Back to skill

Security audit

xhs-word-cloud

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it handles an API token and collected data in ways users should review before installing.

Install only if you are comfortable sending Xiaohongshu keywords, note/profile URLs, limits, and your GUAIKEI_API_TOKEN to guaikei.com. Treat the token like a secret, monitor and rotate it if needed, and regularly delete the generated logs directory if saved comments or competitive research should not persist locally.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/request.js:76
Finding

API Credential Exposed in URL Query Strings

Content
View full analysis

Vulnerability Details

File Locations:

  • src/utils/request.js:76-96
  • src/utils/request.js:101-117
  • src/api/search.js:23-26
  • src/api/search.js:52-59
  • src/api/detail.js:20-23
  • src/api/detail.js:46-50
  • src/api/comment.js:20-23
  • src/api/comment.js:46-50
  • src/api/post.js:20-23
  • src/api/post.js:46-50

Vulnerability Type: Sensitive credential exposure through URL query parameters
Risk Level: Medium

Vulnerable Code

The API modules include the credential in the request parameter object. For example, task creation in src/api/search.js:23-26 uses:

js
return await postJson(
  "/api/xiaohongshu/note-search/keyword",
  { _: Date.now(), token: token },
  { keyword, type, sort, time, limit },
);

Task polling in src/api/search.js:52-59 also includes the token:

js
const res = await getJson("/api/xiaohongshu/note-search/info", {
  _: Date.now(),
  token: token,
  keyword,
  type,
  sort,
  time,
  limit,
});

The same pattern appears in the detail, comment, and post API modules:

js
// src/api/detail.js
{ _: Date.now(), token: token }

// src/api/comment.js
{ _: Date.now(), token: token }

// src/api/post.js
{ _: Date.now(), token: token }

The request utility serializes these parameter objects directly into the URL. The complete relevant POST request construction in src/utils/request.js:76-96 is:

js
async function postJson(path, params, data) {
  if (!path || typeof path !== "string") {
    throw new Error("path 必须是非空字符串");
  }
  if (!params || typeof params !== "object") {
    throw new Error("params 必须是对象");
  }
  if (!data || typeof data !== "object") {
    throw new Error("data 必须是对象");
  }
  params.skill_name = skillName();
  const fullPath = `${path}?${querystring.stringify(params)}`;
  const jsonData = JSON.stringify(data);
  const options = {
    host: constants.BASE_URL,

...[truncated 3316 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove token from every query parameter object in:

    • src/api/search.js
    • src/api/detail.js
    • src/api/comment.js
    • src/api/post.js
  2. Pass credentials through an HTTP authorization header, preferably:

    js
    headers: {
      "Authorization": `Bearer ${token}`,
      "Content-Type": "application/json",
    }
    

    Refactor getJson and postJson to accept the token separately from ordinary request parameters so that callers cannot accidentally serialize it into the URL.

  3. If the remote API cannot accept bearer authentication, place the token in the HTTPS POST body for task creation and redesign polling authentication accordingly. Header-based authentication remains preferable.

  4. Configure the API server, reverse proxies, gateways, and observability platforms to redact:

    • Authorization headers
    • Existing token query parameters
    • Any other authentication or session values
  5. Rotate all tokens that may have already appeared in URL logs. Purge or restrict historical logs containing query strings according to the applicable retention policy.

  6. Add automated tests asserting that generated request paths never contain token=, api_key=, or equivalent credential parameters.

  7. Apply short token lifetimes, least-privilege authorization, server-side rate limits, usage monitoring, and immediate revocation support to reduce the impact of future credential exposure.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (49)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents an end-user Xiaohongshu data acquisition/analysis tool. However, the supplied code chunk only provides generic CLI support functions (parseArgs, readValueAfterFlag, buildHelp). It does not interact with Xiaohongshu, make network requests, process note/comment data, or perform any analytics. This is a materially different primary purpose, not merely a supporting implementation detail for the declared behavior when evaluated in isolation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是面向小红书公开内容的搜索、详情查看、评论获取和博主作品抓取能力,属于网络数据采集/查询型功能;而提供的代码片段实际只实现了本地日志写入辅助功能,没有任何与小红书数据搜索、抓取、评论读取或作品列表获取相关的逻辑。虽然日志功能可能是配套实现细节,但就该代码片段本身而言,其行为与声明的业务能力不一致,并且涉及未声明的本地文件系统写入能力。依据要求,代码执行了与声明主用途明显不同的能力,应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个面向小红书公开数据采集与分析的技能,而给出的代码片段仅通过 fs 读取本地 package.json 文件并返回技能/包名称。该行为与搜索小红书内容、抓取评论、获取博主作品等核心功能没有直接对应关系。虽然读取 package.json 可能是内部辅助实现,但就当前提供的代码而言,其实际行为与声明用途明显不一致,且唯一可见能力是本地文件访问而非小红书数据操作,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises substantial Xiaohongshu data operations functionality, including searching notes, fetching details/comments, and collecting creator post lists. However, the supplied code only contains helper functions for printing a banner and formatted log messages. While logging can be a supporting detail in a larger tool, this specific code chunk does not implement or demonstrate the declared core capabilities. Therefore, the description does not accurately represent what this supplied code chunk actually does.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 260)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
- "分析这条小红书笔记评论区的主要观点和负面反馈: node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 100"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 271)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
- "看这个小红书博主最近 20 条作品都在发什么: node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 20"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 283)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
| 看某篇小红书笔记的评论数据 | `src/xiaohongshu/comment-cli.js` | 笔记 URL | 该笔记的评论内容、评论者信息、互动数据 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is entirely in Chinese and presents the skill's usage context only in that language. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly justified, which is not provided here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example prompts and command-use guidance are written exclusively in Chinese, and the document does not offer an alternative language option or note that Chinese is merely an example. This can be read as requiring Chinese-language interaction rather than allowing user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states that all task results are automatically saved to the logs/ directory, but it does not clearly warn users that searched keywords, note URLs, comments, and collected public-profile data may persist locally. In a data-scraping and competitive-intelligence context, retained logs can expose sensitive business research, personal data from comments, or regulated content to other local users, backups, or later unintended disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file title and all natural-language content are presented only in Chinese, with no indication that language selection is optional or that the skill is region-specific. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code sends a note URL and API token to a remote endpoint via HTTP, which is a privacy- and credential-sensitive operation. Although the function comments describe parameters, there is no confirmation prompt or user-facing disclosure in the code indicating that user-supplied data and credentials will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The polling/query function transmits the API token, URL, and requested limit to a remote service. This is a network operation involving potentially sensitive user data, but the code only logs retry errors and does not provide any user-visible warning or confirmation about the data transmission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains natural-language content such as the module description and later retry messages exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JavaScript file contains natural-language comments, error messages, and help output exclusively in Chinese, including the generated CLI help and runtime errors. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code emits user-facing status and warning messages only in Chinese, including the operational guidance shown when the token is invalid. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly justified, which is not indicated here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.