Back to skill

Security audit

xhs-voice-collect

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it handles API tokens and collected social-media data in ways users should review before installing.

Install only if you are comfortable sending Xiaohongshu keywords, URLs, and collected results to the Guaikei API and storing full outputs locally. Treat GUAIKEI_API_TOKEN and xsec_token-bearing URLs as sensitive, review or delete the logs directory regularly, and avoid using this on shared workspaces without log controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credential Transmitted in URL Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/log.js:5
Finding

Complete API Results and Token-Bearing Source URLs Persisted in Plaintext Logs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (46)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书公开内容采集与分析的业务技能,但提供的代码片段仅是通用参数解析器(parseArgs、readValueAfterFlag、buildHelp),用于处理 CLI 输入和帮助信息生成。这类代码最多只是某个命令行工具的配套基础设施,不能证明该技能实际具备声明中的核心功能。根据评估标准,当前代码的主要用途与声明的主要用途存在实质性差异,应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是面向小红书公开数据的搜索、抓取和分析能力,而提供的代码片段没有任何与小红书、网络请求、笔记检索、评论获取或数据分析相关的行为。相反,它执行的是本地日志文件写入,这是与声明的主要用途明显不同的能力。虽然日志功能可能是辅助实现细节,但当前代码片段本身只体现日志落盘能力,无法支撑所声明的核心功能,因此描述与实际行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向小红书公开内容采集与运营分析的技能,但给出的代码片段仅包含一个辅助函数:通过 fs.readFileSync 读取本地 package.json 并返回包名。该行为既没有体现任何与小红书相关的网络请求、数据抓取、搜索、评论读取或博主作品列表获取逻辑,也没有实现描述中的分析能力。虽然读取本地 package.json 可能只是某个技能的辅助实现细节,但就本代码片段本身而言,其功能与声明的核心目的明显不符,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises substantive Xiaohongshu data-access and analysis-related capabilities. However, the supplied code chunk contains only utility functions for printing a banner and formatted log messages to stderr. There is no evidence here of network access, scraping, querying public notes, fetching comments, or retrieving blogger post lists. Because the actual code behavior is materially different from the declared primary purpose, this chunk is a mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 260)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 271)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 283)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill declares access to an environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool scope such as permissions or allowed-tools. In an agent setting, undeclared capability boundaries make secret access and command execution less auditable, increasing the risk of accidental token exposure or broader-than-expected runtime access.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The documentation emphasizes broad data collection and comprehensive result returns, while also describing automatic saving of outputs. Without stated minimization, access controls, or retention limits, this encourages over-collection and persistence of potentially sensitive operational data such as target accounts, search terms, and harvested content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README asserts the tool only accesses public Xiaohongshu data and does not involve privacy-sensitive collection, yet the documented workflow depends on xsec_token-bearing URLs and a third-party API token. This creates a misleading trust boundary: users may underestimate the sensitivity of supplied URLs, tokens, and any resulting data handling, which can lead to inappropriate sharing, weaker safeguards, or policy noncompliance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README states that all task results are automatically saved to logs, but it does not warn users that those logs may contain searched keywords, supplied URLs, comments, profile data, or other collected content. Silent retention increases the risk of unnecessary long-term storage, accidental disclosure, and privacy incidents, especially for shared workstations or team environments.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Saving results under filenames derived from timestamps plus keywords or links can directly expose user intent, monitored targets, and collected content through the filesystem, backups, or shared directories. If links contain signed parameters like xsec_token, those values may be preserved in filenames or nearby log content, increasing disclosure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document instructs users to collect note details, comments, and creator post lists from a public social platform, but it provides no privacy, consent, retention, or terms-of-service guidance. Even when content is publicly accessible, bulk collection and downstream analysis of comments and account activity can create privacy, compliance, and misuse risk, especially when used for profiling, monitoring, or sentiment analysis at scale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This file contains natural-language content in comments and error/log messages exclusively in Chinese, such as the module description and retry messages. Under the policy, forcing a specific language without user opt-in or documented justification is a locale/language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file contains natural-language comments and CLI-facing strings such as errors and help text entirely in Chinese, which forces a specific language experience on users. The file does not indicate that the tool is region-specific or provide any user opt-in or alternative locale, matching the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing strings in this file are exclusively in Chinese, including warnings and recovery instructions, with no indication that the skill supports other languages or that Chinese is a required locale. This can violate language/locale policy when users are not given an explicit opt-in or alternative language path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits user-visible error messages in Chinese (日志文件名必须是非空字符串, 日志内容必须是非空字符串) and later success/error messages are also Chinese-only. That enforces a specific language for the skill's interaction without offering the user any locale choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.