Back to skill

Security audit

小红书每日爆款笔记推荐

Security checks for vulnerabilities and agentic risk

Overview

The skill’s core trend-query purpose is coherent, but it asks for persistent credential handling, reads shell profile files, creates ongoing subscriptions, and generates HTML with notable safety weaknesses.

Review this skill before installing. Use a scoped, revocable RedFox API key, avoid letting the agent write or echo the key in shell profiles, and prefer setting it through a session-scoped secret mechanism. Do not enable daily subscription pushes unless you understand where that state is stored and how to cancel it. Treat generated HTML reports and /tmp cache files as untrusted, especially if cache files can be modified by other users or processes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T01 · Skill Instruction Hijacking

Warning
Location
references/core_workflow.md:49
Finding

Mandatory promotional output hijacks normal Agent responses

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gen_xhs_html.py:575
Finding

Generated reports allow HTML and JavaScript injection from API or cache data

Content
View full analysis
' + '
' + rankHtml + '
' + '' + '
' + (avatar ? '' : '') + '' + (userUrl && userUrl !== '#' ? '' + userName + '' : userName) + '' + (fans ? '·' + fans + '' : '') + '
' + '
' + '
' + ''; } document.getElementById('noteList').innerHTML = html; ``` The data is initially serialized as follows: ```python js_data = json.dumps(hot_list, ensure_ascii=False, indent=2) ``` The cache path loads article objects without sanitizing individual fields: ```python with open(args.input_json, 'r', encoding='utf-8') as f: cache = json.load(f) cached_articles = cache.get("articles", []) result = { "fetch_time": f"{cached_rank_date} 19:00", "query_type": "日榜", "rank_dat ...[truncated 2485 chars]
Remediation
View remediation
` element and escape at least `<`, `>`, `&`, U+2028, and U+2029 before embedding it. 8. Validate the complete cache schema before generating HTML. 9. Add a restrictive Content Security Policy that prohibits inline scripts and limits network destinations. 10. Add tests using quote-breaking, event-handler, `javascript:` URL, and `` payloads. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/xhs_daily_fetcher.py:641
Finding

Predictable shared temporary cache permits cache poisoning and symlink attacks

Content
View full analysis
0: raw_articles = process_ranking_data(data, 50) cache_data = { "rank_date": rank_date, "category": category, "articles": raw_articles } try: os.makedirs( os.path.dirname(os.path.abspath(args.output_json)), exist_ok=True ) with open(args.output_json, "w", encoding="utf-8") as f: json.dump(cache_data, f, ensure_ascii=False, indent=2) print(f"Data cached at: {args.output_json}", file=sys.stderr) except Exception as e: print(f"Cache write failed: {e}", file=sys.stderr) ``` ### Technical Analysis `/tmp` is normally shared by multiple local users and processes. The fixed filename is predictable, while `open(..., "w")`: - Follows symbolic links. - Truncates existing files. - Does not require exclusive creation. - Does not verify file ownership. - Does not force mode `0600`. - Does not perform an atomic replacement. A local attacker can pre-create the cache as a symlink to another file writable by the victim. When the fetcher runs, it follows the symlink and overwrites the target. An attacker can also replace or race the cache before HTML generation. Because the HTML generator trusts the cache contents, cache poisoning can be chained with the HTML-injection vulnerability. ### Attack Path #### Symlink overwrite 1. The attacker predicts `/tmp/xhs_daily_cache.json`. 2. The attacker creates that path as a symbolic link to another file writable by the victi ...[truncated 1019 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/xhs_daily_fetcher.py:27
Finding

Credential discovery reads shell profiles and encourages plaintext global persistence

Content
View full analysis
' >> ~/.zshrc source ~/.zshrc echo $REDFOX_API_KEY ``` Equivalent profile-reading logic also appears in `scripts/gen_xhs_html.py`, lines 29–59. ### Technical Analysis Reading `REDFOX_API_KEY` from the current process environment is sufficient for the declared API operation. Searching four shell startup files broadens the Skill's local-file access beyond that minimum requirement. Although the current parser only returns lines beginning with the expected export statement, it still opens and reads files that commonly contain unrelated credentials, aliases, private paths, and executable shell confi ...[truncated 1542 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/gen_xhs_html.py:307
Finding

