Back to skill

Security audit

xhs-voice-collect

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Xiaohongshu public-data collection tool that uses a third-party API and saves results locally, so users should handle queries and logs thoughtfully.

Before installing, confirm you are comfortable sending Xiaohongshu keywords and URLs to the GUAIKEI third-party API and storing returned public-platform data in local logs. Use it for public data only, keep the API token private, and clean up logs when queries or results are sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The file adds undisclosed vendor-controlled private-token gating and a personal contact/promotional recovery flow that is not aligned with the stated skill purpose of collecting public Xiaohongshu data. This creates a supply-chain and trust risk: operators may be pressured to obtain credentials through an off-platform social contact, and the skill’s real dependency model is obscured from users and reviewers.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The CLI writes the full fetched result set, including note details and comments, to a local JSON file by default. Even if the source content is public, automatic persistence expands exposure, creates an unexpected retention surface, and may capture identifiers or sensitive user-generated text without the operator realizing it.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The README states that all task results are automatically saved to the logs directory, but it does not clearly warn users that searched keywords, queried URLs, and collected public-platform data may be persisted on disk. This can create unintended local data exposure, especially on shared machines or in team environments where logs may be backed up, synced, or accessed by others.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation instructs users to configure an API token and run scripts against an external service, but it does not clearly disclose that user-supplied keywords, note URLs, profile URLs, and related query data will be transmitted to a third-party API. This creates a transparency and data-handling risk: users may unintentionally send sensitive research targets, tracking URLs, or business intelligence queries off-platform without informed consent.

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The CLI persists fetched comment results to a local JSON file automatically, and those results may contain personal data, user-generated content, or sensitive business intelligence derived from public notes/comments. Because this happens without an explicit warning, consent prompt, configurable opt-out, or visible retention controls in this file, users may unintentionally store scraped data on disk where it can later be exposed through shared machines, backups, logs, or mishandled artifacts.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The tool sends a user-supplied URL to an external API and later stores the returned detail data locally, but it does not provide an explicit warning or consent mechanism about transmission and retention. In a data-collection skill focused on scraping/public-content analysis, this increases privacy and compliance risk because operators may unknowingly export or retain large amounts of comment data.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The CLI persists full search output to a local JSON file named with the user keyword, without explicit user consent or any warning that data will be stored on disk. In this skill’s context, search terms may reveal sensitive business research, competitive intelligence targets, or personal interests, and the saved results may also contain public account data that users did not intend to retain locally, increasing exposure on shared systems or in CI/agent environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.