Back to skill

Security audit

小红书七日爆款笔记

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Xiaohongshu analytics purpose, but it uses overbroad credential handling, local data persistence, unsafe generated HTML, and under-specified recurring subscription behavior that users should review before installing.

Install only if you are comfortable granting this skill access to a RedFox API key, allowing it to contact redfox.hk, and letting it write cached API responses and HTML reports locally. Prefer setting REDFOX_API_KEY only in the current session or a proper secret store, do not print the full key, review/delete .cache data, and avoid opening generated HTML reports from untrusted or unreviewed API data until the escaping and remote-script issues are fixed. Treat any daily subscription as persistent automation and confirm how to cancel it before enabling it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
references/core_workflow.md:183
Finding

Mandatory Promotional Output Hijacking

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gen_xhs_html.py:399
Finding

Stored HTML and JavaScript Injection in Generated Reports

Content
View full analysis
{page_title} ... ''' ``` ### Technical Analysis Data from the remote API or a caller-supplied JSON file is placed directly inside an executable `script` element using `json.dumps`. JSON serialization alone does not make data safe for embedding in HTML. In ...[truncated 2112 chars]
Remediation
View remediation
`, `&`, U+2028, and U+2029 before embedding. - Parse it with `JSON.parse` after reading `textContent`. 7. HTML-escape `category` and any other metadata interpolated into document markup. 8. Add `rel="noopener noreferrer"` to links opened with `target="_blank"`. 9. Apply a restrictive Content Security Policy that disallows inline scripts and unexpected network destinations. 10. Add regression tests covering: - Closing script sequences. - Quotes in attributes. - Event-handler injection. - HTML elements in titles and usernames. - Unsafe URL schemes. 11. Treat API responses as untrusted even when received over HTTPS. ]]>