Generated reports execute third-party CDN scripts without integrity verification

Content
View full analysis
``` The installation instructions also use an unpinned Python dependency command: ```bash pip install requests ``` The same CDN script references are present in `scripts/xhs_weekly.html`, lines 7–8. ### Technical Analysis Every generated report loads and executes JavaScript from cdnjs when opened. Although versions appear in the URL, the tags do not include Subresource Integrity hashes. Consequently, the browser cannot verify that the returned files match the versions reviewed by the Skill author. The report also has no restrictive Content Security Policy. If the CDN, distribution path, network trust boundary, or upstream package is compromised, altered JavaScript executes with the same document privileges as the report's own code. The Python dependency instruction is also not reproducible because it specifies neither an exact version nor a package hash. This allows the installed dependency version to change over time. This is a supply-chain weakness rather than evidence that the current named dependencies are malicious. ### Attack Path 1. A user generates and opens an HTML report while connected to the network. 2. The browser requests `html2canvas` and `jspdf` from cdnjs. 3. A compromised upstream or delivery path returns modified JavaScript. 4. Because no integrity hash is present, the browser accepts and executes it. 5. The malicious dependency can read or alter report content and initiate network requests. For Python installation: 1. The user runs the unpinned `pip install requests` command. 2. The package index resolves whichever version is current under t ...[truncated 605 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (32)

Tainted flow: 'headers' from os.environ.get (line 196, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/gen_xhs_html.py (reported line 207)May include surrounding context.

python
try:
        # 接口仅支持 GET(query 参数);POST 会返回系统错误
        response = requests.get(REDFOX_API_BASE, params=params, headers=headers, timeout=30)
        if response.status_code >= 400:
            return {"fetch_time": rank_date + " 19:00", "query_type": "日榜", "category": category, "hot_list": []}

Tainted flow: 'headers' from os.environ.get (line 175, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/xhs_daily_fetcher.py (reported line 186)May include surrounding context.

python
try:
        # 接口仅支持 GET(query 参数);POST 会返回系统错误
        response = requests.get(REDFOX_API_BASE, params=params, headers=headers, timeout=30)
        if response.status_code >= 400:
            raise Exception(f"HTTP请求失败: {response.status_code}, {response.text}")

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow instructs the agent to persist a user-supplied API key into shell profiles or Windows user environment and then verify it by echoing it back. For a simple trend-query skill, modifying persistent system configuration is unnecessary and expands scope from data retrieval into credential handling, increasing the chance of secret exposure, accidental reuse by other tools, and unwanted system changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README explicitly says users can invoke the skill by describing needs in natural language with no command constraints. In agent environments, overly broad invocation guidance increases the chance of accidental triggering from ordinary conversation and can cause the skill to run in contexts the user did not clearly intend, including making external API calls or initiating subscriptions.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.en.md (reported line 57)May include surrounding context.

md
### Quick Reference

| Intent                    | Example phrase                                 | Result                                                                                                        |
| ------------------------- | ---------------------------------------------- | ------------------------------------------------------------------------------------------------------------- |
| Query today's virals      | `Show me viral notes about mascara`            | Auto-matches category, outputs today's breakout TOP20 + three-dimension analysis + HTML + subscription option |
| Query general hot content | `What's trending on Xiaohongshu lately?`       | Uses "All" category, full four-section output                                                                 |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger example "What's trending on Xiaohongshu lately?" is generic conversational wording that overlaps with normal user chat. This raises the risk that the skill is activated unintentionally during broad discussion, leading to unexpected data retrieval, external requests, or follow-on actions presented as if explicitly requested.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The README advertises automatic daily subscription pushes but does not clearly disclose the persistence of notifications, how to unsubscribe, or what user state/preferences are retained. This can lead to unauthorized or unexpected ongoing engagement, especially if users trigger subscription with a simple reply and are not warned about the behavioral and privacy implications.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This is a markdown file, so vague trigger guidance applies. The text explicitly says users need not remember commands and provides broad everyday-language examples, which could overlap with normal conversation without clarifying when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises capabilities that involve environment-variable access, file reads/writes, and network use, but it does not declare any explicit tool scope or permission boundaries. In agent platforms, this can lead to over-broad execution authority, making it easier for the skill to access secrets like REDFOX_API_KEY, write files, or make outbound requests without clear sandboxing or user visibility.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example trigger phrases are broad enough that ordinary conversation about Xiaohongshu trends or related keywords could unintentionally activate the skill. Accidental activation matters here because the skill can perform network requests and file operations, potentially causing unintended API usage, data retrieval, or local artifact generation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The invocation guidance relies on ambiguous natural-language requests rather than unambiguous commands, increasing the chance that the agent routes unrelated user queries into this skill. Because the skill includes subscription behavior, API calls, and HTML generation, misrouting can lead to unintended external actions or content generation beyond what the user expected.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The generic trigger example '最近小红书有什么热门内容' is extremely broad and overlaps with common assistant queries, making unintended invocation likely. In context, this is more concerning because the skill is designed to fetch external data and may produce follow-on actions like analysis, subscriptions, or file output once activated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

