Back to skill

Security audit

guaikei·小红书问评论

Security checks for vulnerabilities and agentic risk

Overview

The skill largely does what it says, but it handles API credentials and retrieved Xiaohongshu data in ways users should review before installing.

Install only if you are comfortable sending Xiaohongshu keywords, note/profile URLs, and retrieved public data to guaikei.com. Use a scoped or disposable GUAIKEI_API_TOKEN if possible, avoid passing links with sensitive xsec_token parameters unless needed, and periodically delete the generated logs directory because results are saved automatically.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:84
Finding

API Credential Transmitted in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/log.js:25
Finding

Automatic Plaintext Retention of Sensitive URLs and Retrieved User Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (66)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on assessing a Xiaohongshu blogger's real engagement level using true like/comment/favorite data from public works or a single note. However, this code chunk only supports comment-task creation and fetching comment results for a given note URL and limit through backend APIs. There is no logic for gathering likes, favorites, creator-wide works, engagement analysis, or detecting data inflation. While comment retrieval is tangentially related, the implemented capability in this chunk is materially narrower and different from the stated primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The declared description presents a broader analysis skill focused on evaluating a Xiaohongshu blogger/KOL's real engagement level across public works and single notes. However, this code chunk is a narrow API wrapper for creating/querying a single note detail task and retrieving comments for a given note URL. It does not show blogger-level public works collection, engagement-quality evaluation, anti-inflation judgment, or metric-specific processing for likes/comments/saves beyond whatever the backend may return. The comment retrieval capability is substantial and should be declared if it is part of the skill. Therefore the code behavior only partially matches and is materially narrower/different than the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明的核心用途是评估某个小红书博主/笔记的真实互动水平,强调点赞、评论、收藏等真实数据的获取与分析。实际代码仅调用 note-search 相关接口:创建关键词搜索任务、查询搜索结果,并对结果补充笔记 URL 和用户主页 URL。这说明其主要行为是内容搜索,不是博主互动数据评估。虽然搜索结果中可能间接包含部分笔记信息,但当前代码没有显示提取、校验、汇总或分析互动指标,也没有围绕‘某个博主’进行作品级分析。因此描述与代码实际能力存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书博主互动数据获取与分析的技能,但代码片段实际仅实现了通用命令行参数解析与帮助文本生成。这不是为实现声明能力所必需的特定业务逻辑,而是完全通用的基础设施代码。当前代码未体现任何对小红书资源的访问、数据抓取、指标提取或分析评估能力,因此描述与实际行为存在明显且实质性的不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书KOL分析的数据获取与评估技能,而实际代码片段只是一个认证/配置辅助模块,用于检查API token是否有效并输出提示信息。虽然这类模块可能是更大技能的配套部分,但就所给代码块本身来看,其实际行为与声明的核心功能明显不一致,且没有体现任何小红书数据访问或分析能力,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向小红书博主互动数据获取与评估的技能,但给出的代码片段并未体现任何与小红书、作品数据抓取、点赞评论收藏统计或互动质量分析相关的行为。实际代码仅执行本地日志文件写入,这是与声明主用途无关的能力。虽然日志功能可能作为辅助实现存在,但当前提供的代码片段本身的行为与声明用途明显不一致,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is a Xiaohongshu analytics capability focused on collecting and evaluating public engagement metrics. The actual code chunk contains only a helper that reads package.json from the local filesystem and returns the package name. This is materially unrelated to the stated purpose and shows no implementation of Xiaohongshu data retrieval, metric extraction, or engagement analysis. While reading package metadata could be a supporting utility in some projects, this specific chunk by itself does not align with the declared behavior and instead exposes an unrelated capability (local filesystem access for package metadata).

