Back to skill

Security audit

小红书图文笔记提取|小红书文案提取(含图片文字 OCR)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed LinkDigest client that sends user-provided Xiaohongshu links to an external OCR/digest API, with no hidden local persistence or account access found.

Before installing, be comfortable sending each submitted link or share text to linkdigest.dev with your LinkDigest API key. Do not submit private or sensitive links, because text results are cached by link and may be reused for the same public link. Avoid the optional unpinned npx MCP command unless you trust that npm package path, and use max-credit limits when cost matters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
实测同一条图文笔记(公开结果页:https://linkdigest.dev/d/5d0e7837ec2742ea4ae07806d979f0ce ):

- 直接 curl 网页,去掉脚本和样式后只剩 860 个可见字符;
- yt-dlp 报 `No video formats found`(它只认视频笔记);
- LinkDigest 返回的 Markdown 是 35,059 个字符,约为前者的 41 倍。

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
实测同一条图文笔记(公开结果页:https://linkdigest.dev/d/5d0e7837ec2742ea4ae07806d979f0ce ):

- 直接 curl 网页,去掉脚本和样式后只剩 860 个可见字符;
- yt-dlp 报 `No video formats found`(它只认视频笔记);
- LinkDigest 返回的 Markdown 是 35,059 个字符,约为前者的 41 倍。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

提交:

bash
curl -sS -X POST https://linkdigest.dev/api/v1/digest \
  -H "Authorization: Bearer $LINKDIGEST_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url": "https://www.xiaohongshu.com/explore/<笔记ID>?xsec_token=<...>", "format": "json"}'

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill instructs users to run npx mcp-remote without pinning a version or integrity. That can cause execution of a changed or compromised package from the npm registry, creating a supply-chain risk on the local machine.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a narrowly scoped skill for extracting Xiaohongshu 图文笔记 content and OCR text from images. However, the CLI advertises and accepts broader platform usage such as 抖音, TikTok, YouTube, X, and公众号文章, plus video-oriented options like transcript depth and partial long-video handling, which materially exceeds the declared skill purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest presents this skill as an extractor for note text, OCR text, image descriptions, key points, likes/favorites, and hashtags. The code adds separate paid capabilities for translation and marketing-style breakdown analysis, which are not described as part of the skill’s intended behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.