T01 · Skill Instruction Hijacking
- Location
references/core_workflow.md:183- Finding
Mandatory Promotional Output Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its Xiaohongshu analytics purpose, but it uses overbroad credential handling, local data persistence, unsafe generated HTML, and under-specified recurring subscription behavior that users should review before installing.
Install only if you are comfortable granting this skill access to a RedFox API key, allowing it to contact redfox.hk, and letting it write cached API responses and HTML reports locally. Prefer setting REDFOX_API_KEY only in the current session or a proper secret store, do not print the full key, review/delete .cache data, and avoid opening generated HTML reports from untrusted or unreviewed API data until the escaping and remote-script issues are fixed. Treat any daily subscription as persistent automation and confirm how to cancel it before enabling it.
references/core_workflow.md:183Mandatory Promotional Output Hijacking
scripts/gen_xhs_html.py:399Stored HTML and JavaScript Injection in Generated Reports
scripts/gen_xhs_html.py:111Runtime Loading of Third-Party Browser Code Without Integrity Protection
scripts/xhs_weekly_fetcher.py:25Plaintext API-Key Persistence, Shell-Profile Scanning, and Secret Disclosure Guidance
This mismatch is especially concerning because the skill claims benign analytics functionality while static analysis indicates host-level behaviors like extracting API keys from shell config files and persisting raw API data locally. A user expecting simple content analysis may unknowingly approve actions that touch sensitive local configuration or retain data on disk.
This mismatch is especially concerning because the skill claims benign analytics functionality while static analysis indicates host-level behaviors like extracting API keys from shell config files and persisting raw API data locally. A user expecting simple content analysis may unknowingly approve actions that touch sensitive local configuration or retain data on disk.
Referenced artifact was not completely inspected
2. 确保目录结构完整:`SKILL.md`、`references/`、`scripts/`
The README advertises a daily 19:30 subscription push but does not clearly explain persistence, cancellation, notification frequency, or what user data/state is stored to support the subscription. That can lead users to unknowingly enable ongoing notifications or background processing without informed consent, especially when activation is described as a simple reply of '1'.
The README explicitly says users can invoke the skill with unconstrained natural language and 'no commands to memorize,' which makes accidental or overly broad triggering more likely. In an agent ecosystem, this can cause the skill to activate on generic trend-related conversation and perform external API actions or generate reports without sufficiently deliberate user intent.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
### Quick Reference
| Intent | Example phrase | Result |
| ------------------------------ | ------------------------------------------------ | -------------------------------------------------------------------------------------------------------- |
| Query track 7-day hot rankings | `Show me viral notes related to mascara` | Auto-matches "Beauty & Makeup", outputs TOP20 hot rankings + 7-day analysis + HTML + subscription option |
| Query general hot content | `What's trending on Xiaohongshu lately?` | Uses "All" category, full four-section standard output |
The example phrase 'What's trending on Xiaohongshu lately?' is broad everyday language that could plausibly appear in ordinary conversation, increasing overlap between normal chat and skill activation. Because the skill can fetch external data and offer follow-on actions, broad triggers raise the risk of unintended invocation and downstream actions the user did not clearly request.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
## Use Cases
| Scenario | Role | Example question | Benefit |
| --------------------------- | ----------------------- | ---------------------------------------------------- | ----------------------------------------------------------------------------------------- |
| Creator topic inspiration | New Xiaohongshu creator | `Show 7-day hot rankings in skincare` | Quickly find replicable topic directions to lower cold-start trial-and-error costs |
| Brand competitor monitoring | Brand marketing manager | `Query lipstick 7-day virals and export HTML` | Grasp category content direction to optimize placement and seeding strategies |
The README tells users to invoke the skill with unrestricted natural language, without defining clear activation boundaries or requiring an explicit skill-specific trigger. In assistant environments where routing may rely on semantic matching, broad phrasing can cause unintended activation on ordinary requests, leading to unnecessary external API use, unwanted data retrieval, or surprise subscription-related actions.
The skill advertises capabilities that involve environment access, local file read/write, and network calls, but it does not declare any explicit tool scope or permission boundaries. In an agent setting, this weakens least-privilege controls and can enable broader-than-expected access if the skill is invoked automatically.
The skill instructs the agent to persistently modify user shell/profile configuration or Windows user environment variables to set an API key, without a strong warning or explicit consent boundary. Persistent host configuration changes can outlive the session, affect other tools, and expose secrets if written to readable profile files or mishandled in logs/history.
The trigger examples are broad enough that ordinary requests about trending content could invoke the skill unexpectedly. When a skill has network, file, and environment interactions, overbroad activation increases the risk of unintended execution and surprise side effects.
