Back to skill

Security audit

xhs-dpt

Security checks for vulnerabilities and agentic risk

Overview

The skill’s data-collection purpose is coherent, but it should be reviewed because its default service URL sends bearer tokens and submitted links over plain HTTP.

Install only if you are comfortable sending Xiaohongshu note links, xsec_token URL parameters, and the service bearer token to the provider. Prefer configuring a working HTTPS base URL before login or submission, avoid enabling insecure TLS except for controlled testing, and protect ~/.xhs-platform/config.json as an account credential.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
src/config.js:17
Finding

Bearer Credentials and Sensitive Task Data Transmitted over Plaintext HTTP by Default

Content
View full analysis

Vulnerability Details

File Location: src/config.js:17, with authenticated request sinks at src/client.js:48-70 and cli.js:310-313
Vulnerability Type: Plaintext transmission of credentials and sensitive data
Risk Level: High

Complete Code Snippets

src/config.js:17:

js
const DEFAULT_BASE_URL = 'http://st.aidata366.com';

src/client.js:48-70:

js
// Plaintext HTTP with a token only produces a warning; the request proceeds.
if (!_httpWarned && this.token && this.baseUrl.startsWith('http://')) {
  _httpWarned = true;
  process.stderr.write('[warn] Current service address uses plaintext HTTP; the token will be transmitted in plaintext\n');
}

const ctrl = new AbortController();
const timer = setTimeout(() => ctrl.abort(), REQUEST_TIMEOUT_MS);
let res;
let payload = null;
try {
  res = await fetch(this.baseUrl + '/api/v1' + apiPath, {
    method,
    headers: {
      ...(body ? { 'Content-Type': 'application/json' } : {}),
      ...(this.token ? { Authorization: `Bearer ${this.token}` } : {}),
      ...headers,
    },
    body: body ? JSON.stringify(body) : undefined,
    signal: ctrl.signal,
  });

cli.js:310-313:

js
const res = await fetch(`${cfg.baseUrl}/api/v1/platform/exports/${encodeURIComponent(info.export_id)}/file`,
  { headers: { Authorization: `Bearer ${cfg.token}` }, signal: dlCtrl.signal });

Technical Analysis

The built-in service endpoint uses unencrypted HTTP. The API client attaches the account bearer token to authenticated requests regardless of whether the transport is encrypted. Registration and login session operations, profile and quota queries, submitted Xiaohongshu links, task results, and CSV exports consequently use plaintext transport under the default configuration.

The warning at src/client.js:48-52 is informational only. It neither prevents the request nor requires an explicit per-request acknowledgm ...[truncated 2123 chars]

Remediation
View remediation

Remediation Suggestions

  1. Deploy a correctly configured HTTPS endpoint and change DEFAULT_BASE_URL to its https:// URL.
  2. Reject authenticated API calls, login or registration session checks, and export downloads when baseUrl uses HTTP.
  3. If plaintext HTTP is required for local development, permit it only through an explicit development-only option and restrict it to loopback addresses by default.
  4. Do not rely on a stderr warning as a security control; fail closed before attaching bearer credentials to an insecure request.
  5. Keep TLS certificate verification enabled. Avoid carrying insecure: true into normal production use, and require explicit acknowledgment for any diagnostic exception.
  6. After migrating to HTTPS, revoke or rotate tokens that may previously have traversed plaintext networks.
  7. Consider minimizing sensitive URL retention and logging because submitted links contain xsec_token values.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to use network and shell-capable operations, persist authentication tokens in a user-level config file, and interact with a remote service, but it declares no explicit tool scope or permission boundaries. This creates an over-privileged integration surface where an agent may invoke shell, network, or environment access without clear restriction, increasing the risk of data exposure, unsafe command execution patterns, and misuse of stored credentials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The registration/login guidance explicitly instructs the agent to relay fixed Chinese wording verbatim to the user, and the entire operational guidance assumes Chinese-language communication. This is a natural-language locale policy issue because the skill does not offer any user opt-in or alternative language path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language interface, usage text, prompts, and operational guidance are entirely in Chinese, including user-facing instructions such as login/registration guidance and error/help text. This imposes a specific language on users without any visible opt-in, fallback, or locale-selection mechanism, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
98% confidence
Finding

The helper explicitly disables TLS certificate verification process-wide by setting NODE_TLS_REJECT_UNAUTHORIZED=0. This allows man-in-the-middle interception of all subsequent HTTPS requests in the process, including the Bearer token used by this client, which is especially risky for a data-collection skill that authenticates to a backend service and may handle exported results.

Content

Scanner excerpt · src/client.js (reported line 17)May include surrounding context.

js
/** 忽略 HTTPS 证书校验 (服务端自签/域名不匹配证书时由 insecure 配置开启)。进程级。 */
function allowInsecureTls() {
  process.env.NODE_TLS_REJECT_UNAUTHORIZED = '0';
}

/** 业务错误: code 为后端错误码 (1001/1002/3001/...) */

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains natural-language instructions and runtime notices in Chinese, including the stderr messages used during credential migration. Under the policy rule, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is clearly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The migration warnings written to stderr are user-facing operational messages, but they are only presented in Chinese. Because the file does not offer a language choice or indicate that the skill is intentionally limited to a Chinese-speaking audience, this violates the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file contains natural-language comments and runtime messages exclusively in Chinese, including guidance shown to users on errors. This imposes a specific language/locale without any indication that users can choose another language, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The comment documents a timeout path that throws a BizError carrying the last task status. However, this file does not define or import BizError before constructing it at L74, so the actual behavior would be a ReferenceError rather than the documented BizError flow.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
src/client.js:17