T08 · Insecure Dependencies

Warning
Location
scripts/gen_xhs_html.py:111
Finding

Runtime Loading of Third-Party Browser Code Without Integrity Protection

Content
View full analysis
``` ### Technical Analysis Generated and bundled reports download and execute JavaScript from a third-party CDN whenever they are opened. Although the dependency versions are pinned in the URLs, the script tags do not include Subresource Integrity hashes. There is also no restrictive Content Security Policy. The effective executable content can therefore differ from what was inspected in the Skill package if the CDN account, hosting infrastructure, DNS path, or delivery channel is compromised. This behavior also contradicts the generator's claim that the output is an independent or standalone HTML report because important export functions depend on external runtime code. ### Attack Path 1. A user generates or opens the included HTML report. 2. The browser requests `html2canvas` and `jsPDF` from `cdnjs.cloudflare.com`. 3. A compromised or malicious response is returned from the remote dependency source. 4. The browser executes that response in the report context. 5. The injected dependency can inspect or alter the report and initiate additional browser actions or network requests. ### Impact Assessment A successful supply-chain compromise could affect every user who opens a report while the remote resource is compromised. Attacker-controlled browser code could: - Read and modify displayed report data. - Alter generated images or PDF exports. - Insert malicious links or phishing content. - Send report data to external services. - Redirect users or load additional payloads. The code executes with browser-page privil ...[truncated 165 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/xhs_weekly_fetcher.py:25
Finding

Plaintext API-Key Persistence, Shell-Profile Scanning, and Secret Disclosure Guidance

Content
View full analysis
str: import platform import re as re_mod api_key = os.environ.get("REDFOX_API_KEY", "").strip() if api_key: return api_key home = os.path.expanduser("~") config_files = [] if platform.system() == "Windows": config_files = [ os.path.join( home, "Documents", "WindowsPowerShell", "Microsoft.PowerShell_profile.ps1" ), os.path.join( home, "Documents", "PowerShell", "Microsoft.PowerShell_profile.ps1" ), ] else: config_files = [ os.path.join(home, ".zshrc"), os.path.join(home, ".bashrc"), os.path.join(home, ".bash_profile"), os.path.join(home, ".profile"), ] for cf in config_files: if os.path.isfile(cf): try: with open(cf, "r", encoding="utf-8", errors="ignore") as f: content = f.read() match = re_mod.search( r'REDFOX_API_KEY\s*[=:]\s*["\']?([a-zA-Z0-9_\-]+)["\']?', content ) if match: return match.group(1).strip() except Exception: continue ``` The Skill documentation additionally instructs users to append the key to a shell initialization file and verify it by printing the complete value. In English, the relevant instructions are: ```text Append `export REDFOX_API_KEY=` to ~/.zshrc or ~/.bashrc. After configuration, verify it with `echo $REDFOX_API_KEY`. ``` ### Technical Analysis The authenticate ...[truncated 1969 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

This mismatch is especially concerning because the skill claims benign analytics functionality while static analysis indicates host-level behaviors like extracting API keys from shell config files and persisting raw API data locally. A user expecting simple content analysis may unknowingly approve actions that touch sensitive local configuration or retain data on disk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

This mismatch is especially concerning because the skill claims benign analytics functionality while static analysis indicates host-level behaviors like extracting API keys from shell config files and persisting raw API data locally. A user expecting simple content analysis may unknowingly approve actions that touch sensitive local configuration or retain data on disk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
2. 确保目录结构完整:`SKILL.md`、`references/`、`scripts/`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The README advertises a daily 19:30 subscription push but does not clearly explain persistence, cancellation, notification frequency, or what user data/state is stored to support the subscription. That can lead users to unknowingly enable ongoing notifications or background processing without informed consent, especially when activation is described as a simple reply of '1'.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly says users can invoke the skill with unconstrained natural language and 'no commands to memorize,' which makes accidental or overly broad triggering more likely. In an agent ecosystem, this can cause the skill to activate on generic trend-related conversation and perform external API actions or generate reports without sufficiently deliberate user intent.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.en.md (reported line 58)May include surrounding context.

md
### Quick Reference

| Intent                         | Example phrase                                   | Result                                                                                                   |
| ------------------------------ | ------------------------------------------------ | -------------------------------------------------------------------------------------------------------- |
| Query track 7-day hot rankings | `Show me viral notes related to mascara`         | Auto-matches "Beauty & Makeup", outputs TOP20 hot rankings + 7-day analysis + HTML + subscription option |
| Query general hot content      | `What's trending on Xiaohongshu lately?`         | Uses "All" category, full four-section standard output                                                   |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example phrase 'What's trending on Xiaohongshu lately?' is broad everyday language that could plausibly appear in ordinary conversation, increasing overlap between normal chat and skill activation. Because the skill can fetch external data and offer follow-on actions, broad triggers raise the risk of unintended invocation and downstream actions the user did not clearly request.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.en.md (reported line 74)May include surrounding context.

md
## Use Cases

| Scenario                    | Role                    | Example question                                     | Benefit                                                                                   |
| --------------------------- | ----------------------- | ---------------------------------------------------- | ----------------------------------------------------------------------------------------- |
| Creator topic inspiration   | New Xiaohongshu creator | `Show 7-day hot rankings in skincare`                | Quickly find replicable topic directions to lower cold-start trial-and-error costs        |
