Back to skill

Security audit

多社交平台内容同步

Security checks for vulnerabilities and agentic risk

Overview

The skill is a high-impact social posting automation package whose documentation overstates implemented publishing behavior and lacks sufficient safeguards for accounts, sessions, CAPTCHA handling, and scheduled/batch posting.

Review before installing. Treat this as a prototype, not a reliable publishing tool: it may report success without posting. Do not run it against real social accounts until publishing is implemented, sandboxing is fixed, dependencies are pinned, cookie storage is secured, and live batch/scheduled posting requires explicit confirmation or dry-run review.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/distribute.py:464
Finding

Chromium Browser Sandbox Explicitly Disabled

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:4
Finding

Unpinned and Unverified Third-Party Dependencies

Content
View full analysis
=1.40.0 # selenium>=4.15.0 # 可选,如需使用 Selenium # 图片处理 Pillow>=10.0.0 # 配置解析 PyYAML>=6.0.1 # 验证码识别(可选) # easyocr>=1.7.0 # paddlepaddle>=2.5.0 # pytesseract>=0.3.10 # 其他工具 requests>=2.31.0 python-dateutil>=2.8.2 ``` ### Technical Analysis All active dependencies use open-ended minimum-version constraints. No lock file, exact versions, or package hashes are supplied. Consequently, the same installation command can resolve different package and transitive-dependency versions over time. This is not evidence that any listed package is malicious. The security concern is that installation implicitly trusts any future release satisfying the lower-bound constraint. A compromised package account, malicious release, dependency takeover, or unexpected incompatible update could therefore affect installations without any change to the audited repository. Python packages and their build backends can execute code during installation. The absence of cryptographic hash verification also means the project does not independently constrain the exact artifacts accepted by the package installer. ### Attack Path 1. An attacker compromises a direct or transitive dependency's release channel, or publishes a malicious future version under an otherwise trusted package name. 2. The malicious version still satisfies the project's `>=` constraint. 3. A user follows the documented `pip install -r requirements.txt` command. 4. The package resolver selects and downloads the malicious or compromised release. 5. Installation-time code or imported runtime code executes with the privileges of the user performing the installation or running the Skill. ### Impact Assessment Successful dependency compromise could execute arbitrary Python code with the privileges of the installing or e ...[truncated 465 chars]
Remediation
View remediation

other

Note
Location
scripts/distribute.py:620
Finding

Distribution Operation Reports Success Without Publishing Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (39)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 176)May include surrounding context.

bash
# 清除登录缓存
rm -rf data/cookies/*

# 强制重新登录
python3 scripts/distribute.py --relogin

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The declared description presents a full-featured cross-platform publishing automation tool triggered by Xiaohongshu posting and supporting media adaptation, metadata filling, and captcha processing. The supplied code chunk does not implement those capabilities directly. Instead, it performs batch orchestration: reading note IDs, optionally generating placeholder recent IDs, calling an external distribute.py script, spacing executions, and printing a summary. While this wrapper is related to content distribution in a broad sense, its actual behavior is materially narrower than the declared functionality, and several advertised capabilities are absent from the code shown.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

该描述与代码存在实质性不匹配。描述强调这是一个可用的“自动分发工具”,核心价值在于:从小红书获取已发布内容,并自动同步发布到抖音、视频号、快手。代码确实包含若干与该目标相关的支撑模块,例如图片按平台比例处理、标题/描述/标签截断与补充、验证码处理辅助、以及浏览器自动化基类。但最关键的能力并未真正实现:_fetch_source_content 只是返回硬编码/示例内容,明确带有 TODO;_distribute_to_platform 也没有真实执行任何平台登录或发布动作,只是处理内容后输出“发布成功”日志并返回 True。因此,代码更像是“分发工具脚手架/原型”,而不是描述中的已实现自动分发系统。此外,描述中的“在小红书发布后”暗示某种自动触发或监听机制,但代码只有 CLI 参数入口,没有触发器。验证码方面也并非完全自动,短信验证码需要用户手动输入。综合来看,声明的核心功能成熟度和自动化程度明显高于代码实际行为,应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

声明描述的是一个在“小红书发布后”自动同步到多个平台的分发工具,并强调内容处理与验证码处理能力;但提供的代码片段实际实现的是一个独立的定时调度器。它通过解析命令行参数计算下一次运行时间,循环等待,并在到点后调用 scripts/distribute.py。也就是说,该代码的直接行为是‘定时执行分发脚本’,而不是监听“小红书发布后”事件,也没有在该片段中实现图片处理、标题标签填写或验证码处理。定时执行可以被视为分发系统的相关辅助功能,但它属于声明中未提及的重要触发/调度能力,因此描述与实际代码行为存在实质性不匹配。

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The documented use of rm -rf data/cookies/* is a destructive shell operation with wildcard deletion. Even though the target path is limited, encouraging users or agents to run recursive forced deletion via shell increases the risk of accidental data loss, path confusion, or abuse if variables, working directory assumptions, or symlinks are involved.

