Back to skill

Security audit

小红书养生笔记日更

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly generates local Xiaohongshu health posts, but it embeds an unrelated WeChat payment/contact upgrade flow that users should review carefully before installing.

Install only if you are comfortable with the local note-archiving workflow and ignore the embedded WeChat upgrade/payment instructions unless you independently trust the publisher. Use a dedicated notes folder, avoid storing sensitive health or personal data, and confirm before any scheduled run saves or indexes content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill markets itself as compliance-safe and explicitly warns against directing users to WeChat, yet it also advertises a paid upgrade via the author's WeChat. This contradiction can mislead users into trusting the skill's safety claims while embedding off-platform solicitation, creating policy-evasion and social-engineering risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This section directly instructs users to add a WeChat account, send money, and transmit proof of payment, despite earlier prohibiting exactly that behavior. It is dangerous because it normalizes policy-violating off-platform contact and payment collection, and could be used for fraud, data harvesting, or account enforcement evasion.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The scheduled-trigger language is underspecified and does not define who configures it, what content it may process, or what safeguards apply. That ambiguity can lead to automatic execution without informed user consent, especially when the workflow includes saving content and indexing it into a library.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The scheduled-trigger language is underspecified and does not define who configures it, what content it may process, or what safeguards apply. That ambiguity can lead to automatic execution without informed user consent, especially when the workflow includes saving content and indexing it into a library.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill mandates a female-gendered voice ('姐妹们') and perspective without asking whether that matches the user's intent or audience. While not a classic security flaw, it can produce unwanted or misleading outputs and reduce user control over generated content.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document includes obfuscated contact variants such as 'VX', 'V我', and similar forms in a section discussing prohibited traffic diversion. Even framed as forbidden examples, including concrete bypass-oriented phrases in an operational skill can educate users on evasion patterns and facilitate cross-platform diversion attempts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The hard rules enforce a fixed gendered tone and persona, including first-person identity and social relationships, instead of allowing user choice. This can lead to deceptive or unsuitable output for contexts where the user does not want fabricated persona traits.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill tells the AI to remember a notes directory and later save files and ingest them into a full-text library, but it does not prominently warn users about persistence or retention. This can cause users to unintentionally store sensitive drafts or behavioral data in locations they did not fully understand.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.