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

代码片段仅实现了基础的 withRetry 工具:包装一个异步函数,在失败时按指数退避重试,并在标记为 nonRetryable 时立即抛出错误。这属于通用支撑性基础设施,但当前提供的代码本身完全没有显示与小红书、博主、作品、笔记、点赞、评论、收藏、互动质量评估等声明用途直接相关的行为。如果这是整个技能中一个辅助模块,则它本身只是支持细节;但题目要求比较该描述与所给代码块实际行为,该代码块的实际功能与声明的主要用途明显不一致,因此应判定为描述不准确。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a Xiaohongshu data retrieval and engagement-analysis skill. However, the supplied code only contains generic utility functions for printing a banner and formatted logs to stderr. There is no evidence of network access, scraping/API calls, note/blogger analysis, or metric evaluation. This is a materially different primary purpose from the declared behavior, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes a Xiaohongshu analytics capability: obtaining real public engagement metrics and using them to evaluate creator interaction quality for collaboration decisions. However, this code chunk contains only helper functions for validating keyword strings, cleaning keyword input, and formatting search options with bounds/defaults. These are supporting search-input utilities and do not themselves implement the declared core behavior. Because the actual code shown has a materially different immediate purpose and lacks the promised data retrieval/analysis capabilities, this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description promises a skill for obtaining real public engagement data for Xiaohongshu creators and notes, supporting influencer evaluation. However, this code chunk is limited to helper functions that normalize URLs, classify them as note/profile URLs, and convert URLs into simplified names. These are supporting utilities, but in isolation they do not implement the declared core functionality. Therefore the supplied code chunk does not accurately represent the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

代码的核心行为是:通过笔记链接创建并获取“评论任务”,输出评论结果JSON,并将结果写入日志文件。这与声明中的高层用途存在明显偏差。声明强调的是获取博主或笔记的真实互动数据(点赞/评论/收藏)并据此评估KOL互动质量,而当前代码片段只展示了单篇笔记评论抓取接口的CLI封装,没有看到点赞数、收藏数、博主作品列表、博主维度分析、互动质量评估或注水识别等功能。因此该代码片段的实际能力明显比声明更窄,且主用途更偏向“抓取单篇笔记评论”。这构成描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The declared description emphasizes retrieving public works plus true like/comment/favorite counts for single notes and using that data to evaluate interaction quality and detect inflated metrics. This code chunk only implements a command-line wrapper around an external post task: it validates a Xiaohongshu profile URL, sets a note-count limit, calls createPostTask/getPostTask, and returns whatever results come back. There is no visible logic for analyzing engagement quality, judging data inflation, or specifically fetching single-note metrics. Additionally, the input is explicitly a profile URL, not an individual note URL, so the 'single note' portion of the description is not supported by this code. While the external API may possibly return relevant post metrics, that capability is not demonstrated in the supplied code, making the description materially broader than the observed behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code’s primary function is generic search over Xiaohongshu content using a keyword, with options for type, sort, time, and limit. It does not target a specific blogger, does not clearly fetch a blogger profile or all works, and does not implement analysis of 'real' engagement quality beyond returning search results. While sorting by likes/comments/favorites is related to engagement metrics, that is only a search feature and not the declared purpose of assessing a blogger’s authentic interaction level. Therefore the supplied code chunk materially differs from the declared skill description.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
node src/xiaohongshu/detail-cli.js --url "<笔记链接>" [--limit N]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill declares access to a sensitive environment variable (GUAIKEI_API_TOKEN) but does not define any explicit tool scope such as allowed tools or permissions boundaries. In agent environments, missing scope declarations can cause over-broad invocation or unclear secret-handling expectations, increasing the risk of unintended token exposure or misuse through command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description contains broad trigger language that can cause the agent to invoke the skill for many generic Xiaohongshu-analysis requests, even when the user did not explicitly ask for this external API-backed workflow. Over-broad activation increases the chance of unnecessary third-party data disclosure, accidental token use, and surprising behavior outside the user's intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The scenario examples use everyday phrases like '看看XX最近有什么新内容' and '帮我搜XX的笔记' without enough gating conditions, making the skill easy to over-trigger in routine conversations. In an agent context, that can lead to unneeded outbound queries and data sharing with the external provider when a simpler local response or clarification would suffice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README materially expands the skill’s apparent scope beyond the metadata description, advertising keyword mining, competitor monitoring, trend prediction, and comment analysis in addition to engagement evaluation. This can mislead users, reviewers, or downstream agents about what the skill will do, weakening informed consent and policy enforcement around scraping, profiling, and monitoring behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

清单描述将技能定位为获取博主公开作品及单篇笔记的真实点赞/评论/收藏数据,用于评估互动质量,并明确不用于其他方向。但更新日志显示该技能曾新增或支持评论信息获取、评论情绪分析、关键词搜索、热门笔记挖掘、竞品分析和趋势监控等能力,明显超出当前描述的互动数据核验范围。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document expands the skill from the manifest-described purpose of evaluating real engagement on Xiaohongshu creators into a broader 'insights and competitor analysis assistant' with keyword search and other collection workflows. This capability drift is dangerous because users, reviewers, and orchestration systems may authorize or invoke the skill under a narrower trust boundary than what the documentation actually encourages, leading to over-collection and misuse.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16