The trigger condition covers very broad user intents like asking about Xiaohongshu hot content or trend analysis, which can cause the skill to activate during ordinary discussion rather than clear task requests. In an agent setting, overly broad activation increases the chance of unintended external data access, unsolicited automation setup prompts, or workflow execution without sufficiently specific user intent.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
**💡热门内容分析**
| 内容分类 | 内容特征 | 实际效果 | 参考笔记 |
| :------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------ | :--------------------------------- |
| 封面设计 | 采用高清摄影或设计软件精心制作的封面图,画面构图饱满、色彩搭配协调,同时加入醒目的文字标题或标签,突出核心卖点或吸引眼球的元素,通过强烈的视觉冲击力在用户快速浏览时瞬间抓住注意力 | 点击率提升45% | [笔记标题链接1]<br>[笔记标题链接2] |
| 内容创作 | 围绕用户痛点或情感共鸣点展开叙事,采用第一人称视角分享真实经历或心得,结合表情符号和分段排版增强可读性,适当设置悬念或反转,激发用户的情感共鸣和参与欲望 | 互动率提升50% | [笔记标题链接3]<br>[笔记标题链接4] |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
**💡热门内容分析**
| 内容分类 | 内容特征 | 实际效果 | 参考笔记 |
| :------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------ | :--------------------------------- |
| 封面设计 | 采用高清摄影或设计软件精心制作的封面图,画面构图饱满、色彩搭配协调,同时加入醒目的文字标题或标签,突出核心卖点或吸引眼球的元素,通过强烈的视觉冲击力在用户快速浏览时瞬间抓住注意力 | 点击率提升45% | [笔记标题链接1]<br>[笔记标题链接2] |
| 内容创作 | 围绕用户痛点或情感共鸣点展开叙事,采用第一人称视角分享真实经历或心得,结合表情符号和分段排版增强可读性,适当设置悬念或反转,激发用户的情感共鸣和参与欲望 | 互动率提升50% | [笔记标题链接3]<br>[笔记标题链接4] |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
**📈爆款标题分析**
| 标题类型 | 标题特征 | 标题模版 | 发布规律 | 参考标题 |
| :------- | :----------------------------------------------------------------------------------------------------------------- | :--------------- | :------------------- | :----------------------- |
| 提问式 | 标题以疑问句开头,设置悬念或提出用户关心的问题,引发用户的好奇心和思考欲望,激发点击阅读或评论互动 | "你还在XX吗?" | 工作日早高峰效果最佳 | 这个方法你还在用吗? |
| 数字式 | 标题中包含具体的数字、数量或统计数据,利用人们对量化信息的偏好,增强内容的可信度和专业感,让用户觉得内容有价值 | "XX个XX技巧" | 午餐时间点击率高 | 5个快速提升XX的技巧 |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
**📈爆款标题分析**
| 标题类型 | 标题特征 | 标题模版 | 发布规律 | 参考标题 |
| :------- | :----------------------------------------------------------------------------------------------------------------- | :--------------- | :------------------- | :----------------------- |
| 提问式 | 标题以疑问句开头,设置悬念或提出用户关心的问题,引发用户的好奇心和思考欲望,激发点击阅读或评论互动 | "你还在XX吗?" | 工作日早高峰效果最佳 | 这个方法你还在用吗? |
| 数字式 | 标题中包含具体的数字、数量或统计数据,利用人们对量化信息的偏好,增强内容的可信度和专业感,让用户觉得内容有价值 | "XX个XX技巧" | 午餐时间点击率高 | 5个快速提升XX的技巧 |
The subscription prompt encourages users to reply with '订阅' or '1' to create a recurring daily push task, but it does not clearly warn that this creates an ongoing automation with repeated future actions. This weakens informed consent and can lead to users unintentionally authorizing persistent notifications or scheduled processing.
The instructions say to create a daily 19:30 push automation task immediately on a simple reply, but they omit cancellation, review, and consent safeguards. Persistent automations are higher risk than one-time actions because they continue operating after the current conversation and may surprise users or be difficult to stop.
The instruction explicitly says not to tell the user which category their keyword was mapped to, reducing transparency about how the system interprets and processes input. Hidden classification can mislead users, make outputs harder to validate, and increase the chance of silent misrouting to an unintended category.
The workflow tells the agent to remember and reuse a cached JSON path derived from prior user-triggered fetching for later HTML generation, without any explicit retention limit, access boundary, or renewed consent. Reusing stored user-derived data across steps can expose data longer than necessary and may enable unintended reuse if context or users change.
The script serializes attacker-controlled JSON into the page and then constructs HTML with string concatenation, inserting fields such as title, userName, avatar, and photoJumpUrl directly into innerHTML and attributes without proper escaping. A crafted data file can therefore inject arbitrary HTML or JavaScript into the generated report, leading to stored XSS when a user opens the file locally in a browser.
The generated HTML automatically loads and executes JavaScript from third-party CDNs when the local file is opened. Because this script embeds unpinned remote dependencies into an otherwise local reporting artifact, anyone opening the HTML implicitly trusts external code that could change, be blocked, or be used for supply-chain compromise, expanding risk beyond simple file generation.
The script scans shell profile files such as .zshrc and .bashrc to extract API credentials if the environment variable is absent. For a content analytics skill, reading unrelated user configuration files is over-privileged behavior that can access secrets beyond the intended execution scope and normalize credential harvesting patterns.
The script automatically saves the full raw API response to disk, even when the user only asked for a ranking query. This creates unnecessary data persistence, can expose sensitive or proprietary response contents to other local users or later processes, and expands the blast radius if the cache directory is read, indexed, synced, or exfiltrated.
No suspicious patterns detected.