T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Credential Exposed in URL Query Parameters
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real Xiaohongshu public-data tool, but it needs review because it handles API credentials and saved results in ways that can expose sensitive data.
Install only if you are comfortable sending Xiaohongshu keywords, note/profile URLs, and retrieved public comment/content data to guaikei.com. Treat generated logs as sensitive and delete them when no longer needed. Do not print the full API token; ask the publisher to move token authentication out of URL query strings, add a no-save option or redaction, and narrow activation to explicit Xiaohongshu requests.
src/utils/request.js:76API Credential Exposed in URL Query Parameters
SKILL.md:143Documentation Recommends Printing the Full API Token
src/utils/log.js:5Complete API Results Are Automatically Stored in Plaintext
The declared purpose centers on discovering and ranking public Xiaohongshu notes via keyword search and filters. The supplied code does something materially different: it creates and queries tasks for retrieving comments from a specific Xiaohongshu note URL. This is not a supporting detail of keyword note search; it is a separate capability with different inputs, outputs, and user intent. Therefore the description does not accurately represent this code chunk.
声明描述的核心能力是“关键词搜索小红书公开笔记”,并支持排序、时间筛选以及对多个关键词热度进行调研;而代码片段实际处理的是另一类功能:针对给定的小红书笔记链接创建详情抓取任务,并查询该任务结果,返回单篇笔记详情及评论数据。代码中没有任何关键词搜索、排序、时间筛选、列表分页或多关键词对比逻辑,反而包含了未在声明中体现的‘按URL抓取笔记详情/评论’能力。因此该代码与声明用途存在明显的功能性不匹配。
声明描述的核心能力是“小红书关键词检索与排序筛选分析”。但该代码片段没有任何关键词参数、排序参数、时间筛选参数,也没有体现多关键词对比或热门内容搜索。相反,代码是基于博主URL创建任务并获取该博主已发布笔记结果,属于博主内容抓取/详情查询模块。虽然同属小红书公开内容范围,但主目的和输入资源类型(关键词 vs 博主URL)均明显不同,构成实质性不匹配。
代码片段的实际功能是一个通用参数解析模块(args.js),属于底层 CLI 支撑工具。它不访问小红书,也不执行搜索、抓取、排序、时间过滤或结果返回。虽然这类工具可能是更大项目中的配套组件,但就所提供代码片段本身而言,其行为与声明的技能核心用途明显不一致。因此应判定为描述与代码行为不匹配。
从提供的代码片段看,唯一功能是校验GUAIKEI_API_TOKEN格式并输出提示信息,核心行为是服务可用性控制,而非执行小红书内容搜索或分析。虽然这可能是技能的一个辅助模块,但就该代码片段本身而言,它与声明的主要用途严重不一致,且包含未声明的微信联系方式与私有TOKEN获取引导。因此应判定为描述与实际行为不匹配。
声明描述的是一个面向小红书公开笔记的搜索与分析技能,但提供的代码片段只是本地日志写入模块,主要涉及文件名清理、目录创建和文件写入。两者主目的明显不同。虽然日志功能可能作为辅助实现存在,但当前代码片段完全没有体现声明中的核心能力,反而展示了未声明的本地文件系统访问/写入行为。因此该代码与声明用途不匹配。
The declared description describes a full-featured Xiaohongshu content discovery/search capability. The supplied code chunk does not implement any of that behavior; it merely reads package.json from the local filesystem to obtain the package name. This is materially different from the declared primary purpose and accesses a different resource (local files rather than Xiaohongshu/public notes). While this could be a small supporting utility within a larger skill, based on this chunk alone it does not match the declared functionality.