| Brand competitor monitoring | Brand marketing manager | `Query lipstick 7-day virals and export HTML`        | Grasp category content direction to optimize placement and seeding strategies             |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README tells users to invoke the skill with unrestricted natural language, without defining clear activation boundaries or requiring an explicit skill-specific trigger. In assistant environments where routing may rely on semantic matching, broad phrasing can cause unintended activation on ordinary requests, leading to unnecessary external API use, unwanted data retrieval, or surprise subscription-related actions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises capabilities that involve environment access, local file read/write, and network calls, but it does not declare any explicit tool scope or permission boundaries. In an agent setting, this weakens least-privilege controls and can enable broader-than-expected access if the skill is invoked automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to persistently modify user shell/profile configuration or Windows user environment variables to set an API key, without a strong warning or explicit consent boundary. Persistent host configuration changes can outlive the session, affect other tools, and expose secrets if written to readable profile files or mishandled in logs/history.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger examples are broad enough that ordinary requests about trending content could invoke the skill unexpectedly. When a skill has network, file, and environment interactions, overbroad activation increases the risk of unintended execution and surprise side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger condition covers very broad user intents like asking about Xiaohongshu hot content or trend analysis, which can cause the skill to activate during ordinary discussion rather than clear task requests. In an agent setting, overly broad activation increases the chance of unintended external data access, unsolicited automation setup prompts, or workflow execution without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/core_workflow.md (reported line 158)May include surrounding context.

md
**💡热门内容分析**

| 内容分类 | 内容特征                                                                                                                                                                           | 实际效果      | 参考笔记                           |
| :------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------ | :--------------------------------- |
| 封面设计 | 采用高清摄影或设计软件精心制作的封面图,画面构图饱满、色彩搭配协调,同时加入醒目的文字标题或标签,突出核心卖点或吸引眼球的元素,通过强烈的视觉冲击力在用户快速浏览时瞬间抓住注意力 | 点击率提升45% | [笔记标题链接1]<br>[笔记标题链接2] |
| 内容创作 | 围绕用户痛点或情感共鸣点展开叙事,采用第一人称视角分享真实经历或心得,结合表情符号和分段排版增强可读性,适当设置悬念或反转,激发用户的情感共鸣和参与欲望                           | 互动率提升50% | [笔记标题链接3]<br>[笔记标题链接4] |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/core_workflow.md (reported line 414)May include surrounding context.

md
**💡热门内容分析**

| 内容分类 | 内容特征                                                                                                                                                                           | 实际效果      | 参考笔记                           |
| :------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------ | :--------------------------------- |
| 封面设计 | 采用高清摄影或设计软件精心制作的封面图,画面构图饱满、色彩搭配协调,同时加入醒目的文字标题或标签,突出核心卖点或吸引眼球的元素,通过强烈的视觉冲击力在用户快速浏览时瞬间抓住注意力 | 点击率提升45% | [笔记标题链接1]<br>[笔记标题链接2] |
| 内容创作 | 围绕用户痛点或情感共鸣点展开叙事,采用第一人称视角分享真实经历或心得,结合表情符号和分段排版增强可读性,适当设置悬念或反转,激发用户的情感共鸣和参与欲望                           | 互动率提升50% | [笔记标题链接3]<br>[笔记标题链接4] |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/core_workflow.md (reported line 167)May include surrounding context.

md
**📈爆款标题分析**

| 标题类型 | 标题特征                                                                                                           | 标题模版         | 发布规律             | 参考标题                 |
| :------- | :----------------------------------------------------------------------------------------------------------------- | :--------------- | :------------------- | :----------------------- |
| 提问式   | 标题以疑问句开头,设置悬念或提出用户关心的问题,引发用户的好奇心和思考欲望,激发点击阅读或评论互动                 | "你还在XX吗?"   | 工作日早高峰效果最佳 | 这个方法你还在用吗?     |
| 数字式   | 标题中包含具体的数字、数量或统计数据,利用人们对量化信息的偏好,增强内容的可信度和专业感,让用户觉得内容有价值     | "XX个XX技巧"     | 午餐时间点击率高     | 5个快速提升XX的技巧      |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/core_workflow.md (reported line 423)May include surrounding context.

md
**📈爆款标题分析**

| 标题类型 | 标题特征                                                                                                           | 标题模版         | 发布规律             | 参考标题                 |
| :------- | :----------------------------------------------------------------------------------------------------------------- | :--------------- | :------------------- | :----------------------- |
| 提问式   | 标题以疑问句开头,设置悬念或提出用户关心的问题,引发用户的好奇心和思考欲望,激发点击阅读或评论互动                 | "你还在XX吗?"   | 工作日早高峰效果最佳 | 这个方法你还在用吗?     |
| 数字式   | 标题中包含具体的数字、数量或统计数据,利用人们对量化信息的偏好,增强内容的可信度和专业感,让用户觉得内容有价值     | "XX个XX技巧"     | 午餐时间点击率高     | 5个快速提升XX的技巧      |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The subscription prompt encourages users to reply with '订阅' or '1' to create a recurring daily push task, but it does not clearly warn that this creates an ongoing automation with repeated future actions. This weakens informed consent and can lead to users unintentionally authorizing persistent notifications or scheduled processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions say to create a daily 19:30 push automation task immediately on a simple reply, but they omit cancellation, review, and consent safeguards. Persistent automations are higher risk than one-time actions because they continue operating after the current conversation and may surprise users or be difficult to stop.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction explicitly says not to tell the user which category their keyword was mapped to, reducing transparency about how the system interprets and processes input. Hidden classification can mislead users, make outputs harder to validate, and increase the chance of silent misrouting to an unintended category.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow tells the agent to remember and reuse a cached JSON path derived from prior user-triggered fetching for later HTML generation, without any explicit retention limit, access boundary, or renewed consent. Reusing stored user-derived data across steps can expose data longer than necessary and may enable unintended reuse if context or users change.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script serializes attacker-controlled JSON into the page and then constructs HTML with string concatenation, inserting fields such as title, userName, avatar, and photoJumpUrl directly into innerHTML and attributes without proper escaping. A crafted data file can therefore inject arbitrary HTML or JavaScript into the generated report, leading to stored XSS when a user opens the file locally in a browser.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The generated HTML automatically loads and executes JavaScript from third-party CDNs when the local file is opened. Because this script embeds unpinned remote dependencies into an otherwise local reporting artifact, anyone opening the HTML implicitly trusts external code that could change, be blocked, or be used for supply-chain compromise, expanding risk beyond simple file generation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script scans shell profile files such as .zshrc and .bashrc to extract API credentials if the environment variable is absent. For a content analytics skill, reading unrelated user configuration files is over-privileged behavior that can access secrets beyond the intended execution scope and normalize credential harvesting patterns.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script automatically saves the full raw API response to disk, even when the user only asked for a ranking query. This creates unnecessary data persistence, can expose sensitive or proprietary response contents to other local users or later processes, and expands the blast radius if the cache directory is read, indexed, synced, or exfiltrated.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.