Back to skill

Security audit

xhs-topic-track

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Xiaohongshu public-data lookup tool, but users should understand that it sends queries to guaikei.com and saves result JSON locally.

Install only if you are comfortable sending Xiaohongshu search terms or links to the guaikei.com API with your GUAIKEI_API_TOKEN, and treat the generated logs directory as containing potentially sensitive business research data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding
The top-level description frames the skill as keyword-based reputation monitoring, but the body expands behavior to direct note retrieval, profile scraping/monitoring, and reliance on a third-party API service. This mismatch can mislead operators about data flows and scope, increasing the chance that users provide sensitive URLs or authorize external processing they did not expect.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The README describes materially broader capabilities than the manifest summary, including competitor-account monitoring and KOL screening beyond simple brand/product keyword tracking. This scope mismatch can mislead users and reviewers about what data the skill collects and how it may be used, reducing informed consent and weakening security review.

Description-Behavior Mismatch

Low
Confidence
92% confidence
Finding
The README states that all task results are automatically saved to local logs, but this persistence behavior is not clearly surfaced in the higher-level description. Undisclosed automatic storage of fetched content, keywords, and URLs can expose sensitive business research, account targets, or monitoring activity to other local users, backups, or downstream tooling.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The changelog advertises capabilities beyond the declared scope of simple brand/product keyword monitoring, including note-detail/comment analysis, creator work monitoring, hot-note mining, competitor analysis, KOL screening, and trend monitoring. This scope expansion increases the chance of undeclared data collection, overbroad access, and user/operator misunderstanding about what the skill may do, which is a genuine security and governance risk even if not overtly malicious.

Description-Behavior Mismatch

Low
Confidence
88% confidence
Finding
The CLI writes fetched results to a local JSON file containing collected post data without clearly communicating that persistence will occur. In a monitoring context, these results can include user-generated content and metadata, creating unintended local data retention, exposure to other local users/processes, and compliance/privacy issues if the host is shared or logs are broadly accessible.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The CLI writes full search results to a local JSON file as a side effect, but this behavior is not clearly disclosed to the user in the help text or stated skill purpose. Because results may contain user-generated content, brand-monitoring data, or other potentially sensitive business information, silent persistence increases the risk of unintended local data retention and exposure.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
Automatic saving of all task results to a logs directory without a clear warning means fetched platform data and user-supplied keywords or links may be written to disk unexpectedly. In this skill's context, those inputs can reveal sensitive market-intelligence efforts, brand-monitoring targets, or internal research topics, making local disclosure and accidental retention more dangerous.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The CLI persists fetched note/comment data to a local JSON file automatically after successful execution, but this file does not provide an explicit warning, consent prompt, or storage control to the user. Because the retrieved content may include personal opinions, account identifiers, or other sensitive user-generated data, silent local retention increases the risk of unintended disclosure through shared machines, backups, logs, or later exfiltration.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
Persisting result data to disk without a user-facing warning reduces informed consent and can leak collected social-media data beyond the immediate CLI session. Because the skill is described as monitoring public content, silent storage is more dangerous in practice: operators may assume ephemeral processing while the tool leaves durable artifacts that can later be accessed, copied, or mishandled.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
Search results are persisted locally without a clear user-facing warning at execution time, creating an unexpected privacy and data-retention side effect. Users may assume the command only performs a search, while it actually leaves behind a local artifact containing collected content and metadata that could later be accessed by other users or processes on the same system.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.