Back to skill

Security audit

xhs-note-detail

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Xiaohongshu public-data command skill, with notable but disclosed network-token use and local result logging to review before installation.

Install only if you are comfortable sending Xiaohongshu keywords, target URLs, and your Guaikei API token to the Guaikei service. Keep the token scoped and rotated as needed, and periodically delete or protect the generated logs because they may contain research history, comments, and access-bearing Xiaohongshu URLs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:61
Finding

API Credential Transmitted in URL Query Parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:24
Finding

Automatic Plaintext Persistence of Retrieved Content and Access-Bearing URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (43)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a data-mining and analytics integration, but the reported implementation contains only terminal output/logging utilities and no Xiaohongshu retrieval or analytics logic. Such deceptive packaging increases supply-chain risk because reviewers and users may approve or invoke a tool based on claimed benign functionality while overlooking its actual behavior and side effects.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a data-mining and analytics integration, but the reported implementation contains only terminal output/logging utilities and no Xiaohongshu retrieval or analytics logic. Such deceptive packaging increases supply-chain risk because reviewers and users may approve or invoke a tool based on claimed benign functionality while overlooking its actual behavior and side effects.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as a data-mining and analytics integration, but the reported implementation contains only terminal output/logging utilities and no Xiaohongshu retrieval or analytics logic. Such deceptive packaging increases supply-chain risk because reviewers and users may approve or invoke a tool based on claimed benign functionality while overlooking its actual behavior and side effects.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 241)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 253)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description, usage guidance, examples, and operational instructions all force a single language/locale for users. Under the policy, language constraints should either be optional or explicitly justified; this file does not offer an alternative language choice or user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README forces a single language experience for all users through its natural-language instructions and descriptions. Under the policy, language constraints should either provide user opt-in/choice or be clearly documented as region-specific and justified; this file does neither.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest and most of the README consistently describe the skill as a Xiaohongshu public-note search/detail/comment and creator-post analysis tool. Line L25 states '获取抖音评论详情', which expands the documented behavior to Douyin rather than Xiaohongshu and does not match the stated skill scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The changelog is written entirely in Chinese and provides no indication that other languages are supported or that Chinese is an optional locale. Under the policy rule for language or locale, this can be a violation when a skill's natural-language materials impose a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code sends the provided API token as part of outbound HTTP request parameters, which is a sensitive credential-handling operation. Although the function has technical parameter docstrings, there is no user-facing warning, confirmation, or disclosure here that credentials will be transmitted to a remote API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The function transmits the user-supplied note URL and limit values to a remote endpoint, which may reveal user activity or targets being analyzed. The file contains implementation comments but no explicit user-facing warning that external network calls will send this input to a third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code sends an API token and a blogger URL to remote endpoints via postJson, which is a network operation involving potentially sensitive user or system data. Although the functions have technical docstrings and retry logging, there is no user-facing warning, confirmation, or disclosure here that these inputs will be transmitted to an external API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The getPostTask function performs a remote request that includes the API token, URL, and limit parameters. The file contains error logging and parameter docstrings, but no clear user-facing notice that these values are sent over the network to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing strings are exclusively in Chinese and directly communicate operational status and recovery instructions, with no indication that the skill supports other languages or that Chinese-only output is an intentional, justified locale restriction. This matches the policy category for language or locale constraints imposed without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits user-facing error text in Chinese only (and also continues with Chinese output at L35-L37), which imposes a specific language on users without any visible opt-in or documented locale constraint. That matches the policy category for language/locale violations because the skill does not offer a language choice or justify being Chinese-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code emits a hard-coded Chinese error message, and similar strings throughout the file are also Chinese-only. That imposes a specific language on users without opt-in or locale selection, which is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The invalid-token error shown to users is entirely in Chinese and does not provide any mechanism for language choice. This is a user-facing locale constraint embedded in natural-language output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool writes fetched note/comment results to a local JSON file without prior warning in its help text or an explicit user consent mechanism. In the context of a data-collection skill for competitor analysis and KOL screening, this can silently accumulate third-party content and user comments on disk, increasing privacy, compliance, and local data exposure risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The argument descriptions and help text identify the input as a '小红书博主链接' and '主页笔记数量', and the code validates the URL with isProfileUrl before creating and fetching a post task. This does not align with the skill name and manifest emphasis on note detail retrieval; this file implements blogger-profile post listing rather than note-detail lookup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The calls to post.createPostTask and post.getPostTask are network-facing operations that transmit the user-supplied profile URL and request parameters. This file does not explicitly warn the user that their input will be sent to an external service, beyond the skill's general purpose implied by the command.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.