Back to skill

Security audit

Xhs Mcp Service

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real Xiaohongshu automation service, but it exposes powerful account actions with weak local-network, credential, and file-upload controls.

Install only if you understand that this runs a local service capable of controlling a real Xiaohongshu account. Bind it to localhost, add authentication or firewall isolation, keep cookies.json private, avoid running it as an admin/root user, and require manual review before publishing, commenting, liking, favoriting, or uploading local files.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/index.js:359
Finding

Unauthenticated Network Access Enables Remote Control of the XiaoHongShu Account

Content
View full analysis

Vulnerability Details

File Location: src/index.js:30-31, src/index.js:359-365, and src/index.js:408
Additional Affected Entry Points: src/index-fixed.js:29, src/index-fixed.js:231-246, src/index-fixed.js:273; src/index-sse.js:30, src/index-sse.js:151-157, src/index-sse.js:186
Vulnerability Type: Missing authentication and authorization on a network-exposed MCP service
Risk Level: Critical

Vulnerable Code

js
const PORT = process.env.XHS_PORT || 18060;
const HOST = process.env.XHS_HOST || '0.0.0.0';
js
// Handle all /mcp requests
app.all('/mcp', async (req, res) => {
  console.error(`\n收到请求: ${req.method} ${req.url}`);
  console.error('Content-Type:', req.headers['content-type']);
  console.error('Accept:', req.headers.accept);

  try {
    await transport.handleRequest(req, res);
js
app.listen(PORT, HOST, () => {

Technical Analysis

The MCP server binds to 0.0.0.0 by default, making it reachable through every network interface available to the host. The /mcp route forwards requests directly to the MCP transport without verifying an API key, bearer token, client certificate, session, source address, or user authorization.

The registered tools include sensitive and state-changing operations such as:

  • delete_cookies
  • like_feed
  • favorite_feed
  • post_comment_to_feed
  • reply_comment_in_feed
  • publish_content
  • publish_with_video

These operations execute through a browser carrying the victim's saved XiaoHongShu authentication cookies. Possession of an xsec_token for individual content does not authenticate the caller to this local service and does not protect tools such as publishing or deleting cookies.

The same access-control weakness is present in the alternate HTTP and SSE server implementations.

Attack Path

  1. A victim starts the service using its default configuration.
  2. The service liste ...[truncated 1138 chars]
Remediation
View remediation

Remediation Suggestions

  1. Change the default binding address to 127.0.0.1 or ::1.
  2. Require a cryptographically strong bearer token, mutual TLS, or another authenticated transport before dispatching any MCP request.
  3. Compare tokens using constant-time logic and load credentials from a protected secret store.
  4. Implement authorization policies that distinguish read-only tools from account-changing tools.
  5. Require explicit user confirmation for publishing, commenting, cookie deletion, and other destructive operations.
  6. Restrict access at the host firewall or reverse proxy and do not expose the port directly to untrusted networks.
  7. Add request rate limiting, security event logging, request-size limits, and origin or host validation.
  8. Apply equivalent controls to index-fixed.js, index-sse.js, and index-progressive.js.
  9. Document that remote exposure is unsupported unless authentication and TLS are configured.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/xhs-tools.js:551
Finding

Caller-Controlled Local Paths Can Be Uploaded Through Publishing Tools

Content
View full analysis

Vulnerability Details

File Location: src/index.js:281-289, src/index.js:318-325, src/xhs-tools.js:551-556, and src/xhs-tools.js:633-637
Vulnerability Type: Arbitrary local-file selection and upload
Risk Level: Critical

