Back to skill

Security audit

xhs-strategy-scan

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform the advertised Xiaohongshu research tasks, but it needs review because it sends an API token in URL query strings and automatically saves retrieved data and URLs to plaintext local logs.

Review before installing. Use only for public Xiaohongshu data you are allowed to process, keep GUAIKEI_API_TOKEN private and rotate it if exposed, and treat the generated logs directory as sensitive because it may contain research history, Xiaohongshu URLs with xsec_token values, comments, profile details, and retrieved content.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:75
Finding

API Credential Transmitted in URL Query Parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/xiaohongshu/detail-cli.js:143
Finding

Automatic Plaintext Retention of Request URLs and Retrieved User Data

Content
View full analysis
Remediation
View remediation
` or `--save`. 2. Do not persist successful API results by default. 3. Redact sensitive URL parameters before printing or storing URLs: ```javascript function redactUrl(input) { const parsed = new URL(input); if (parsed.searchParams.has("xsec_token")) { parsed.searchParams.set("xsec_token", "[REDACTED]"); } return parsed.toString(); } ``` 4. Store only the minimum fields needed for the requested task. 5. Create directories and files with restrictive permissions where supported: ```javascript await fs.promises.mkdir(directory, { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, content, { mode: 0o600, }); ``` 6. Add configurable retention controls and a cleanup command for old logs. 7. Document clearly that retrieved content and request metadata may be written locally. 8. Prevent accidental repository inclusion by adding `logs/` to `.gitignore`. 9. For environments requiring archival, support encrypted output or require the caller to supply a protected destination. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (48)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码片段只实现了通用的命令行参数处理辅助函数(parseArgs、readValueAfterFlag、buildHelp),属于基础支持组件。它没有执行任何与小红书相关的网络请求、公开笔记搜索、详情查询、评论获取、博主作品抓取或运营分析逻辑。根据评估标准,虽然这可能是更大技能中的底层工具文件,但就该代码片段本身而言,其实际行为与声明用途存在明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是面向小红书公开内容抓取与分析的数据工具,但给出的代码片段仅实现了本地日志文件写入功能,没有体现任何搜索笔记、获取详情/评论、抓取博主作品或数据分析相关逻辑。虽然日志功能可能是辅助实现细节,但就该代码片段本身而言,其行为与声明的核心能力并不一致,且涉及未声明的本地文件系统写入能力。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a Xiaohongshu data collection and analysis tool with multiple user-facing retrieval capabilities. The supplied code chunk does not implement any of those behaviors. Instead, it is a small utility that accesses the local filesystem to read package.json and return the package name. This is materially different from the declared purpose, so the description does not accurately represent the provided code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

从提供的代码片段看,代码只包含一个通用工具模块,用于打印横幅和日志,不涉及网络请求、数据抓取、搜索、详情查询、评论获取或分析逻辑。声明描述的是一个面向小红书运营分析的数据采集与洞察工具,而实际代码片段的直接行为仅是终端输出辅助功能,主目的与声明严重不一致。虽然这可能只是整体项目中的一个支持性文件,但按当前“供评估的代码片段”来看,其行为并未体现声明中的核心能力,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 260)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 271)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 283)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not clearly warn users that searched keywords, note URLs, profile URLs, comment data, and derived analytics may persist on disk. In a data-scraping and competitor-analysis tool, this creates a real privacy and operational-security risk because sensitive research activity and collected third-party content may be retained longer than intended and exposed to other local users, backups, or downstream sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file documents capabilities to retrieve public note details, comment content, and creator post histories for analysis, including competitor monitoring and sentiment analysis. Under SQP-2 for markdown files, descriptions that could affect user data or privacy should include warnings, but these sections provide operational guidance only and omit any disclosure about handling third-party content, privacy expectations, or compliance considerations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup instructions require a live API credential (GUAIKEI_API_TOKEN) but do not warn users to keep it secret, avoid hardcoding it, or prevent it from being printed in logs, shared in screenshots, or committed to repositories. In agent/tooling environments, omission of secret-handling guidance materially increases the chance of credential exposure and subsequent unauthorized API use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code sends a token and note URL to remote API endpoints via postJson/getJson, which is a network operation involving potentially sensitive user or system data. Although the docstrings describe parameters, they do not explicitly warn users that the token and URL are transmitted to an external service, and there is no confirmation or user-facing disclosure in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JavaScript file contains natural-language comments and user-facing CLI messages exclusively in Chinese, including thrown errors and generated help text. Under the stated policy, forcing a specific language without offering user choice or documenting a justified locale restriction is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The user-facing strings at L22-L25 are entirely in Chinese, and the file gives no indication that the skill is China-specific or that users can opt into another language. This creates a natural-language locale policy issue because the skill imposes a language choice by default rather than offering flexibility or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits user-facing error messages in Chinese (日志文件名必须是非空字符串, 日志内容必须是非空字符串) and later continues the same pattern for success/error output. The file provides no indication that the skill is region-specific or that users can choose their language, which creates a language-policy violation under the stated rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The success and failure messages shown to users are hardcoded in Chinese (已保存到, 日志写入失败). Because the file contains no opt-in, translation support, or documented regional scope, it appears to force a specific locale in violation of the natural-language policy rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Multiple user-visible error messages in this file are hard-coded in Chinese, including request failures and parameter validation text, with no mechanism to respect user language preference. The policy calls for flagging forced language/locale behavior when no opt-in or documented locale constraint is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.