Back to skill

Security audit

guaikei·小红书笔记搜索

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Xiaohongshu data retrieval tool, but it handles credentials and saved results in ways users should review before installing.

Install only if you are comfortable sending Xiaohongshu keywords, URLs, xsec_token-bearing links, and your GUAIKEI_API_TOKEN to the Guaikei service. Treat the generated logs/ directory as sensitive, delete old result files when no longer needed, and prefer a token you can rotate because the implementation places it in request URLs rather than an authorization header.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credential Exposed in URL Query Strings

Content
View full analysis
{ return await postJson( "/api/xiaohongshu/note-search/keyword", { _: Date.now(), token: token }, { keyword, type, sort, time, limit }, ); }, ``` The polling request also contains the token: ```js async function getSearchTask(token, keyword, type, sort, time, limit) { return await withRetry( async () => { const res = await getJson("/api/xiaohongshu/note-search/info", { _: Date.now(), token: token, keyword, type, sort, time, limit, }); ``` The shared request implementation serializes those parameters directly into the URL: ```js async function postJson(path, params, data) { if (!path || typeof path !== "string") { throw new Error("path 必须是非空字符串"); } if (!params || typeof params !== "object") { throw new Error("params 必须是对象"); } if (!data || typeof data !== "object") { throw new Error("data 必须是对象"); } params.skill_name = skillName(); const fullPath = `${path}?${querystring.stringify(params)}`; const jsonData = JSON.stringify(data); const options = { host: constants.BASE_URL, path: fullPath, method: "POST", headers: { "Content-Type": "application/json", "Content-Length": Buffer.byteLength(jsonData), }, }; return await r ...[truncated 2722 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/log.js:5
Finding

Automatic Plaintext Persistence of Retrieved Data and URL Tokens

Content
View full analysis
|]/g, "_") .replace(/\.\.+/g, "_") .replace(/^\.+|\.+$/g, ""); if (safeFilename.length > 200) { safeFilename = safeFilename.substring(0, 200); } if (safeFilename === "") { safeFilename = `log_${Date.now()}`; } const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outputFilename, content); utils.printSuccess(` → 已保存到 ${outputFilename}`); } catch (error) { utils.printError(`日志写入失败: ${error.message}`); } } ``` Successful search results are persisted automatically: ```js await log.taskWrite( `${startTime}_${keyword}_${type}_${sort}_${limit}_search.json`, JSON.stringify(finalOutput, null, 2), ); ``` The detail, comment, and post commands use the same pattern and write their complete structured output to the `logs/` directory. ### Technical Analysis Every successful operation writes its complete result to disk without requiring an explicit output option. The stored JSON can contain: - Search keywords and ...[truncated 2606 chars]
Remediation
View remediation
` or `--save`. 2. Do not write result files by default when stdout already provides the structured result. 3. Redact sensitive URL parameters before serialization, including `xsec_token` and any future authentication-related fields. 4. Create files with restrictive permissions: ```js await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, }); ``` 5. Create the log directory with restrictive permissions where supported. 6. Implement configurable retention, automatic expiration, or documented cleanup procedures. 7. Avoid including raw request URLs in persisted metadata when a normalized, token-free identifier is sufficient. 8. Clearly disclose the exact stored fields, destination directory, retention behavior, and security implications in `SKILL.md`. 9. Add tests confirming that persisted output does not contain known sensitive query parameters. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (50)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation performs undeclared local file writes, that exceeds the stated read-oriented data retrieval purpose and can create persistence, data leakage, or tampering risks. Hidden write capability is especially concerning in agent skills because operators may assume the skill is non-mutating based on its description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the implementation performs undeclared local file writes, that exceeds the stated read-oriented data retrieval purpose and can create persistence, data leakage, or tampering risks. Hidden write capability is especially concerning in agent skills because operators may assume the skill is non-mutating based on its description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation performs undeclared local file writes, that exceeds the stated read-oriented data retrieval purpose and can create persistence, data leakage, or tampering risks. Hidden write capability is especially concerning in agent skills because operators may assume the skill is non-mutating based on its description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation performs undeclared local file writes, that exceeds the stated read-oriented data retrieval purpose and can create persistence, data leakage, or tampering risks. Hidden write capability is especially concerning in agent skills because operators may assume the skill is non-mutating based on its description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the implementation performs undeclared local file writes, that exceeds the stated read-oriented data retrieval purpose and can create persistence, data leakage, or tampering risks. Hidden write capability is especially concerning in agent skills because operators may assume the skill is non-mutating based on its description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the implementation performs undeclared local file writes, that exceeds the stated read-oriented data retrieval purpose and can create persistence, data leakage, or tampering risks. Hidden write capability is especially concerning in agent skills because operators may assume the skill is non-mutating based on its description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the implementation performs undeclared local file writes, that exceeds the stated read-oriented data retrieval purpose and can create persistence, data leakage, or tampering risks. Hidden write capability is especially concerning in agent skills because operators may assume the skill is non-mutating based on its description.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
- "看这篇笔记的详情和评论区: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
- "看这位博主最近 20 条作品: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
- "只拉这篇笔记的评论做舆情: node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares access to a sensitive environment variable (GUAIKEI_API_TOKEN) but does not define any explicit tool scope such as permissions or allowed-tools. This weakens least-privilege boundaries and makes it harder for a host agent to constrain what the skill may access or invoke, especially if the implementation grows beyond the documented behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation rules are broad enough to trigger on many general Xiaohongshu-related requests, including cases where the user did not explicitly ask for external data retrieval. Over-broad activation can cause unnecessary secret use, unexpected third-party data access, and accidental exfiltration of user-provided URLs or research intent to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not warn users that exported results may contain sensitive business intelligence such as competitor monitoring data, comment datasets, KOL screening results, and queried URLs. Automatic persistence increases the chance of unintended local exposure, retention beyond need, or accidental sharing, especially in team or shared-host environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s instructional content, examples, and operational guidance are all presented only in Chinese. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code sends an API token and a user-supplied note URL to a remote endpoint via postJson, but the file provides no user-facing warning, confirmation, or explicit disclosure beyond parameter docstrings. For code files, network calls that transmit user or system data should have some visible disclosure unless clearly covered elsewhere, and that is not evident in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The getJson call sends the API token and user-provided URL parameters to a remote API, yet there is no visible user-facing notice, confirmation, or warning in this file about that data transmission. Under the code-file criteria, network calls involving user or system data should not be silent unless the disclosure exists elsewhere and is explicit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

When the token is missing or invalid, the skill displays a hardcoded Chinese-language message directing the user to contact a specific WeChat number to obtain a private token. This creates an unapproved off-platform contact path and language-forcing behavior, which can be abused for social engineering, bypass normal support channels, and pressure users into sharing information or procuring credentials outside trusted workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Multiple natural-language messages in this file are hard-coded in Chinese, such as error responses and validation messages. The file does not indicate that the skill is region-specific or provide any user opt-in or fallback for language selection, which is a locale-policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Validation and network error messages such as '响应解析失败', '请求失败', and 'path 必须是非空字符串' are presented only in Chinese. Because these strings are user-visible and no locale choice or regional justification is provided in the file, they represent a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:15