Vulnerable Code

js
server.tool(
  'publish_content',
  '发布图文内容到小红书',
  {
    title: z.string().max(20).describe('标题(最多20字)'),
    content: z.string().max(1000).describe('正文内容(最多1000字)'),
    images: z.array(z.string()).min(1).describe('图片路径列表(HTTP链接或本地绝对路径)'),
js
server.tool(
  'publish_with_video',
  '发布视频内容到小红书',
  {
    title: z.string().max(20).describe('标题(最多20字)'),
    content: z.string().max(1000).describe('正文内容(最多1000字)'),
    video: z.string().describe('本地视频文件绝对路径'),
js
// Upload images
for (const imagePath of images) {
  const uploadInput = await page.$('input[type="file"]');
  if (uploadInput) {
    await uploadInput.uploadFile(imagePath);
    await sleep(2000);
  }
}
js
// Upload video
const uploadInput = await page.$('input[type="file"]');
if (uploadInput) {
  await uploadInput.uploadFile(video);
  await sleep(10000);
}

Technical Analysis

The MCP schemas accept caller-supplied filesystem paths. Those values are passed directly to Puppeteer's uploadFile method without:

  • Restricting access to a dedicated upload directory
  • Canonicalizing paths with realpath
  • Rejecting traversal or symbolic links
  • Confirming ownership or intended user selection
  • Validating extension, MIME type, magic bytes, or file size
  • Requiring local user approval before the upload

Puppeteer resolves the path using the privileges of the Node.js service process and makes the selected file available to the remote website's file input. Consequently, a caller can make the service access any compatible file readable by its operating-system account.

Although XiaoHongShu may reject unsupported format ...[truncated 1480 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not expose arbitrary filesystem paths through the MCP interface.
  2. Require files to be staged in a dedicated, owner-only upload directory.
  3. Return opaque file identifiers to clients and resolve those identifiers server-side instead of accepting paths.
  4. Canonicalize each candidate using fs.realpath and verify that the result remains under the approved directory.
  5. Reject .. traversal, symbolic links, device files, network paths, and paths outside the allowlisted root.
  6. Validate extension, MIME type, file signature, dimensions, duration, and maximum size before upload.
  7. Open files using protections against symbolic-link races where supported.
  8. Run the service as an unprivileged OS account with access only to the upload directory.
  9. Require explicit local confirmation showing the canonical path, file type, destination, and intended publication visibility.
  10. Remove staged files securely after the operation completes or expires.

T09 · Insecure Skill Coding Practices

Error
Location
src/browser.js:95
Finding

Authentication Cookies Are Persisted in Plaintext Without Explicit Owner-Only Permissions

Content
View full analysis

Vulnerability Details

File Location: src/browser.js:13, src/browser.js:81-86, and src/browser.js:95-99
Vulnerability Type: Insecure storage of authentication material
Risk Level: High

Vulnerable Code

js
const COOKIES_PATH = path.join(__dirname, '..', 'data', 'cookies.json');
js
async loadCookies() {
  try {
    const cookiesString = await fs.readFile(COOKIES_PATH, 'utf-8');
    const cookies = JSON.parse(cookiesString);
    await this.page.setCookie(...cookies);
    console.error('✅ Cookies 加载成功');
js
async saveCookies() {
  const cookies = await this.page.cookies();
  await fs.mkdir(path.dirname(COOKIES_PATH), { recursive: true });
  await fs.writeFile(COOKIES_PATH, JSON.stringify(cookies, null, 2));
  console.error('✅ Cookies 保存成功');
}

Technical Analysis

The complete browser cookie collection is serialized as plaintext JSON under the project directory. The directory and file are created without explicit mode settings, so their effective permissions depend on the process umask, inherited directory permissions, platform defaults, and ACL configuration.

On systems with a permissive umask or shared project directory, other local accounts or processes may be able to read the file. The cookie file may contain session credentials that allow an attacker to impersonate the authenticated account without knowing its password.

The code also does not verify file ownership, reject symbolic links, encrypt the stored data, or validate that the cookie file has secure permissions before loading it.

