Back to skill

Security audit

xhs-note-rank

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Xiaohongshu public-data lookup tool that calls a third-party API and saves local result logs, with no evidence of hidden destructive or exfiltration behavior.

Before installing, confirm you are comfortable sending Xiaohongshu search terms, note/profile links, and the GUAIKEI_API_TOKEN to the third-party guaikei.com API. Expect result data to be saved locally under logs, and use official support channels where possible rather than relying solely on the embedded WeChat contact.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Low
Confidence
95% confidence
Finding
The 401/403 error path exposes a personal WeChat contact number and directs users to an off-platform acquisition channel unrelated to the request helper's technical function. In a skill that handles analytics API access, embedding a private contact route in error handling is inappropriate and can be abused for social engineering, trust hijacking, or unauthorized commercial redirection when authentication fails.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.