Back to skill

Security audit

xiaohongshu-title

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrowly scoped Xiaohongshu title-writing helper with no evidence of hidden code execution, data access, persistence, or credential use.

Install this if you want Chinese Xiaohongshu/RedNote-style title ideas optimized for engagement. Be aware that it may shape generic topics into persuasive marketing titles unless you invoke it only for that use case, and review generated claims for accuracy and advertising compliance before publishing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction hard-codes a specific language and stylistic objective ('native, emotional, visually structured' and optimized for CTR) without checking whether the user wants that format. This can override user preference and steer outputs toward manipulative or mismatched content, though the impact is limited because it affects presentation rather than granting access or executing code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is configured to trigger on essentially any user-provided raw text or topic, which makes activation overly broad and increases the chance the skill will inappropriately influence unrelated conversations. In an agent setting, this can cause prompt hijacking of general tasks, reduce user control, and apply persuasion-oriented content generation outside the intended Xiaohongshu title use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The examples and category labels are entirely written in Chinese, presenting the skill behavior as Chinese-only by default. There is no indication that users may opt into another language or that the locale restriction is intentionally limited to a Chinese-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The reference material is entirely framed around Chinese keywords, Chinese examples, and Chinese compliance terms, which effectively prescribes a specific language/locale for outputs. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific; neither is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The docstring states the function filters titles based on 'Xiaohongshu algorithm preferences,' which implies a fixed locale/platform context. Because the file does not offer any user choice or explain that this is intentionally limited to a region-specific workflow, this can be read as a language/locale policy constraint embedded in natural language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.