Attack Path

  1. The victim logs in using src/login.js.
  2. saveCookies() writes the authenticated browser cookies to data/cookies.json.
  3. A local attacker, compromised process, backup collector, or shared-directory user obtains read access to that file.
  4. The attacker copies the cookie values and imports them into another browser or automation sessio ...[truncated 824 chars]
Remediation
View remediation

Remediation Suggestions

  1. Store session credentials in an operating-system keychain or encrypted secret store.
  2. If a file is unavoidable, create data with mode 0700 and cookies.json with mode 0600.
  3. Set permissions explicitly rather than relying on the process umask.
  4. Use atomic creation with exclusive flags, validate ownership, and reject symbolic links before reading or writing.
  5. Keep the credential file outside the source tree and exclude it from backups, synchronization, package publication, and version control.
  6. Encrypt stored cookies using a key maintained outside the project directory.
  7. Minimize the stored cookie set and define expiration, revocation, and rotation procedures.
  8. Refuse to start if the credential file or parent directory has unsafe ownership or permissions.
  9. Clear both the file and in-memory browser cookies when the user invokes the cookie-deletion operation.

T09 · Insecure Skill Coding Practices

Error
Location
src/browser.js:34
Finding

Chromium Sandbox, Same-Origin Security, and Site Isolation Are Disabled

Content
View full analysis

Vulnerability Details

File Location: src/browser.js:34-41
Vulnerability Type: Unsafe browser security configuration
Risk Level: High

Vulnerable Code

js
const launchOptions = {
  headless: this.headless,
  args: [
    '--no-sandbox',
    '--disable-setuid-sandbox',
    '--disable-blink-features=AutomationControlled',
    '--disable-web-security',
    '--disable-features=IsolateOrigins,site-per-process',
  ],

Technical Analysis

The browser is deliberately launched with several core security boundaries disabled:

  • --no-sandbox disables Chromium's process sandbox.
  • --disable-setuid-sandbox disables the Linux setuid sandbox mechanism.
  • --disable-web-security disables significant same-origin policy enforcement.
  • --disable-features=IsolateOrigins,site-per-process weakens site isolation.

These flags are applied while Chromium loads live remote websites and executes their JavaScript. Browser automation does not require disabling same-origin policy or site isolation for the operations implemented in this project.

Without the sandbox, successful exploitation of a Chromium renderer vulnerability has a more direct path to the privileges of the Node.js service account. Disabling web security and site isolation also increases the potential effect of malicious or compromised cross-origin content loaded by the page.

Attack Path

  1. The service starts Chromium using the insecure launch flags.
  2. The automated browser visits XiaoHongShu pages and loads their scripts, advertisements, media, and other remote resources.
  3. A malicious or compromised resource exploits a Chromium vulnerability or abuses the weakened cross-origin configuration.
  4. Because sandbox and isolation protections are disabled, the exploit has fewer barriers between renderer code and the host environment or authenticated browser state.
  5. The attacker may access session data or obtain the privileges o ...[truncated 560 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove --no-sandbox and --disable-setuid-sandbox.
  2. Remove --disable-web-security.
  3. Remove the flag that disables IsolateOrigins and site-per-process.
  4. Run Chromium as a dedicated, unprivileged operating-system account.
  5. Configure the deployment host or container so Chromium's normal sandbox can operate.
  6. If containerization is used, retain Chromium's sandbox and also apply seccomp, capability dropping, read-only filesystems, and restricted volume mounts.
  7. Keep Puppeteer and its bundled Chromium version updated with security patches.
  8. Restrict browser network access to required XiaoHongShu domains where operationally feasible.
  9. Avoid running the service as root or with access to sensitive host directories.
  10. Fail securely rather than automatically disabling the sandbox when the environment is incompatible.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (62)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims full Xiaohongshu operational capability, but the documented/observed behavior does not substantiate that breadth. This mismatch can mislead users and agents into trusting the skill for sensitive account actions without understanding its real behavior, which is risky in automation contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger condition is so broad that ordinary mentions of Xiaohongshu may activate the skill even when the user did not intend account operations. Over-broad invocation increases the risk of unnecessary access to local services and accidental execution of account-affecting workflows.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
import { publishContent } from './src/xhs-tools.js';

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
import { publishContent } from './src/xhs-tools.js';

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
- **浏览器管理**: `src/browser.js`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · USAGE.md (reported line 168)May include surrounding context.

