user-facing warning, confirmation, or disclosure in this file that these values will be transmitted externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The getDetailTask function performs a network call that includes the API token and requested resource URL in the request parameters. The file contains no user-facing disclosure or warning that sensitive credentials and user-supplied targets are transmitted to an external API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code sends the provided token in HTTP request parameters when creating a search task, but the file contains no user-facing warning, confirmation, or explicit disclosure that a credential will be transmitted to an external API. Although there are retry error logs, they do not inform the user about the sensitive outbound action itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This function performs an HTTP request that transmits the user's token and search keyword to a remote endpoint, but there is no visible warning, prompt, or user-oriented documentation in the file explaining that user data and credentials are being sent externally. The existing retry logging only reports failures and does not satisfy disclosure of the operation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits all user-facing warning and informational text in Chinese only. The file provides no indication that the skill is region-specific or that users can choose another language, which creates a language/locale policy violation under the stated rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits user-facing error text in Chinese only (for example at L07 and L11), and additional success/error messages later in the file follow the same pattern. The policy for this category flags language or locale constraints when a skill forces a specific language without offering user choice or documenting a justified region-specific scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Several user-facing error strings are written only in Chinese, including operational guidance and support instructions. If the organization requires language choice or avoids forcing a locale, this can be a policy violation because the code provides no user opt-in or fallback language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code builds and sends outbound HTTPS GET and POST requests using caller-supplied params and data, which may include user or system data. There is no confirmation prompt, logging, comment, or docstring in this file disclosing that the skill sends data to a remote service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language comments and error messages exclusively in Chinese, including validation feedback shown to users. Because the skill forces a specific language without any opt-in, fallback, or documented region-specific justification in this file, it violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16