Back to skill

Security audit

xhs-schedule-track

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Xiaohongshu data tool, but it handles the API token and target links in ways that can expose them in URLs and saved logs.

Review before installing. Only use this if you are comfortable sending your Xiaohongshu keywords or links and GUAIKEI_API_TOKEN to guaikei.com. Treat the token as a secret, avoid sharing command output or logs, inspect/delete the logs directory after sensitive research, and rotate the token if you believe it may have been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:83
Finding

API Credentials and Sensitive Request Data Exposed Through URL Query Strings

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (54)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

该代码片段仅包含参数解析与帮助文本生成的基础设施函数(parseArgs、readValueAfterFlag、buildHelp),属于通用 CLI 支撑模块。按照评估标准,支持性实现细节本身不应视为问题;但这里提供的代码与声明用途之间几乎没有直接对应的业务行为,既未访问小红书相关资源,也未实现任何所宣称的核心功能。因此,就这段代码本身而言,描述与实际行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是面向小红书公开内容检索与分析的数据抓取/查询能力,而代码片段实际仅实现了本地日志写入功能,没有体现任何小红书搜索、笔记详情获取、评论抓取、博主作品列表抓取或数据分析逻辑。虽然日志记录可能是某个更大系统的辅助模块,但就该代码片段本身而言,其行为与声明的核心用途无直接对应关系,且包含未在描述中提及的本地文件系统写入能力,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a feature-rich Xiaohongshu data collection and analysis tool. However, the supplied code chunk contains only a small utility that reads package.json from the local filesystem and returns the package name. This is materially different from the declared purpose and does not implement any of the described capabilities. While this may be a supporting helper in a larger project, based on the supplied code chunk alone, the actual behavior does not match the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description describes a full-featured Xiaohongshu data collection and analysis tool. However, the supplied code only contains utility functions for printing a banner and formatted logs. While logging can be a supporting detail in a larger tool, this specific code chunk does not actually implement any of the declared core capabilities. Therefore, for this chunk, the description does not accurately represent what the code actually does.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 260)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 271)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 283)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill declares an environment variable dependency (GUAIKEI_API_TOKEN) but does not define an explicit tool/permission scope such as permissions or allowed-tools. In an agent environment, missing scope declarations can cause overbroad access assumptions or make secret usage insufficiently constrained and auditable, especially for a third-party API integration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description and all usage instructions are written exclusively in Chinese and repeatedly prescribe Chinese natural-language trigger examples, which can amount to a locale/language constraint. The file does not state that other languages are supported or give users an opt-in choice, so it effectively forces a specific language without documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that all task results are automatically saved under a local logs directory, but it does not clearly warn users that fetched note content, comment data, profile links, and search terms may persist on disk. For a scraping/data-collection tool, this creates a real privacy and operational security risk because sensitive research targets or collected public data may be exposed to other local users, backups, or downstream tooling without the operator realizing it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This is a markdown file, so SQP-2 applies to missing user warnings in the skill description. The document explains collecting public content, comments, and competitor account data, but it does not warn users that the skill will retrieve third-party platform data and may process potentially sensitive URLs, comments, or account information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

For markdown files, SQP-2 covers omitted warnings about behaviors affecting privacy or system integrity. The file tells users to set an API token in the environment, but does not warn that this is a secret credential that must not be exposed in logs, prompts, screenshots, or shared command history.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code sends the provided API token as part of an HTTP request, which is a safety-relevant data transmission. Although the function docstrings name the parameter as a token, there is no explicit user-facing warning, confirmation, or comment disclosing that credential data will be sent to a remote API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function performs a network call that includes the API token and the user-supplied URL in request parameters. This is a data transmission that can affect user privacy or credential handling, and this file does not provide an explicit warning or disclosure beyond basic parameter naming.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends the provided API token in HTTP requests when creating a search task, which is a sensitive credential-handling and network transmission operation. Although the JSDoc names the parameter as an API token, there is no user-facing warning, confirmation, or explicit disclosure in the code about transmitting credentials to the remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The token and search parameters are sent via a GET request, which commonly places sensitive values into URLs. URLs may be stored in browser history, intermediary proxies, server access logs, monitoring tools, and referrer metadata, increasing the chance of token leakage and unauthorized API use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The user-facing error and info messages are entirely in Chinese, which imposes a specific language on users. There is no indication that the skill is region-specific or that users can opt into another language, which violates the natural-language policy criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.