Back to skill

Security audit

xhs-search-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Xiaohongshu research purpose, but it exposes the user's AgentBay API key in console and persistent logs.

Review before installing. Do not run this version with a real AgentBay API key unless the key logging is removed or redacted, and rotate any key already used with it. Treat collected Xiaohongshu notes/comments as local stored data, use a contained environment, and pin dependencies before production use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/common.py:214
Finding

AgentBay API Key Exposed in Plaintext Logs

Content
View full analysis
Remediation
View remediation
= 8 else "[REDACTED]" _log.info("AgentBay credential loaded: %s", masked_key) ``` Complete omission is preferable to masking. 3. Add a centralized logging filter that redacts known secret values and sensitive field names such as `api_key`, `authorization`, `token`, `password`, and `cookie`. 4. Rotate every AgentBay API key used while the vulnerable code was active. Rotation is necessary because deleting logs does not invalidate credentials that may already have been copied. 5. Securely remove existing local logs and investigate whether console output or logs were forwarded to CI/CD systems, support archives, backups, or centralized logging platforms. 6. Restrict log-file permissions to the account executing the skill and reduce retention periods. 7. Add automated tests and secret-scanning checks that fail when credentials or sensitive configuration values appear in log output. ]]>

T08 · Insecure Dependencies

Warning
Location
requirements.txt:6
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Package Changes

Content
View full analysis
=2.0 wuying-agentbay-sdk ``` The documented installation command is: ```bash pip install -r requirements.txt ``` ### Technical Analysis The project installs third-party packages without exact version pins or integrity hashes. Both `playwright` and `wuying-agentbay-sdk` can resolve to any version currently selected by the package index. The `pydantic>=2.0` constraint has no upper bound and can likewise resolve to future releases that were not reviewed with this project. This makes installations non-reproducible and permits the effective dependency code to change after the skill has been audited. If a dependency account, release pipeline, or configured package index is compromised, a malicious future release could be selected automatically. Even without malicious activity, incompatible future releases could introduce security regressions or change behavior. Python packages may execute code during installation and are imported with the privileges of the user running the skill. Dependency integrity is therefore part of the project's trust boundary. ### Attack Path 1. The user follows the documented setup procedure and runs `pip install -r requirements.txt`. 2. `pip` queries the configured package index and resolves the newest versions satisfying the broad constraints. 3. A package release has changed since the project was audited, or the package source, maintainer account, release pipeline, or index has been compromised. 4. Because no exact version or hash is required, `pip` accepts and installs the changed artifact. 5. Malicious installation or imported runtime code executes with the privileges of the user running the skill. 6. That code may access project files, envi ...[truncated 696 chars]
Remediation
View remediation
pydantic== wuying-agentbay-sdk== ``` 2. Generate and maintain a lock file that also constrains transitive dependencies. 3. Record cryptographic hashes for every accepted distribution and install with hash verification: ```bash pip install --require-hashes -r requirements.txt ``` 4. Configure an explicitly trusted package index rather than relying on ambient pip configuration. Consider using an internal package mirror containing approved artifacts. 5. Review dependency provenance, release history, maintainers, and published artifacts before updating pins. 6. Use automated dependency vulnerability scanning and a controlled update process in which version changes are reviewed, tested, and committed deliberately. 7. Perform dependency installation in an isolated virtual environment or container with minimal filesystem access and without unnecessary credentials in the environment. 8. Update `SKILL.md` so its installation procedure requires the locked, hash-verified dependency set. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code logs the full AgentBay API key via _log.info(f"session_id: {session_id}, api_key:{api_key}"), which exposes a credential to local log files and console output. Anyone with access to logs can reuse the key to access the AgentBay account or associated resources, and this exposure is unrelated to the stated keyword-research functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