声明描述的是一个面向小红书公开笔记的搜索与分析技能,核心能力应包括关键词检索、排序、时间过滤以及返回笔记和互动指标。但提供的代码片段只包含 URL 处理辅助函数:将 http 规范为 https、拒绝非 https 或含空格的 URL、判断是否为笔记链接或主页链接、以及从 URL 生成名称。它既没有执行搜索,也没有抓取或返回任何笔记内容、互动数据或时间筛选结果。虽然仍然限定在小红书域名相关资源上,但其实际作用是 URL 验证/归类,和声明的主要用途存在明显不一致。
声明描述的是“小红书公开笔记关键词搜索”能力,核心是按关键词检索笔记,并支持排序、时间筛选、比较关键词表现等研究场景。而代码实际实现的是 comment-cli:它要求传入单个小红书笔记链接(--url),可选评论数量限制(--limit),验证是否为笔记链接后,调用 comment.createCommentTask 和 comment.getCommentTask 获取该笔记评论数据。代码中没有任何关键词搜索、排序、时间筛选、多关键词对比或笔记列表返回逻辑。虽然帮助文本提到 search-cli 可产出 url,但当前代码块本身的主要功能是评论抓取,不是搜索。因此描述与实际行为存在明显且实质性的功能不匹配。
声明描述的是一个“按关键词搜索小红书公开笔记”的能力,核心功能应包括关键词检索、排序、时间筛选,以及返回笔记列表用于趋势/爆款分析。但代码片段实际是 detail-cli.js,只接受笔记链接(--url)和评论数量限制(--limit),并通过 createDetailTask/getDetailTask 获取单条公开笔记的详情与评论。代码中没有任何关键词输入、搜索逻辑、排序参数、时间筛选参数,资源访问粒度也从“搜索结果列表”变为“单篇笔记详情”。虽然帮助文本提到 URL 可来自 search-cli 的输出,但本代码自身并不实现声明中的搜索能力,因此描述与该代码块实际行为存在明显不匹配。
声明描述的是一个“小红书关键词搜索”技能:用户提供关键词,系统按互动指标和时间条件筛选、排序公开笔记,用于热度分析与选题调研。但代码中 post-cli.js 明确要求 --url/-u 参数,帮助文本写的是“小红书博主链接”,并使用 validator.isProfileUrl(url) 校验主页链接格式;随后调用 post.createPostTask(token, url, limit) 和 post.getPostTask(token, url, limit) 获取“主页笔记”。整个流程围绕博主主页URL与笔记数量limit展开,没有关键词参数,也没有排序字段、时间筛选条件或多关键词对比逻辑。因此该代码与声明的核心目的存在明显偏差,属于实质性不匹配。
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
node src/xiaohongshu/detail-cli.js --url "<笔记链接>" [--limit N]
The documentation expands the skill from keyword-based Xiaohongshu search into four separate capabilities, including note detail lookup, creator profile retrieval, and comment extraction. This creates a scope mismatch between the manifest and actual described behavior, which can bypass user expectations, policy review boundaries, or permission assumptions and enable broader data access than advertised.
The note-detail and comment-analysis sections document retrieval of full note content and comment data, which is materially broader than simple public keyword search. Even if the content is publicly accessible, exposing comment harvesting and detailed note analysis without declaring it in the manifest increases privacy, compliance, and review-evasion risk.
The creator-post lookup capability enables retrieval and monitoring of a creator's recent published works, which goes beyond keyword search and supports account-level tracking. In context, this broadens the skill into competitor or KOL surveillance functionality not clearly disclosed in the manifest, increasing misuse and consent-risk concerns.
The standalone comment-query capability allows targeted extraction of comment data independent of note-detail retrieval, making bulk comment collection easier and broadening the operational scope beyond search/listing. This is dangerous because comment harvesting can implicate privacy expectations, platform restrictions, and undisclosed data processing beyond what users and reviewers were told the skill does.
This module adds comment-task creation and retrieval capabilities that go beyond the declared skill scope of keyword-based public note discovery and engagement comparison. Scope expansion is dangerous because it increases data access and collection behavior without clear user expectation or manifest disclosure, which can enable unauthorized scraping of comment content and create privacy/compliance risk.
The manifest describes a skill for searching public Xiaohongshu notes by keyword, sorting/filtering results, and returning note lists with engagement metrics. This file instead accepts a specific note URL and creates/fetches a comment task, returning comment data, which is a materially different capability from keyword-based note search.
The manifest says this skill searches public Xiaohongshu notes by keyword with sorting and time filtering for topic research. This file instead requires a '小红书博主链接', validates it as a profile URL, and submits a 'post' task to retrieve homepage notes for that creator, which is a materially different user-facing capability.
The skill declares access to an environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool scope such as allowed tools or permissions. In an agent setting, missing scope boundaries can let the runtime expose more capability than the user or platform expects, especially for networked commands that depend on secrets.
The skill includes broad trigger phrases like '最近什么火' and '帮我找热门内容' that can capture generic social-media research requests even when the user did not specify Xiaohongshu. In an agent router, this can cause over-broad invocation and unintended exfiltration of user prompts, keywords, or links to the third-party backend, especially because the skill sends inputs to guaikei.com.
Detected: suspicious.exposed_secret_literal