Back to skill

Security audit

XHS Content Generate

Security checks for vulnerabilities and agentic risk

Overview

This Xiaohongshu writing skill is coherent and disclosed, with expected external content fetching as its main user-visible risk.

Install this if you want a Chinese Xiaohongshu-style drafting workflow. Expect it to contact 36kr for RSS topics, optionally fetch user-provided reference links with browser-like tools, and use the humanizer-zh dependency for final polishing. Avoid giving sensitive/private links as references, and be aware the RSS helper is not hardened against unusually large or stalled feed responses.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch-rss-hot.js:22
Finding

Unbounded RSS Response Buffering Enables Denial of Service

Content
View full analysis

Vulnerability Details

File Location: scripts/fetch-rss-hot.js, lines 22-28
Vulnerability Type: Unbounded remote response buffering
Risk Level: Medium

Vulnerable Code

js
https.get(url, (res) => {
  let data = '';
  res.on('data', chunk => data += chunk);
  res.on('end', () => resolve(data));
  res.on('error', reject);
}).on('error', reject);

Technical Analysis

The RSS client accumulates the complete HTTPS response in an in-memory string without enforcing a maximum response size. It also does not configure connection or response timeouts, verify that the HTTP status is successful, or validate the response content type before buffering and parsing it.

Although the feed URL is statically configured, exploitation is possible if the configured service or an infrastructure component controlling its valid HTTPS response is compromised. A malicious or malfunctioning endpoint can return an extremely large body or continuously stream data without ending the response. Each chunk is appended to data, causing memory consumption to grow until the process becomes unresponsive or is terminated.

Attack Path

  1. An attacker compromises the configured RSS service or otherwise gains control over the content returned through its valid HTTPS endpoint.
  2. The Skill invokes node scripts/fetch-rss-hot.js.
  3. The endpoint returns a very large response or an indefinitely streamed body.
  4. The data event handler continuously appends received chunks to the in-memory string.
  5. Because no byte limit or timeout exists, the Node.js process exhausts memory or remains occupied indefinitely.
  6. The Skill run fails, and the hosting agent process may suffer degraded availability depending on process isolation.

Impact Assessment

The issue primarily affects availability. It does not directly grant filesystem privileges, command execution, credential access, or privilege escalation.

A successful exploit can exhaust memory allocated to the Node.js ...[truncated 317 chars]

Remediation
View remediation

Remediation Suggestions

  1. Enforce a conservative maximum response size and destroy the request when the limit is exceeded.
  2. Configure connection and response timeouts so stalled or indefinitely streamed responses are terminated.
  3. Reject redirects unless they are explicitly required and constrained to trusted HTTPS hosts.
  4. Accept only successful HTTP status codes, such as 200.
  5. Validate the response Content-Type against expected RSS/XML media types.
  6. Check Content-Length when present, while retaining streamed byte counting because that header can be absent or inaccurate.
  7. Prefer incremental XML parsing rather than buffering the entire document.
  8. Run the script with process-level memory and execution-time limits as defense in depth.
  9. Return a controlled error when any limit is exceeded.

Example hardening pattern:

js
function fetchXML(url) {
  const MAX_BYTES = 2 * 1024 * 1024;
  const TIMEOUT_MS = 10_000;

  return new Promise((resolve, reject) => {
    const req = https.get(url, (res) => {
      if (res.statusCode !== 200) {
        res.resume();
        reject(new Error(`Unexpected HTTP status: ${res.statusCode}`));
        return;
      }

      const contentType = res.headers['content-type'] || '';
      if (!/(application|text)\/(rss\+xml|xml)/i.test(contentType)) {
        res.resume();
        reject(new Error(`Unexpected content type: ${contentType}`));
        return;
      }

      let bytes = 0;
      const chunks = [];

      res.on('data', (chunk) => {
        bytes += chunk.length;
        if (bytes > MAX_BYTES) {
          req.destroy(new Error('RSS response exceeds size limit'));
          return;
        }
        chunks.push(chunk);
      });

      res.on('end', () => {
        resolve(Buffer.concat(chunks).toString('utf8'));
      });

      res.on('error', reject);
    });

    req.setTimeout(TIMEOUT_MS, () => {
      req.destroy(new Error('RSS request timed out'));
    });

    req.on('error', reject);
  });
}
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description centers on generating Xiaohongshu-style爆款笔记 using topic intake, style learning from reference posts, deep opinion generation, and prose optimization. The supplied code does none of that. Its primary purpose is to retrieve and rank hot topics from an RSS feed (36kr), using publication time and feed order to estimate heat, then print a topic list in the terminal. This is a materially different function and includes undeclared network access to external RSS resources. While hot-topic fetching could theoretically support a writing workflow, this code chunk itself only performs topic discovery and ranking, not style analysis or content generation.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
node scripts/fetch-rss-hot.js [keyword]

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description defines the skill exclusively as a 小红书 content generator and all examples/instructions assume Chinese output, but there is no statement that the user may choose another language. This creates a language/locale constraint without explicit opt-in.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
skills: ["humanizer-zh"]
    permissions:
      - "network:https://36kr.com"
      - "file:read:~/.openclaw/workspace/skills/humanizer-zh/SKILL.md"
    behavior:
      networkAccess: true
      usesHumanizerSkill: true

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs the agent to use an external browser/tool on user-provided links, which broadens data access beyond the narrowly declared 36kr RSS permission. This can lead to unintended retrieval of arbitrary external content, increasing exposure to prompt injection, malicious pages, tracking, or privacy issues when processing untrusted links.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill does not warn users that supplied links may be fetched via network-enabled tools and then analyzed as untrusted external content. Without transparency and consent, users may unknowingly trigger requests to third-party sites, leaking metadata or exposing the agent to hostile page content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file title and all guidance are written exclusively in Chinese, and the style-imitation instructions assume output in that language context. Under the policy rule for natural-language violations, a skill that effectively fixes a specific language without user opt-in can be a locale-policy issue unless the regional constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file is entirely framed as a Chinese Xiaohongshu writing template library, with all templates and instructions written only in Chinese and no indication that language is optional. Under the policy for natural-language violations, a skill that enforces a specific language without user opt-in can be noncompliant unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

该脚本实际实现的是从36kr RSS源抓取并排序“热点话题”,属于外部资讯采集/热点发现能力。技能清单中声明的核心能力是话题获取、风格分析、深度观点生成和文风优化;其中“话题获取”可以成立,但这里的实现更具体地引入了面向新闻RSS的热点监测能力,而清单描述和触发场景并未表明该技能会访问外部资讯源来抓取实时热点。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

Multiple user-facing strings in the script are hard-coded in Chinese, such as status messages and the final prompt. This imposes a specific language on users without any opt-in or documented locale constraint, which matches the natural-language policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.