bash
# 删除旧 cookies 重新登录
rm data/cookies.json
npm run login

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The function uploads user-supplied media and clicks the publish button, causing an irreversible or hard-to-retract post from the user's creator account without an explicit confirmation barrier. In an agent skill, this materially increases the risk of unauthorized brand/account activity, accidental leaks of local files, and reputational or compliance damage.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This function performs the same high-impact action for video content: it uploads a local file and publishes it from the user's account with no explicit confirmation step. The combination of local file access and account posting is especially sensitive in an MCP setting because a compromised prompt chain could exfiltrate or publicly disclose unintended media.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The install guide tells users to execute npx @modelcontextprotocol/inspector without pinning a version. That causes retrieval and execution of the latest published package at runtime, which creates supply-chain risk if the package is compromised, replaced with a malicious release, or unexpectedly changed. In the context of an MCP-related tool, users are being instructed to run code locally on a machine that may also hold browser sessions, credentials, or automation secrets, making this more sensitive than a generic docs issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section documents state-changing actions such as deleting cookies, liking, favoriting, commenting, and publishing without an explicit warning that these actions affect a real user account and may have irreversible or publicly visible consequences. In an MCP skill context, such omissions are more dangerous because an AI agent may operationalize these capabilities quickly and users may not realize account state or public content will be modified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The Claude integration examples explicitly encourage autonomous social-media actions such as searching, liking multiple results, and publishing content, but do not instruct that these actions should require explicit human approval. In the skill context, this increases risk of unintended mass interaction, account misuse, spammy behavior, or accidental public posting by an AI assistant.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The scheduled publishing guidance promotes unattended public posting without warning about risks such as accidental publication, stale or unreviewed content, policy violations, or reputational damage. Because this is an automation skill for a real social platform, unattended posting materially increases the chance of unauthorized or unintended public actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README advertises account-affecting actions such as liking, commenting, deleting cookies, and publishing content, but does not place clear safety warnings, confirmation expectations, or abuse-prevention guidance next to those capabilities. In an agent skill context, this increases the risk of unintended destructive or reputation-affecting actions being triggered on a real user account.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents environment-variable use and local service interaction but does not declare any explicit tool scope or permissions boundary. That makes it easier for an agent framework to invoke the skill with broader-than-necessary capabilities, increasing the chance of unintended access to local resources or environment-derived secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables actions that can modify a real Xiaohongshu account state, including posting, liking, favoriting, commenting, and deleting cookies, but it does not require explicit user warning or confirmation. In an agent setting, this can lead to accidental account changes, session loss, or reputational damage from unintended social actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

Using an unpinned package via npx installs and executes whatever version is current at runtime. This creates a supply-chain risk where a malicious or compromised upstream release could run arbitrary code on the local machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation states that login cookies are automatically saved to data/cookies.json but does not warn that these cookies are sensitive authentication material. If mishandled, copied, committed, or read by other local users/processes, they could enable account takeover or unauthorized use of the XHS account.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file documents actions such as liking, favoriting, commenting, replying, and publishing content, but does not clearly warn that these operations modify the user's live XHS account and may create public or hard-to-reverse side effects. In an MCP skill context, users may trigger these tools through an agent, so missing warnings materially increases the risk of unintended account actions and platform abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module automatically reloads previously saved cookies from disk and injects them into the browser session, reusing authentication state without any confirmation or visibility to the user. If an attacker can plant or tamper with the cookie file, or if stale sensitive cookies remain on disk, the automation may run under an unintended account or expose a valid session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code persists authenticated browser cookies to a predictable local JSON file in plaintext, which can enable session hijacking if the host is shared, compromised, or backed up insecurely. In the context of an XHS automation skill, those cookies likely grant account access, so silent persistence meaningfully increases credential exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file exposes multiple state-changing MCP tools such as deleting cookies, liking/favoriting content, posting comments, and publishing posts, but it does not implement any confirmation, authorization, or policy gate before executing them. In an MCP setting, this is risky because an upstream agent or prompt-injected workflow could trigger real account actions on behalf of the user without a clear last-mile consent check.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.