Back to skill

Security audit

小红书文案创作

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Xiaohongshu copywriting helper that uses a RedFox API key and trend data, with some privacy and scoping cautions but no evidence of malicious behavior.

Install only if you are comfortable giving this skill a RedFox API key and sending Xiaohongshu search keywords to redfox.hk. Use it explicitly for Xiaohongshu note research or copywriting, and avoid sharing sensitive personal writing samples; non-confidential public drafts are a safer style reference.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The README instructs users to invoke the skill with broad natural-language phrases like 'Help me write a Xiaohongshu note...' and 'Find me trending ... notes recently,' which are highly likely to overlap with ordinary user requests in a general-purpose agent. This can cause unintended skill activation, routing sensitive or unrelated user prompts into this skill, especially since the metadata says it should run only in the main agent and not be delegated, increasing the chance of mis-scoped execution.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The README says users can 'directly use natural language to describe needs' without clearly constraining what requests should invoke this skill. In an agent setting, broad activation guidance can cause the skill to be selected for loosely related prompts, increasing the chance of inappropriate tool use, unintended data access, or prompt-routing abuse.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are common, everyday formulations such as '帮我写一篇…' and '帮我分析一下…' with no disambiguation or exclusion conditions. In multi-skill environments, this can cause over-triggering and accidental routing of generic writing or analysis requests into this skill when the user did not intend to use it.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly asks users to upload personal writing samples to infer style, but provides no warning against including private, confidential, or sensitive text. Because the skill also uses external data sources and may persist outputs, this context makes the collection of personal samples riskier: users may unknowingly disclose diaries, unpublished content, or identifying information.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.