T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Credential Exposed in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent for Xiaohongshu public-data retrieval, but it handles API tokens and saved results in ways users should review before installing.
Install only if you are comfortable sending Xiaohongshu links and query terms to Guaikei and storing full returned results locally. Treat GUAIKEI_API_TOKEN and xsec_token-bearing URLs as sensitive, avoid shared workspaces, review or clean the logs/ directory, and consider modifying the tool to redact tokens and pass API credentials in headers before regular use.
src/utils/request.js:76API Credential Exposed in URL Query Strings
src/utils/log.js:25Automatic Storage of Complete Results and Token-Bearing URLs with Unrestricted Default File Modes
Based on this snippet alone, the implementation is not aligned with the declared purpose. The declared description is narrowly scoped to Xiaohongshu public data operations, but the code references a different base domain (www.guaikei.com) and contains only generic networking/configuration constants. While this may be just a supporting file, the explicit external resource configured is inconsistent with the claimed Xiaohongshu-only target, so this is a likely description-behavior mismatch.
声明描述的是一个面向小红书公开数据处理的垂直平台技能,但代码片段实际只是通用参数解析工具库(args 解析与 help 文本生成)。它既没有访问小红书资源,也没有实现任何与笔记搜索、详情、评论、博主作品相关的行为。虽然这类工具代码可能作为底层支持模块存在,但就该代码片段本身而言,其实际行为与声明的技能目的不一致,属于 materially different primary purpose。
声明描述的是一个面向小红书公开内容抓取/处理的技能,但提供的代码片段实际只是在本地文件系统中写入日志文件。它访问的是本地磁盘资源(fs/path),而不是小红书网页或公开数据接口。该行为本身可作为辅助实现细节存在,但当前代码片段没有体现任何与小红书搜索、详情、评论、博主作品相关的逻辑;其实际功能与声明的主要用途明显不一致。因此应判定为描述与代码行为不匹配。
The declared description says the skill is specifically for processing public Xiaohongshu content. However, the provided code chunk is a utility that accesses the local filesystem, parses package.json, and returns the package name. This is unrelated to Xiaohongshu platform data and represents a materially different behavior than the declared purpose. While utility code can support a larger skill, this chunk by itself does not reflect the declared capability and instead performs an undeclared local metadata/file read operation.
声明描述的是一个面向小红书公开数据抓取/查询的垂直技能,但给出的代码片段只是底层通用重试工具函数,没有体现任何与小红书、公开数据、搜索、详情、评论或博主作品相关的业务逻辑。虽然这类工具函数可能作为实现细节被该技能内部使用,但如果仅根据该代码片段判断,其实际行为与声明的主功能并不一致:代码展示的是通用基础设施能力,而不是声明中的平台专用能力。因此应判定为描述与代码行为不匹配。
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
node src/xiaohongshu/detail-cli.js --url "<笔记链接>" [--limit N]
The skill declares use of a sensitive environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool scope such as permissions or allowed-tools. That weakens least-privilege controls and makes it harder for a host agent to constrain secret access or clearly communicate what capabilities the skill needs.
The skill documentation is written entirely in Chinese and presents user utterance patterns, operational guidance, and outputs only in Chinese, without indicating that users may choose another language. This creates a natural-language locale constraint that is not documented as optional or justified as a region-specific compliance requirement.
The README asserts the tool only accesses public Xiaohongshu data and does not involve privacy-sensitive data, yet the examples require URLs containing xsec_token parameters. Even if those tokens are commonly embedded in shared public links, they are still security-relevant request parameters and may grant scoped access, enable replay, or expose user/session-linked metadata if logged or mishandled. In a scraping/data-collection skill, this mismatch increases the risk that users underestimate sensitivity and paste tokens into commands, logs, or shared environments.
The README states that all task results are automatically saved under logs/ using time plus keyword/link-based naming, but it does not warn that this may persist searched keywords, note/profile URLs, xsec_token-bearing links, and derived analysis data to disk. This creates a clear local data exposure risk through filesystem leakage, backups, source-control accidents, shared workstations, or support bundle sharing. In this skill's context, users are likely to process competitor monitoring, KOL screening, and comment analysis data, making stored outputs potentially commercially sensitive as well as token-sensitive.
标题及整份说明文档均以中文固定提供,未见任何允许用户选择语言/locale 或说明该技能仅面向特定中文业务场景的明确声明。根据规则,未获用户选择即强制特定语言属于自然语言层面的语言/locale 策略问题。
This file contains natural-language text such as comments and runtime error messages in Chinese, and there is no indication that the skill is region-specific or that users can opt into that locale. Per the policy, forcing a specific language without user choice is a natural-language policy violation.
The retry log string emitted during task creation is fixed in Chinese and may be surfaced to users or operators regardless of their language preference. The file does not provide any mechanism for locale selection or justify a Chinese-only policy.
The retry log string emitted during task querying is fixed in Chinese and may be surfaced to users or operators regardless of their language preference. The file does not provide any mechanism for locale selection or justify a Chinese-only policy.
The function accepts an API token and sends it via postJson as part of the request parameters. While the docstring names the parameter, it does not warn users that the token will be transmitted to an external API, and there is no confirmation or user-facing disclosure in the code shown.
This function performs a network request with token, url, and limit included in the request parameters. The code contains no user-facing notice or warning that user-supplied links and authentication data are sent to a remote service, which meets the missing-disclosure criteria for network calls transmitting user or system data.
This code displays all warning and informational messages exclusively in Chinese, including operational guidance for recovering functionality. Because the file provides no user opt-in, language selection, or documented region-specific constraint, it violates the policy against forcing a specific language or locale.
The string literal on L035 presents the failure notice and remediation only in Chinese, including instructions to contact a specific WeChat number. This imposes a specific language/locale in user-facing output without offering any language choice or documenting a justified locale restriction.
This code emits all validation and error messages in Chinese, such as '搜索关键词不能为空' and the later keyword-format warnings. Under the policy for natural-language violations, forcing a specific language without opt-in or documented regional justification is a reportable locale-policy issue.
The CLI persists fetched comment results to a local JSON file by default, but there is no clear user-facing consent or warning at execution time that scraped data will be stored on disk. In shared environments or when handling sensitive public content, this can create unintended local data retention and disclosure risk if other users or processes can access the file.
The manifest frames the skill as operating on public Xiaohongshu data and not using login-state data, but this file explicitly requires a GUAIKEI_API_TOKEN to be configured. Reading an external credential is a capability beyond the user-facing purpose of simply retrieving public note details, and the need for credentialed backend access is not disclosed in the stated scope.
Detected: suspicious.exposed_secret_literal