文件整体以中文为唯一指定输出与交互形式,并多处使用“必须原样输出”等强制措辞,但未看到允许用户选择其他语言或说明仅面向特定中文场景的明确限制。根据规则,未经用户选择而强制单一语言/locale 可能构成自然语言政策违规。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill adds a subscription/push capability beyond one-time query and analysis, enabling ongoing actions after the initial request. Persistent notifications increase the risk of unwanted autonomous behavior, surprise data access, and repeated outbound activity that users may not fully expect from a ranking lookup skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad enough to overlap with casual discussion of popular content or trends, which can cause the agent to invoke the skill unexpectedly. In this skill, accidental activation matters because it may lead to external API calls, credential checks, or follow-on actions like subscription prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow tells the agent to perform persistent system changes and enable push-like behavior without prominent risk disclosure or explicit consent boundaries. Users are not adequately warned that credentials may persist across sessions or that subscriptions create ongoing activity, making unintended system and privacy impact more likely.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions encourage the agent to help store API credentials persistently and to verify them by printing them in the shell, which can expose secrets in terminal history, chat transcripts, screenshots, or logs. In the context of a content-ranking skill, this credential handling is disproportionate and materially increases secret leakage risk.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/core_workflow.md (reported line 157)May include surrounding context.

md
**💡热门内容分析**

| 内容分类 | 内容特征                                                                                                                                                                           | 实际效果      | 参考笔记                           |
| :------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------ | :--------------------------------- |
| 封面设计 | 采用高清摄影或设计软件精心制作的封面图,画面构图饱满、色彩搭配协调,同时加入醒目的文字标题或标签,突出核心卖点或吸引眼球的元素,通过强烈的视觉冲击力在用户快速浏览时瞬间抓住注意力 | 点击率提升45% | [笔记标题链接1]<br>[笔记标题链接2] |
| 内容创作 | 围绕用户痛点或情感共鸣点展开叙事,采用第一人称视角分享真实经历或心得,结合表情符号和分段排版增强可读性,适当设置悬念或反转,激发用户的情感共鸣和参与欲望                           | 互动率提升50% | [笔记标题链接3]<br>[笔记标题链接4] |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/core_workflow.md (reported line 166)May include surrounding context.

md
**📈爆款标题分析**

| 标题类型 | 标题特征                                                                                                           | 标题模版         | 发布规律             | 参考标题                 |
| :------- | :----------------------------------------------------------------------------------------------------------------- | :--------------- | :------------------- | :----------------------- |
| 提问式   | 标题以疑问句开头,设置悬念或提出用户关心的问题,引发用户的好奇心和思考欲望,激发点击阅读或评论互动                 | "你还在XX吗?"   | 工作日早高峰效果最佳 | 这个方法你还在用吗?     |
| 数字式   | 标题中包含具体的数字、数量或统计数据,利用人们对量化信息的偏好,增强内容的可信度和专业感,让用户觉得内容有价值     | "XX个XX技巧"     | 午餐时间点击率高     | 5个快速提升XX的技巧      |

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The workflow introduces HTML/PDF export and file-package generation, which exceeds basic query-and-analysis behavior and causes filesystem side effects. Even if intended for convenience, generating files creates additional attack surface around file writes, unexpected persistence, and content export beyond the user’s immediate request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script scans shell profile files such as ~/.zshrc and ~/.bashrc to extract REDFOX_API_KEY without explicit consent at runtime. Reading unrelated personal config files expands the data-access scope beyond what users may expect and can unintentionally harvest secrets or sensitive local configuration from a broader set of files.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The generated HTML loads executable JavaScript from third-party CDNs at page-open time. Anyone opening the report implicitly trusts those external hosts and the network path; if the CDN is compromised, blocked, or serves altered content, arbitrary script can run in the local browser context of the report viewer.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script's user-facing description, help text, and output strings are entirely in Chinese, effectively imposing a specific language/locale on all users. The file does not offer language selection or document that the skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script reads shell startup files such as .zshrc and .bashrc to extract REDFOX_API_KEY without explicit user consent at runtime. That is a sensitive local file access pattern not necessary for a simple trend-query skill when environment variables or explicit input would suffice, and it normalizes scanning local configuration that may contain unrelated secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Accessing shell rc/profile files to obtain credentials is a privacy-sensitive behavior because those files may contain other secrets, tokens, aliases, or personal configuration. Even though the current code only searches for a specific export line, this local secret-discovery behavior is broader than the skill's stated purpose and occurs without a prominent warning or opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/gen_xhs_html.py:194

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/xhs_daily_fetcher.py:173