Back to skill

Security audit

GitHub to Xiaohongshu

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a Xiaohongshu content generator, but its bundled script handles repository URLs unsafely and can write files outside its intended output folder.

Install only if you are comfortable reviewing or fixing the bundled script first. Use trusted GitHub URLs, avoid running it on attacker-supplied repository strings, and inspect generated HTML before opening or sharing it. The skill appears aimed at content generation rather than credential theft or persistence, but its file-writing and HTML templating need hardening.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/github-to-xhs.py:399
Finding

Path Traversal Through an Unsanitized Repository Slug

Content
View full analysis
= 2: return path_parts[0], path_parts[1] return None, None def create_slug(repo_name): """Create a URL-friendly slug.""" return repo_name.lower().replace('_', '-').replace(' ', '-') def create_directory_structure(base_path, slug): """Create the output directory structure.""" dirs = [ f"{base_path}/{slug}", f"{base_path}/{slug}/prompts" ] for d in dirs: os.makedirs(d, exist_ok=True) return f"{base_path}/{slug}" ``` ```python github_url = sys.argv[1] owner, repo = extract_repo_info(github_url) if not owner or not repo: print(f"Error: Could not parse GitHub URL: {github_url}") sys.exit(1) slug = create_slug(repo) base_path = "/root/.openclaw/workspace/xhs-images" output_dir = create_directory_structure(base_path, slug) files_to_create = [ (f"{output_dir}/analysis.md", generate_analysis_template(repo, owner, github_url)), (f"{output_dir}/outline-strategy-a.md", generate_outline_strategy_a(repo)), (f"{output_dir}/outline-strategy-b.md", generate_outline_strategy_b(repo)), (f"{output_dir}/outline-strategy-c.md", generate_outline_strategy_c(repo)), (f"{output_dir}/outline-strategy-d.md", generate_outline_strategy_d(repo)), (f"{output_dir}/outline-strategy-e.md", generate_outline_strategy_e(repo)), (f"{output_dir}/outline-strategy-f.md", generate_outline_strategy_f(repo)), (f"{output_dir}/xiaohongshu-post.html", generate_html_template(repo, slug)), ] for filepath, content in files_to_create: with open(filepath, 'w', encoding='utf-8') as f: f.w ...[truncated 2473 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/github-to-xhs.py:293
Finding

Stored HTML Injection in Generated Xiaohongshu Output

Content
View full analysis
{repo_name} - 小红书图文 ``` ```python

{repo_name}

多源研究神器

``` ```python

快速开始

git clone {slug}
``` ```python github_url = sys.argv[1] owner, repo = extract_repo_info(github_url) if not owner or not repo: print(f"Error: Could not parse GitHub URL: {github_url}") sys.exit(1) slug = create_slug(repo) base_path = "/root/.openclaw/workspace/xhs-images" output_dir = create_directory_structure(base_path, slug) files_to_create = [ (f"{output_dir}/analysis.md", generate_analysis_template(repo, owner, github_url)), (f"{output_dir}/outline-strategy-a.md", generate_outline_strategy_a(repo)), (f"{output_dir}/outline-strategy-b.md", generate_outline_strategy_b(repo)), (f"{output_dir}/outline-strategy-c.md", generate_outline_strategy_c(repo)), (f"{output_dir}/outline-strategy-d.md", generate_outline_strategy_d(repo)), (f"{output_dir}/outline-strategy-e.md", generate_outline_strategy_e(repo)), (f"{output_dir}/outline-strategy-f.md", generate_outline_strategy_f(repo)), (f"{output_dir}/xiaohongshu-post.html", generate_html_template(repo, slug)), ] ``` ### Technical Analysis The repository name originates from a command-line URL and ...[truncated 1998 chars]
Remediation
View remediation
{safe_repo_name} - Xiaohongshu Post

{safe_repo_name}

git clone {safe_slug}
``` 3. Prefer a template engine with automatic HTML escaping rather than constructing HTML through raw f-strings. 4. Add a restrictive Content Security Policy to reduce the consequences of any future injection: ```html ``` 5. Avoid permitting inline event handlers or external scripts in generated templates. 6. Add regression tests using repository names containing angle brackets, quotation marks, ampersands, event-handler markup, and traversal components. Tests should verify that invalid names are rejected and that accepted values are rendered only as text. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill promises repository analysis, feature extraction, and technical highlighting, but the finding indicates the implementation may only generate static templates or placeholders without actually analyzing the target repository. This is dangerous because users may trust fabricated or unverified output as if it were derived from the repo, leading to misinformation, accidental misrepresentation, or unsafe downstream decisions based on nonexistent analysis.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs use of network access (web_fetch) and local file creation/packaging, but it declares no explicit tool scope or permissions. That creates an over-broad execution surface where a host agent may grant more capabilities than users expect, increasing the chance of unintended data fetches, file writes, or archive creation from untrusted repository content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The delivery message template is written entirely in Chinese and is presented as the required format when sending files. This imposes a specific language on users without indicating that the user can choose their preferred language or locale.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill analyzes a GitHub repository and supports automatic content analysis, but the generated analysis and post files are static templates filled with TODO placeholders. No code fetches, reads, or inspects repository contents; it only parses the URL and writes boilerplate output files.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes generating Xiaohongshu infographic posts with HTML-based visual output, but the HTML contains placeholder sections and the CLI explicitly instructs the user to manually edit analysis.md and xiaohongshu-post.html afterward. This is a notable mismatch between claimed generation capability and actual scaffold-only behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The generated HTML hard-codes lang="zh-CN", which imposes a specific language/locale on all output. The file does not offer user opt-in or explain that the tool is intentionally region-specific, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill workflow says it fetches repository content and stores outputs in local files and packaged archives, but the description does not warn users about this persistence behavior. This matters because fetched repository text may contain sensitive data, license-restricted material, or prompt-injection content that then gets saved and redistributed in archives without the user's informed consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.