A sensitive API credential is written to persistent logs without masking or user warning, creating direct secret leakage. Because this skill stores logs to disk and also enables console logging, the credential may be exposed to operators, other processes, or anyone who can read archived logs.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to use capabilities that include environment access, local file read/write, and networked browser automation, but it does not declare any explicit tool scope or permission boundaries. This creates a least-privilege failure: an agent may invoke powerful capabilities without a machine-readable restriction layer, increasing the risk of over-broad file access, credential exposure, or unintended network actions if the skill is triggered or adapted incorrectly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger description includes broad everyday phrases like '帮我在小红书搜/查/看热点/找笔记/提取评论/做舆情分析', which can overlap with normal conversation and cause unintended activation. Because this skill performs login-state handling, network browsing, and local state/file modification, accidental invocation is more dangerous than in a read-only skill and could lead to unnecessary external actions or exposure of persisted session context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file's natural-language documentation is written exclusively in Chinese, and the script's user-facing messages throughout the file also assume Chinese as the required language. Under the policy, forcing a specific language without user opt-in or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The browser initialization hard-codes locales=["zh-CN"] at L275. This is a natural-language/locale policy concern because it forces a specific locale without offering user opt-in or documenting that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and subsequent status/message text are written only in Chinese, and the script does not indicate that language selection is optional or that the skill is intentionally restricted to Chinese-speaking users. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script is explicitly designed to extract Xiaohongshu note content and comments, then persist that data to local JSON files and status metadata, but it provides no user-facing notice, consent checkpoint, minimization, or retention controls. Because comments and note content can contain personal data or sensitive opinions, silent collection and storage increases privacy, compliance, and misuse risk, especially in a workflow framed as public-opinion analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The docstring, CLI help, logs, and status messages are written in Chinese with no indication that users can choose another language. This creates a language-policy issue because the skill imposes a locale/language preference rather than offering an opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This file contains natural-language instructions and comments exclusively in Chinese, including installation guidance. For a general-purpose skill file, forcing a specific language without user opt-in or documented regional justification can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The dependency 'playwright' is unpinned, so installs may pull different versions over time, including versions with security defects or breaking changes. In a browser-automation skill that logs into a third-party platform and processes session state, dependency drift increases supply-chain and runtime risk.

Content

Scanner excerpt · requirements.txt (reported line 6)May include surrounding context.

text
# 安装:
#   pip install -r requirements.txt
#
playwright
pydantic>=2.0
wuying-agentbay-sdk

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The dependency constraint 'pydantic>=2.0' allows a broad range of versions, including future releases that may introduce vulnerabilities or incompatible behavior. Because this skill likely uses structured parsing and validation for scraped content, depending on an unbounded version range can expose the runtime to known or newly introduced issues.

Content

Scanner excerpt · requirements.txt (reported line 7)May include surrounding context.

text
#   pip install -r requirements.txt
#
playwright
pydantic>=2.0
wuying-agentbay-sdk

Unverifiable Dependency: pydantic has 4 known advisory(ies) (CVE-2021-29510 (Use of "infinity" as an input to datetime and date fields causes infinite loop i); CVE-2024-3772 (Pydantic regular expression denial of service); CVE-2021-29510 (Pydantic is a data validation and settings management using Python type hinting.) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
84% confidence
Finding

The manifest does not pin a specific 'pydantic' version, so it is impossible to verify whether the installed release includes fixes for known advisories. In a scraping and data-processing skill, a vulnerable validation library could enable denial of service or other parser-related issues if malicious input is processed.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The dependency 'wuying-agentbay-sdk' is unpinned, which creates supply-chain risk because future installs may resolve to an unexpected or compromised release. This is more sensitive here because the SDK interfaces with the AgentBay sandbox/browser environment and may handle authentication state or privileged automation actions.

Content

Scanner excerpt · requirements.txt (reported line 8)May include surrounding context.

text
#
playwright
pydantic>=2.0
wuying-agentbay-sdk

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code sends search terms to an external website, which can disclose user-provided or configured data over the network. Although the module docstring describes the search behavior, there is no runtime confirmation or explicit privacy warning to the user about transmitting keywords to a third-party service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.