Back to skill

Security audit

guaikei·小红书笔记详情

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for Xiaohongshu public-data retrieval, but it handles API tokens and saved results in ways users should review before installing.

Install only if you are comfortable sending Xiaohongshu links and query terms to Guaikei and storing full returned results locally. Treat GUAIKEI_API_TOKEN and xsec_token-bearing URLs as sensitive, avoid shared workspaces, review or clean the logs/ directory, and consider modifying the tool to redact tokens and pass API credentials in headers before regular use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credential Exposed in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:25
Finding

Automatic Storage of Complete Results and Token-Bearing URLs with Unrestricted Default File Modes

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (44)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

Based on this snippet alone, the implementation is not aligned with the declared purpose. The declared description is narrowly scoped to Xiaohongshu public data operations, but the code references a different base domain (www.guaikei.com) and contains only generic networking/configuration constants. While this may be just a supporting file, the explicit external resource configured is inconsistent with the claimed Xiaohongshu-only target, so this is a likely description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书公开数据处理的垂直平台技能,但代码片段实际只是通用参数解析工具库(args 解析与 help 文本生成)。它既没有访问小红书资源,也没有实现任何与笔记搜索、详情、评论、博主作品相关的行为。虽然这类工具代码可能作为底层支持模块存在,但就该代码片段本身而言,其实际行为与声明的技能目的不一致,属于 materially different primary purpose。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向小红书公开内容抓取/处理的技能,但提供的代码片段实际只是在本地文件系统中写入日志文件。它访问的是本地磁盘资源(fs/path),而不是小红书网页或公开数据接口。该行为本身可作为辅助实现细节存在,但当前代码片段没有体现任何与小红书搜索、详情、评论、博主作品相关的逻辑;其实际功能与声明的主要用途明显不一致。因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says the skill is specifically for processing public Xiaohongshu content. However, the provided code chunk is a utility that accesses the local filesystem, parses package.json, and returns the package name. This is unrelated to Xiaohongshu platform data and represents a materially different behavior than the declared purpose. While utility code can support a larger skill, this chunk by itself does not reflect the declared capability and instead performs an undeclared local metadata/file read operation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个面向小红书公开数据抓取/查询的垂直技能,但给出的代码片段只是底层通用重试工具函数,没有体现任何与小红书、公开数据、搜索、详情、评论或博主作品相关的业务逻辑。虽然这类工具函数可能作为实现细节被该技能内部使用,但如果仅根据该代码片段判断,其实际行为与声明的主功能并不一致:代码展示的是通用基础设施能力,而不是声明中的平台专用能力。因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
node src/xiaohongshu/detail-cli.js --url "<笔记链接>" [--limit N]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares use of a sensitive environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool scope such as permissions or allowed-tools. That weakens least-privilege controls and makes it harder for a host agent to constrain secret access or clearly communicate what capabilities the skill needs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation is written entirely in Chinese and presents user utterance patterns, operational guidance, and outputs only in Chinese, without indicating that users may choose another language. This creates a natural-language locale constraint that is not documented as optional or justified as a region-specific compliance requirement.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README asserts the tool only accesses public Xiaohongshu data and does not involve privacy-sensitive data, yet the examples require URLs containing xsec_token parameters. Even if those tokens are commonly embedded in shared public links, they are still security-relevant request parameters and may grant scoped access, enable replay, or expose user/session-linked metadata if logged or mishandled. In a scraping/data-collection skill, this mismatch increases the risk that users underestimate sensitivity and paste tokens into commands, logs, or shared environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that all task results are automatically saved under logs/ using time plus keyword/link-based naming, but it does not warn that this may persist searched keywords, note/profile URLs, xsec_token-bearing links, and derived analysis data to disk. This creates a clear local data exposure risk through filesystem leakage, backups, source-control accidents, shared workstations, or support bundle sharing. In this skill's context, users are likely to process competitor monitoring, KOL screening, and comment analysis data, making stored outputs potentially commercially sensitive as well as token-sensitive.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

标题及整份说明文档均以中文固定提供,未见任何允许用户选择语言/locale 或说明该技能仅面向特定中文业务场景的明确声明。根据规则,未获用户选择即强制特定语言属于自然语言层面的语言/locale 策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file contains natural-language text such as comments and runtime error messages in Chinese, and there is no indication that the skill is region-specific or that users can opt into that locale. Per the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The retry log string emitted during task creation is fixed in Chinese and may be surfaced to users or operators regardless of their language preference. The file does not provide any mechanism for locale selection or justify a Chinese-only policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The retry log string emitted during task querying is fixed in Chinese and may be surfaced to users or operators regardless of their language preference. The file does not provide any mechanism for locale selection or justify a Chinese-only policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The function accepts an API token and sends it via postJson as part of the request parameters. While the docstring names the parameter, it does not warn users that the token will be transmitted to an external API, and there is no confirmation or user-facing disclosure in the code shown.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This function performs a network request with token, url, and limit included in the request parameters. The code contains no user-facing notice or warning that user-supplied links and authentication data are sent to a remote service, which meets the missing-disclosure criteria for network calls transmitting user or system data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code displays all warning and informational messages exclusively in Chinese, including operational guidance for recovering functionality. Because the file provides no user opt-in, language selection, or documented region-specific constraint, it violates the policy against forcing a specific language or locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The string literal on L035 presents the failure notice and remediation only in Chinese, including instructions to contact a specific WeChat number. This imposes a specific language/locale in user-facing output without offering any language choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits all validation and error messages in Chinese, such as '搜索关键词不能为空' and the later keyword-format warnings. Under the policy for natural-language violations, forcing a specific language without opt-in or documented regional justification is a reportable locale-policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI persists fetched comment results to a local JSON file by default, but there is no clear user-facing consent or warning at execution time that scraped data will be stored on disk. In shared environments or when handling sensitive public content, this can create unintended local data retention and disclosure risk if other users or processes can access the file.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest frames the skill as operating on public Xiaohongshu data and not using login-state data, but this file explicitly requires a GUAIKEI_API_TOKEN to be configured. Reading an external credential is a capability beyond the user-facing purpose of simply retrieving public note details, and the need for credentialed backend access is not disclosed in the stated scope.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16