Back to skill

Security audit

Xiaohongshu (RedNote) & Douyin Reader: transcript, image OCR, English translation

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently sends a user-provided public social-media link to LinkDigest for paid extraction and translation, with the main privacy and cost implications disclosed.

Install only if you are comfortable sending the public link or copied share text to linkdigest.dev under your LinkDigest API key. Use --max-credits for budget control, avoid private or sensitive links because results may be cached by link, and treat translations, OCR, summaries, and model-written key points as service output to verify against originals.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill requires access to an API key, shell execution, and outbound network access, but it does not declare an explicit tool scope or allowed-tools policy. That increases the attack surface because a host agent may grant broader capabilities than necessary, making misuse of the API key or arbitrary command execution more likely if the skill is invoked in an unexpected context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest says this skill is for reading Xiaohongshu/RedNote and Douyin links, but the code's own CLI description and help text explicitly support TikTok, YouTube, X, and WeChat articles. That means the implemented behavior is materially broader than the advertised scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.