Back to skill

Security audit

小红书爆款雷达

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but its local HTML report generation has concrete file-write and HTML-injection risks, and subscriptions persist search details in calendar tasks.

Install only if you are comfortable giving the skill a Redfox API key, allowing it to write local HTML reports, and optionally creating calendar subscriptions. Open generated reports cautiously, avoid sensitive keywords on shared systems, and prefer a fixed safe output directory until the report escaping and filename handling are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_xhs_hot_articles.py:225
Finding

Persistent HTML Injection in Generated Reports

Content
View full analysis
相关性 {relevance_score} 热度 {popularity_score} 时效 {recency_score} ''' card_html = f'''
{idx + 1}. {title}
{author_name}({fuzzy_count(fans)}粉) · 发布日期:{pub_time}
{scores_html}
🔥 {interactive_count}互动 👍{like_count} ⭐{collect_count} 查看作品 ↗
''' ``` The API-returned keyword is also inserted directly into the report: ```python

小红书热门笔记数据分析报告

关键词:{keyword} | 时间范围:{time_range}
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_xhs_hot_articles.py:616
Finding

Directory Traversal Through the Default HTML Report Filename

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (29)

Tainted flow: 'req' from os.environ.get (line 89, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/fetch_xhs_hot_articles.py (reported line 91)May include surrounding context.

python
body = json.dumps(payload, ensure_ascii=False).encode("utf-8")
            req = urllib.request.Request(url, data=body, headers=headers, method="POST")
            
            with urllib.request.urlopen(req, timeout=30) as resp:
                status_code = resp.status
                raw = resp.read().decode("utf-8")

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
python scripts/fetch_xhs_hot_articles.py --keyword <关键词> --start-date <日期>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
python scripts/fetch_xhs_hot_articles.py --keyword <关键词> --start-date <日期>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
python scripts/fetch_xhs_hot_articles.py --keyword <关键词> --start-date <日期>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
python scripts/fetch_xhs_hot_articles.py --keyword <关键词> --start-date <日期>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 459)May include surrounding context.

md
python scripts/fetch_xhs_hot_articles.py --keyword <关键词> --start-date <日期>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 460)May include surrounding context.

md
python scripts/fetch_xhs_hot_articles.py --keyword <关键词> --start-date <日期>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 461)May include surrounding context.

md
python scripts/fetch_xhs_hot_articles.py --keyword <关键词> --start-date <日期>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 462)May include surrounding context.

md
python scripts/fetch_xhs_hot_articles.py --keyword <关键词> --start-date <日期>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 523)May include surrounding context.

md
python scripts/fetch_xhs_hot_articles.py --keyword <关键词> --start-date <日期>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 529)May include surrounding context.

md
python scripts/fetch_xhs_hot_articles.py --keyword <关键词> --start-date <日期>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 525)May include surrounding context.

md
| SKILL 定义 | `SKILL.md` | 定义 Skill 元数据、意图理解规则、泛化词拓展策略、展示策略、订阅逻辑、自检清单 |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L090 says users can 'Just describe your needs in natural language' without defining boundaries, trigger scope, or negative examples. This is ambiguous for a markdown skill description because many ordinary requests could match, making it unclear when this skill should activate versus other skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire skill documentation, examples, and interaction wording are presented only in Chinese, with no indication that users may choose another language or locale. This can violate language-choice policy when the skill effectively assumes a fixed language without explicit opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README says users can 'directly use natural language to describe your needs' without any command format, but it does not define clear trigger boundaries, exclusions, or constrained invocation phrases. This is ambiguous enough to overlap with ordinary conversation and could cause unintended activation of the skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool scope or permissions despite clearly requiring environment-variable access, network access to the Redfox API, and local file creation for HTML reports. This weakens least-privilege controls and creates room for unintended tool use or capability expansion if the host agent interprets the document broadly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a search-and-recommend skill, but the documentation also introduces timed subscription behavior and calendar task creation. This is a scope expansion vulnerability because an agent or user may authorize a search tool without realizing it can persist data and create scheduled actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation advertises HTML report generation but does not clearly warn users that running the search writes a local file. Undisclosed file creation can surprise users, leak search terms through filenames, and create residual artifacts on shared or monitored systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill hard-codes required user replies such as "拓展", "不拓展", and other Chinese response formats throughout the instructions, effectively enforcing a specific language for interaction. There is no opt-in or alternative language handling documented, which is a locale/language policy concern.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to create calendar or scheduled tasks after showing search results, which goes beyond the minimum capability needed for content discovery. Persistent scheduled actions can store user interests and trigger future behavior, increasing privacy and consent risks if users do not fully understand what is being created.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The subscription flow directs use of calendar_create without a clear warning that search keywords, time ranges, and schedule preferences will be stored in a calendar/task system. This creates a transparency and privacy issue because users may disclose sensitive interests without informed consent to persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Documenting a --debug mode that prints raw API responses without any warning encourages logging of full upstream payloads, which may contain API metadata, identifiers, content, or other sensitive business/user data. In this skill context, the tool handles externally sourced content and uses an API key-backed service, so verbose raw-response logging increases the chance of accidental data leakage into terminal history, CI logs, agent traces, or shared artifacts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The HTML output sets lang="zh-CN", which forces a specific language/locale in generated content. Under the policy, locale constraints should be optional, user-selected, or clearly justified as region-specific; this file does not provide such opt-in or justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a search/recommendation tool for discovering hot notes, which implies fetching and returning content data. This script additionally persists a rendered HTML report locally every run, even though file output is not mentioned in the stated skill purpose and is not necessary to perform the search itself.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The documentation first says the agent must not add recommendations or suggestions before outputting results, and elsewhere repeatedly requires proactive recommendation of finer-grained tracks and mandatory subscription prompts after output. This is not merely incomplete wording: the instructions describe incompatible operator intent about whether unsolicited recommendations should be made.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.