Back to skill

Security audit

ljh-xhs

Security checks across malware telemetry and agentic risk

Overview

The skill is mainly a Xiaohongshu content-analysis helper, but it also creates persistent local files and archives business context, so users should review its storage behavior before installing.

Install only if you are comfortable with the skill writing local state and saving business-analysis outputs in the workspace. Use it in a dedicated project directory, avoid sharing sensitive commercial details unless needed, and tell the agent not to create or update archives if you want a no-persistence run.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is described as a Xiaohongshu post decomposer, but it also performs onboarding persistence by checking for and creating local state files. This expands behavior beyond the declared purpose and introduces hidden statefulness, which can surprise users and create unnecessary privacy and integrity risks.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill mixes scoped content analysis with general business consulting intake, cross-tool archival behavior, and user-group promotion. This over-broad scope increases the chance of collecting or retaining unrelated business data and makes the skill's trust boundary unclear.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs the agent to create a local onboarding tracking file automatically on first run, without prior user warning or opt-in. Silent writes create consent, privacy, and integrity concerns, especially in environments where users do not expect tools to modify the filesystem.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill directs creation of brand archive files and saved deliverables in the current directory, but does not provide an upfront warning before these writes occur as part of normal operation. Persisting user business information without clear notice can expose sensitive commercial data and create unauthorized records.

Ssd 3

Medium
Confidence
96% confidence
Finding
The skill establishes persistent collection and storage of brand basics, audience, selling points, timelines, and deliverables across sessions without strong minimization limits. This creates avoidable retention of potentially sensitive business intelligence and increases exposure if the workspace is shared or later compromised.

Ssd 3

Low
Confidence
88% confidence
Finding
The onboarding flow records persistent onboarding status and a timestamp in a local file. While low severity, it is still unnecessary persistent tracking for a content-analysis skill and may violate user expectations in constrained or privacy-sensitive environments.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.