T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:71- Finding
API Credential Exposed in Request Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This looks like a real Xiaohongshu public-data tool, but it needs Review because it sends user queries and URLs to a third-party API, handles the API token weakly, and automatically saves fetched data locally.
Install only if you are comfortable sending Xiaohongshu keywords, URLs, and related request data to www.guaikei.com using your GUAIKEI_API_TOKEN. Treat the token as sensitive, avoid submitting private or sensitive URLs, and review or delete the generated logs because they may contain xsec_token URLs, comments, profile data, and research queries.
src/utils/request.js:71API Credential Exposed in Request Query Strings
src/validate/url.js:3URL Allowlist Bypass Through Substring-Based Validation
src/utils/log.js:5Sensitive URLs and Retrieved Data Persisted in Unprotected Log Files
The declared description describes a broader Xiaohongshu operations data tool with multiple capabilities: searching public notes, viewing note details and comments, and scraping a creator's public works list. However, the supplied code chunk is limited to search functionality only. It creates a keyword search task and fetches search results from note-search endpoints, then enriches results with note/profile URLs. There is no code here for note detail APIs, comment APIs, or creator works-list retrieval. Because the description asserts capabilities not represented by this code chunk, the description does not accurately match the actual behavior shown.
声明描述的是一个面向小红书公开内容检索与分析的业务型工具,但所给代码片段仅是基础的参数解析与帮助文案生成模块,属于通用支撑组件。按照评估标准,支撑实现细节本身不应被判定为问题;但这里的问题在于:当前代码片段没有表现出声明中的核心功能或相近行为,主用途与声明明显不一致。因此应判定为描述与实际代码行为不匹配。
代码片段的核心功能只是校验和返回TOKEN,并在TOKEN无效时输出提示与微信联系方式,属于认证/配置辅助逻辑。就当前提供的代码而言,看不到任何与小红书数据获取、分析或内容检索相关的实现,因此其实际行为与声明的主要用途存在明显不一致。虽然TOKEN管理可以作为某类技能的配套模块,但该片段本身并未体现所声明的主要能力。
The declared purpose describes a data collection/analysis tool for Xiaohongshu public content. The supplied code chunk does not implement any of those platform-related capabilities. Instead, it performs local filesystem logging by creating directories and writing content to a file. Local file write access is an undeclared capability in the description, and the primary behavior shown is materially unrelated to the declared purpose. While logging could be a supporting utility in a larger system, this chunk by itself does not reflect the stated functionality.
The declared description promises substantive Xiaohongshu data collection and analysis functionality. However, the supplied code chunk contains only utility functions for printing a banner and colored log messages to stderr. That behavior is merely auxiliary and does not implement the described searching, viewing, scraping, or analytics capabilities. Based on this chunk alone, the actual behavior does not match the declared purpose.
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
The skill declares use of an environment variable (GUAIKEI_API_TOKEN) but does not define any explicit tool scope such as permissions or allowed-tools. That weakens least-privilege controls and can let the runtime expose capabilities more broadly than necessary, especially for a third-party integration that sends user-supplied keywords and URLs to an external API.
The manifest description and keywords are entirely in Chinese and centered on a Chinese platform, but the file does not indicate that language or locale is optional or intentionally constrained for a region-specific audience. This can be a language/locale policy concern when a skill appears to assume a specific language without user opt-in.
The skill manifest and the rest of the README consistently position the tool as a Xiaohongshu-focused analytics utility for searching public notes, note details/comments, and creator post lists. Line L25 explicitly states '获取抖音评论详情', which describes a Douyin capability outside that stated Xiaohongshu scope.
Automatically saving all task results to logs/ can persist scraped note details, comments, URLs, and analysis outputs on disk without clear user consent, retention limits, or access controls. In shared environments, CI runners, or synced workspaces, this increases the risk of unintended disclosure of collected platform data and operational metadata.
This markdown file uses Chinese exclusively for the skill changelog and does not indicate that users can choose another language or that the skill is intentionally limited to a Chinese-language or region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.
The document operationalizes collection and analysis of Xiaohongshu public notes, comments, and creator post data, but it provides no warning or guardrails about privacy, applicable platform terms, or lawful/appropriate handling of user-generated content. Even when content is publicly accessible, large-scale scraping, comment harvesting, and downstream profiling can create compliance, privacy, and misuse risks, especially for competitor monitoring and KOL screening workflows.
This code performs outbound HTTPS requests and can send serialized request data via req.write(data), but the file contains no comments, logging, or other user-visible disclosure explaining that user or system data may be transmitted. For code files, outbound network transmission is safety-relevant when there is no accompanying warning or explanation in the file.
Multiple user-visible error messages in this file are hard-coded in Chinese, including authentication and network failures, with no indication that the user can choose another language. This is a natural-language policy concern because the skill enforces a specific language/locale without opt-in or documented justification.
This JavaScript file contains multiple user-facing error strings in Chinese, such as the validation messages printed via utils.printError. Under the policy rule for language/locale, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy violation.
The manifest describes a tool for searching public Xiaohongshu notes, viewing note details and comments, and listing a creator's public works. In this file, the implementation additionally depends on a separate credentialed service via GUAIKEI_API_TOKEN and task-creation/task-fetch API calls, which is an extra capability not evident from the stated user-facing purpose.
This code reads a credential from the GUAIKEI_API_TOKEN environment variable and sends the user-supplied Xiaohongshu URL to create/get detail tasks. While the CLI prints the URL and task status, it does not clearly disclose that data is being sent to an external service or warn about privacy implications in user-facing messaging.
The manifest emphasizes searching and viewing public Xiaohongshu data for analysis use cases, which implies retrieval-oriented behavior. This file also writes the full output to a JSON log file on disk, adding local persistence behavior that is not described in the manifest.
The CLI persists the fetched blogger-post results to a local JSON file, which goes beyond transient querying and can create unintended at-rest data exposure. Even if the source content is public, saved result sets may contain aggregated profile/post metadata that remains on disk, can be accessed by other local users or processes, and may violate user expectations for a read-only inspection tool.
The tool sends user-provided keywords and parameters to an external API as part of its core function, but this file does not clearly disclose that transfer at the point of use. In a data collection/search skill, external transmission is expected, but lack of explicit notice can still create privacy and compliance risk when users input sensitive research terms.
No suspicious patterns detected.