Content

Scanner excerpt · SKILL.md (reported line 358)May include surrounding context.

bash
# 清除登录缓存
rm -rf data/cookies/*

# 强制重新登录
python3 scripts/distribute.py --relogin

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code unconditionally logs and returns publication success even though no browser or app publishing logic exists. In an automation skill that claims cross-platform distribution, this creates a dangerous false-success condition that can cause operators to believe content was propagated when it was not, undermining auditability and operational trust.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README markets automatic cross-platform synchronization, batching, scheduling, and staggered posting without a clear risk disclosure that such automation can trigger anti-abuse systems, account bans, or platform-integrity issues. Given the skill’s purpose is multi-platform posting automation, the missing warning makes unsafe or policy-violating use more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly promotes automated CAPTCHA handling and even suggests third-party CAPTCHA services, but does not warn that CAPTCHA images can contain sensitive session-linked challenges or that outsourcing them may expose account activity and violate platform controls. In a browser automation skill that logs into multiple social platforms, this materially increases privacy, account lockout, and policy-evasion risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill documents shell commands and file operations but does not declare any tool scope such as permissions or allowed-tools. In an agent environment, undeclared shell/file capabilities reduce least-privilege controls and can let the skill perform actions users or reviewers did not explicitly authorize.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill promotes automatic cross-platform posting without an upfront warning that it can publish user content to multiple external services and potentially affect account standing, privacy, or compliance with platform rules. In this context, the omission is more dangerous because the skill automates actions across several accounts and even discusses evasion-style measures like random delays and human-like simulation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This manifest contains all human-readable comments and labels in Chinese, which imposes a specific language on operators without any visible opt-in or alternative locale support. Under the stated policy, a forced language choice in natural-language content is a reportable locale-policy issue unless it is explicitly documented as region-specific or optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This manifest contains only Chinese labels and comments, which effectively imposes a specific language on users and maintainers. The file does not indicate that the skill is region-specific or provide any opt-in or alternative language support, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation describes handling SMS verification, cookies, usernames, and account configuration without any privacy or security guidance for sensitive data storage and use. This is dangerous because operators may store phone numbers, session cookies, and login artifacts insecurely, leading to account takeover, privacy breaches, or unauthorized publishing if those credentials are exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The API documentation exposes automation commands that can publish content to third-party platforms, alter account state, and trigger irreversible external actions, but it does not warn operators about these side effects or require explicit confirmation patterns. In a multi-platform posting tool, missing safety guidance increases the chance of accidental mass posting, misuse of connected accounts, and unintended data propagation across services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The changelog explicitly advertises automated CAPTCHA handling, randomized delays to simulate human behavior, and staggered posting to avoid platform risk controls, but provides no warning about account bans, legal/compliance issues, or platform Terms of Service violations. In the context of a multi-platform automation skill, this materially increases the risk that users will deploy evasion features for abusive automation or unauthorized account activity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire guide is written exclusively in Chinese and all example titles, tags, and workflow guidance assume Chinese-language output and Chinese platforms, without any note that this is a locale-specific guide or that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The batch tool automatically invokes a subordinate distribution script that can publish content to external platforms, but this file provides no explicit confirmation prompt, dry-run safeguard, or clear warning at execution time about those side effects. In an agent skill context, this increases the risk of unintended mass posting if the script is triggered with the wrong inputs or by a user who does not fully understand that real external actions will occur.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/batch_distribute.py (reported line 122)May include surrounding context.

python
cmd.append("--use-app")
        
        try:
            result = subprocess.run(
                cmd,
                capture_output=True,
                text=True,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring presents the skill entirely in Chinese and does not indicate any language choice or locale constraint. Under the policy rule, forcing a specific language without offering user opt-in or documenting a justified regional limitation is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module and manifest describe a tool that fetches published content from 小红书 and redistributes it, and this method is documented as source-content retrieval. In reality, the implementation explicitly says it is a simplified stub and returns fixed sample data instead of actually fetching source posts, which contradicts the documented intent of the function.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script is designed to automatically perform repeated external posting actions on a schedule once launched, without any in-code confirmation, dry-run mode, rate-limit safeguard, or explicit warning before each run. In the context of a multi-platform content distribution skill, this increases the risk of unintended mass posting, policy violations, account restrictions, or accidental propagation of bad content across several services.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/schedule.py (reported line 108)May include surrounding context.

python
cmd.append("--use-app")
        
        try:
            result = subprocess.run(
                cmd,
                capture_output=True,
                text=True,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language instructions and examples are entirely in Chinese, and the file does not indicate that this is a region-specific skill or offer users an explicit language choice. Per the policy, forcing a specific language without opt-in can be a locale-policy issue unless the constraint is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file's human-readable instructions and labels are entirely in Chinese, beginning with the title and warning comments. Under the policy rule for natural-language issues, this can be considered a locale/language constraint because no alternative language, opt-in, or justification for a Chinese-only audience is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This YAML file’s human-readable comments and labels are entirely in Chinese, which indicates a fixed language choice in the skill’s natural-language surface. The file does not document that the skill is China-specific or offer any language/locale choice, so it may violate a language/locale policy requiring user opt-in or justified locale constraints.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.