Back to skill

Security audit

xhs-comments

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned, but its default setup can send account tokens and exported comment data over unencrypted HTTP, so it needs careful review before installation.

Install only if you are comfortable using a paid third-party Xiaohongshu comment collection service and handling public comment personal data. Before authenticating, prefer configuring a valid HTTPS base URL, avoid insecure mode, and do not use the default plaintext HTTP endpoint on untrusted networks. Review whether you want automatic link conversion and cross-skill credential migration before running collection jobs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
src/config.js:20
Finding

Bearer Tokens and Sensitive Collection Data Transmitted over Plaintext HTTP by Default

Content
View full analysis

Vulnerability Details

File Location: src/config.js:20-23
Vulnerability Type: Plaintext transmission of authentication credentials and sensitive data
Risk Level: High

Vulnerable Code

javascript
// Server certificate is not yet configured, so HTTP remains the default.
const DEFAULT_BASE_URL = 'http://st.aidata366.com';

The default is consumed by src/client.js:49-70, which sends the bearer token with API requests:

javascript
if (!_httpWarned && this.token && this.baseUrl.startsWith('http://')) {
  _httpWarned = true;
  process.stderr.write('[warn] Current service address uses plaintext HTTP...\n');
}

res = await fetch(this.baseUrl + '/api/v1' + apiPath, {
  method,
  headers: {
    ...(body ? { 'Content-Type': 'application/json' } : {}),
    ...(this.token ? { Authorization: `Bearer ${this.token}` } : {}),
    ...headers,
  },
  body: body ? JSON.stringify(body) : undefined,
  signal: ctrl.signal,
});

CSV downloads repeat this behavior in cli.js:386-392:

javascript
const res = await fetch(
  `${cfg.baseUrl}/api/v1/platform/exports/${encodeURIComponent(info.export_id)}/file`,
  {
    headers: { Authorization: `Bearer ${cfg.token}` },
    signal: dlCtrl.signal
  }
);

Technical Analysis

The built-in service URL uses unencrypted HTTP. Authenticated operations attach the account bearer token to the Authorization header, while submissions and responses can include note URLs, task results, account information, public nicknames, comment text, and IP-location data.

The client emits a warning when HTTP is used, and SKILL.md:54-57 discloses the risk, but neither mechanism blocks the request or requires explicit authorization to continue. A warning does not provide confidentiality, integrity, or server authentication.

The project permits users to configure HTTPS, so this is not evidence of covert credential theft or malicious intent. Ne ...[truncated 1593 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the default endpoint with a correctly configured HTTPS service using a certificate valid for the service hostname.
  2. Reject authenticated requests to HTTP endpoints rather than merely printing a warning.
  3. If HTTP compatibility must temporarily remain, require an explicit per-command opt-in before transmitting credentials and clearly state that it must only be used on a trusted isolated network.
  4. Apply the same transport-policy check to the direct CSV download path in cli.js, not only to requests made through ApiClient.
  5. Avoid the process-wide NODE_TLS_REJECT_UNAUTHORIZED=0 bypass. If private certificates must be supported, use a narrowly scoped HTTPS client with an explicitly configured trusted CA.
  6. Rotate tokens that may previously have traversed untrusted plaintext networks after HTTPS enforcement is deployed.
  7. Add automated tests verifying that bearer-authenticated API calls and export downloads fail closed when the destination uses HTTP.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (14)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill requires network, shell, and environment access but does not declare any tool scope restrictions, so an agent may grant broader capabilities than necessary. In this context, the skill performs authenticated scraping, stores tokens locally, and can call external services over HTTP, which increases the blast radius of misuse or prompt-triggered overreach.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation description contains broad trigger terms around comments, scraping, sentiment, and export, which can cause the skill to activate on loosely related requests without clear user intent. Because the skill performs paid collection of personal data fields such as nickname and IP location and may auto-call another conversion skill, unintended activation can lead to privacy-impacting actions, token use, and charges.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The instructions require the agent to send a fixed Chinese registration message to the user and the document consistently mandates Chinese-language interaction, but it does not offer opt-in language selection. This can violate language/locale policy when users operate in other languages and no justification for a Chinese-only constraint is stated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains natural-language instructions, help text, and operational messages exclusively in Chinese, which effectively imposes a specific language on users. The policy allows locale constraints only when explicitly documented and justified or when users are offered a choice, neither of which is present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a tool for collecting/querying/exporting Xiaohongshu note comments, with mention of paid service usage, but this CLI also exposes full register/login flows that create remote sessions, present QR/login links, validate access tokens, and persist auth tokens locally. Authentication is often an implementation detail, but here it is elevated into user-facing commands and behavior beyond the stated comment-collection scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill allows users to disable HTTPS certificate validation via an 'insecure' setting, which can expose bearer tokens, exported data, and task metadata to man-in-the-middle attacks. In a tool handling authentication tokens and downloadable CSV data, this materially weakens transport security and makes interception or response tampering much easier on hostile networks.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
96% confidence
Finding

The function disables TLS certificate verification globally by setting NODE_TLS_REJECT_UNAUTHORIZED='0', which allows man-in-the-middle interception of all subsequent HTTPS requests in the process. In this client, the API uses Bearer tokens and handles account/session actions and data export, so a network attacker could steal credentials, tamper with task responses, or redirect exports without being blocked by certificate validation.

Content

Scanner excerpt · src/client.js (reported line 17)May include surrounding context.

js
/** 忽略 HTTPS 证书校验 (服务端自签/域名不匹配证书时由 insecure 配置开启)。进程级。 */
function allowInsecureTls() {
  process.env.NODE_TLS_REJECT_UNAUTHORIZED = '0';
}

/** 业务错误: code 为后端错误码 (1001/1002/3001/...) */

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s natural-language comments and user-facing stderr messages are entirely in Chinese, including migration notices at L075-L076. Under the policy, forcing a specific language without user opt-in is a language/locale policy violation unless the constraint is explicitly justified and documented as user-facing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code imports credentials from a different skill's config file without an explicit user consent step or strong provenance check. Cross-skill credential reuse expands trust boundaries: a comment-collection tool can silently consume another tool's token and endpoint settings, which may expose unrelated service access or inherit insecure transport settings unexpectedly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The skill's stated purpose is remote comment collection and CSV export, but this module allows XHS_CONFIG_PATH to redirect configuration reads and writes to an arbitrary filesystem path. That testing/account-switching capability is not justified by the end-user purpose described in the manifest and expands local file access behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file’s comments and emitted guidance/messages are written in Chinese, including operational prompts shown to users on errors. Because there is no indication of language choice or opt-in, this appears to impose a specific language/locale on all users, which matches the policy-violation category for language constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The default skillTip and usage-related output shown during error handling are hardcoded in Chinese. This is a natural-language policy concern because the skill does not present a user language choice or clearly justify the locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
99% confidence
Finding

Several authentication, quota, validation, CAPTCHA, retry, and network messages are emitted directly to users in Chinese. Since the file provides no opt-in, fallback, or documented region-specific limitation, this constitutes a language/locale policy violation under the specified rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The timeout message and positive-number validation error are emitted in Chinese and may be presented directly to users. Without an explicit user choice or justified locale restriction, this conflicts with the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.insecure_tls_verification

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
cli.js:235

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
src/client.js:17