Back to skill

Security audit

xhs-report-generate

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated Xiaohongshu public-data purpose, but it needs review because it handles credentials and saved results in ways users may not expect.

Review this before installing. Use it only if you are comfortable sending your Guaikei API token, search terms, Xiaohongshu URLs, and request parameters to the third-party API service. Treat the generated logs directory as sensitive, especially when URLs contain xsec_token values or the research is business-sensitive. Prefer a version that moves the API token to an Authorization header, makes logging opt-in, redacts URL tokens, and documents retention/deletion practices.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
src/utils/request.js:76
Finding

API Credential Transmitted in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/log.js:5
Finding

Automatic Plaintext Persistence of Retrieved Data and Security-Bearing URLs

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.substring(0, 200); } if (safeFilename === "") { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outputFilename, content); utils.printSuccess(` → 已保存到 ${outputFilename}`); } catch (error) { utils.printError(`日志写入失败: ${error.message}`); } } ``` The complete successful response, including request metadata and API results, is passed to this function: ```js await log.taskWrite( `${startTime}_${keyword}_${type}_${sort}_${limit}_search.json`, JSON.stringify(finalOutput, null, 2), ); ``` ```js await log.taskWrite( `${startTime}_${validator.url2Name(url)}_detail.json`, JSON.stringify(finalOutput, null, 2), ); ``` The detail output embeds the submitted URL in the stored object: ```js const finalOutput = { status: "success", error_code: "OK", message: "详情任务完成", timestamp: new Date().toLocaleString(), request: { command: "detail", url: url, limit: limit, }, skill_metadata: { skill_version: constants.VERSION, runtime_ver ...[truncated 2533 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (45)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

代码片段仅包含 src/utils/args.js,一个通用 CLI 参数解析器。它负责读取命令行参数、处理 --help/-h、匹配 flag/alias、检查重复参数、必填参数、位置参数,并生成帮助文本。这属于底层辅助工具,不涉及任何小红书平台的数据访问、网络请求、内容抓取、搜索、评论读取或博主作品列表获取。根据评估标准,当前代码的主要用途与声明的技能用途存在实质性差异,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是小红书公开内容搜索、详情/评论抓取和数据分析相关能力;而给出的代码片段实际只实现了本地日志文件写入功能,使用 Node.js 的 fs/path 访问本地文件系统,在 logs 目录创建并写入文件。该行为与所宣称的核心业务能力没有直接对应关系,也涉及未在描述中体现的本地文件写入资源访问。虽然日志记录可视为辅助功能,但当前提供的代码片段本身并未体现任何小红书数据获取或分析逻辑,因此就“该代码块实际做什么”而言,和声明用途存在明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises substantial Xiaohongshu data retrieval and analysis-related functionality. However, the supplied code chunk only uses fs and path to locate package.json, parse it, and return pkg.name. This is materially unrelated to the declared end-user purpose. While it may be a small helper module, based on the provided chunk alone the actual behavior does not match the described capability set.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The supplied code chunk is a generic utility module for terminal output, using process.stderr/console.error to print a banner and formatted log lines. The declared description claims substantive Xiaohongshu data-access and scraping capabilities, but none of those behaviors appear in this chunk. Because the code shown has a materially different immediate purpose than the declared end-user functionality, this chunk does not accurately represent the declared description. While logging can be a supporting detail in a larger tool, based on this code alone the declared capabilities are absent.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description forces a single language/locale presentation for users by providing the activation and purpose text only in Chinese. The file does not offer an opt-in language choice or justify that the skill is intended exclusively for a Chinese-language or region-specific audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not warn users that those results may contain scraped URLs, search keywords, note details, or comment data. In a scraping and competitive-intelligence tool, this can lead to unintended retention of potentially sensitive business research or third-party content on disk, increasing exposure through local compromise, backups, or accidental sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This file documents capabilities that retrieve public note details, comments, and creator-post data for analysis, including sentiment and negative-opinion summarization, but it does not include any user-facing warning about privacy, responsible use, or the impact of collecting and analyzing third-party content. Under the markdown-file criteria for SQP-2, behaviors that may affect privacy should be disclosed in the skill description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The function sends potentially sensitive data, including an API token and a user-provided Xiaohongshu URL, to a remote endpoint via postJson. While the code has technical comments and retry error logging, it does not include any user-facing warning, confirmation, or disclosure about this network transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This network request transmits an API token together with the requested Xiaohongshu URL and limit to an external API endpoint. The file contains developer-oriented comments and retry logging, but no visible user disclosure that user or credential data is being sent over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits all user-facing status and recovery messages exclusively in Chinese, including warnings and setup instructions. For a general-purpose skill file, that imposes a language choice on users without opt-in or any documented region-specific justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The error messages in this file are hard-coded in Chinese, including credential and support guidance, which imposes a specific language on users. The file provides no locale selection, fallback, or indication that the skill is intentionally region- or language-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits all user-facing validation and error messages in Chinese, such as at L08, L13, L17, L21, L26, L54, L59, L64, and L68. Because the file does not provide any user opt-in, fallback, or documented justification for a Chinese-only locale, it creates a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The calls to createCommentTask and getCommentTask send user-provided inputs and likely associated metadata to a remote service, but the code offers no explicit disclosure that network requests will be made. The help text mentions a required API token, yet it does not clearly warn that the note URL and request parameters are transmitted off-host.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.