T09 · Insecure Skill Coding Practices
- Location
src/utils/request.js:76- Finding
API Credential Transmitted in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it claims, but it handles API tokens and collected social-media data in ways users should review before installing.
Install only if you are comfortable sending Xiaohongshu keywords, URLs, and collected results to the Guaikei API and storing full outputs locally. Treat GUAIKEI_API_TOKEN and xsec_token-bearing URLs as sensitive, review or delete the logs directory regularly, and avoid using this on shared workspaces without log controls.
src/utils/request.js:76API Credential Transmitted in URL Query Strings
src/utils/log.js:5Complete API Results and Token-Bearing Source URLs Persisted in Plaintext Logs
声明描述的是一个面向小红书公开内容采集与分析的业务技能,但提供的代码片段仅是通用参数解析器(parseArgs、readValueAfterFlag、buildHelp),用于处理 CLI 输入和帮助信息生成。这类代码最多只是某个命令行工具的配套基础设施,不能证明该技能实际具备声明中的核心功能。根据评估标准,当前代码的主要用途与声明的主要用途存在实质性差异,应判定为不匹配。
声明描述的是面向小红书公开数据的搜索、抓取和分析能力,而提供的代码片段没有任何与小红书、网络请求、笔记检索、评论获取或数据分析相关的行为。相反,它执行的是本地日志文件写入,这是与声明的主要用途明显不同的能力。虽然日志功能可能是辅助实现细节,但当前代码片段本身只体现日志落盘能力,无法支撑所声明的核心功能,因此描述与实际行为不一致。
声明描述的是一个面向小红书公开内容采集与运营分析的技能,但给出的代码片段仅包含一个辅助函数:通过 fs.readFileSync 读取本地 package.json 并返回包名。该行为既没有体现任何与小红书相关的网络请求、数据抓取、搜索、评论读取或博主作品列表获取逻辑,也没有实现描述中的分析能力。虽然读取本地 package.json 可能只是某个技能的辅助实现细节,但就本代码片段本身而言,其功能与声明的核心目的明显不符,因此应判定为描述与行为不匹配。
The declared description promises substantive Xiaohongshu data-access and analysis-related capabilities. However, the supplied code chunk contains only utility functions for printing a banner and formatted log messages to stderr. There is no evidence here of network access, scraping, querying public notes, fetching comments, or retrieving blogger post lists. Because the actual code behavior is materially different from the declared primary purpose, this chunk is a mismatch.
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"
Referenced artifact was not completely inspected
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |
Referenced artifact was not completely inspected
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |
Referenced artifact was not completely inspected
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |
The skill declares access to an environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool scope such as permissions or allowed-tools. In an agent setting, undeclared capability boundaries make secret access and command execution less auditable, increasing the risk of accidental token exposure or broader-than-expected runtime access.
The documentation emphasizes broad data collection and comprehensive result returns, while also describing automatic saving of outputs. Without stated minimization, access controls, or retention limits, this encourages over-collection and persistence of potentially sensitive operational data such as target accounts, search terms, and harvested content.
The README asserts the tool only accesses public Xiaohongshu data and does not involve privacy-sensitive collection, yet the documented workflow depends on xsec_token-bearing URLs and a third-party API token. This creates a misleading trust boundary: users may underestimate the sensitivity of supplied URLs, tokens, and any resulting data handling, which can lead to inappropriate sharing, weaker safeguards, or policy noncompliance.
The README states that all task results are automatically saved to logs, but it does not warn users that those logs may contain searched keywords, supplied URLs, comments, profile data, or other collected content. Silent retention increases the risk of unnecessary long-term storage, accidental disclosure, and privacy incidents, especially for shared workstations or team environments.
Saving results under filenames derived from timestamps plus keywords or links can directly expose user intent, monitored targets, and collected content through the filesystem, backups, or shared directories. If links contain signed parameters like xsec_token, those values may be preserved in filenames or nearby log content, increasing disclosure risk.
The document instructs users to collect note details, comments, and creator post lists from a public social platform, but it provides no privacy, consent, retention, or terms-of-service guidance. Even when content is publicly accessible, bulk collection and downstream analysis of comments and account activity can create privacy, compliance, and misuse risk, especially when used for profiling, monitoring, or sentiment analysis at scale.
This file contains natural-language content in comments and error/log messages exclusively in Chinese, such as the module description and retry messages. Under the policy, forcing a specific language without user opt-in or documented justification is a locale/language policy violation.
This file contains natural-language comments and CLI-facing strings such as errors and help text entirely in Chinese, which forces a specific language experience on users. The file does not indicate that the tool is region-specific or provide any user opt-in or alternative locale, matching the language/locale policy violation criteria.
The user-facing strings in this file are exclusively in Chinese, including warnings and recovery instructions, with no indication that the skill supports other languages or that Chinese is a required locale. This can violate language/locale policy when users are not given an explicit opt-in or alternative language path.
This code emits user-visible error messages in Chinese (日志文件名必须是非空字符串, 日志内容必须是非空字符串) and later success/error messages are also Chinese-only. That enforces a specific language for the skill's interaction without offering the user any locale choice or documenting a justified region-specific constraint.
No suspicious patterns detected.