Back to skill

Security audit

xhs-short-url

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to perform the claimed Xiaohongshu URL-shortening workflow, but it needs Review because saved bearer tokens are sent over plaintext HTTP by default and TLS checks can be disabled.

Review before installing. Use this only if you are comfortable sending Xiaohongshu URLs, task data, exports, and account bearer tokens to the configured service. Prefer setting an HTTPS base URL with a valid certificate before login or submission, avoid enabling insecure TLS, and rotate credentials if they may have been used over untrusted networks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
src/config.js:18
Finding

Bearer Token and Task Data Transmitted over Plaintext HTTP by Default

Content
View full analysis

Vulnerability Details

File Location: src/config.js:18-20 (primary location), src/client.js:48-72, cli.js:292-293
Vulnerability Type: Plaintext transmission of credentials and sensitive task data
Risk Level: High

Vulnerable Code

js
// src/config.js:18-20
// The server's HTTPS certificate is not ready, so HTTP remains the default.
const DEFAULT_BASE_URL = 'http://st.aidata366.com';
js
// src/client.js:48-52
if (!_httpWarned && this.token && this.baseUrl.startsWith('http://')) {
  _httpWarned = true;
  process.stderr.write(
    '[warn] Current service address uses plaintext HTTP; the token will be transmitted in plaintext\n'
  );
}
js
// src/client.js:66-72
res = await fetch(this.baseUrl + '/api/v1' + apiPath, {
  method,
  headers: {
    ...(body ? { 'Content-Type': 'application/json' } : {}),
    ...(this.token ? { Authorization: `Bearer ${this.token}` } : {}),
    ...headers,
  },
js
// cli.js:292-293
const res = await fetch(
  `${cfg.baseUrl}/api/v1/platform/exports/${encodeURIComponent(info.export_id)}/file`,
  { headers: { Authorization: `Bearer ${cfg.token}` }, signal: dlCtrl.signal }
);

Technical Analysis

The built-in service URL uses unencrypted HTTP. Authenticated API calls add the locally stored bearer token to the Authorization header and transmit it to this endpoint. Submission bodies, Xiaohongshu URLs, task results, profile information, and exported CSV data may also traverse the same unencrypted channel.

The client detects this condition but only emits a warning to standard error. It neither blocks the request nor requires explicit consent. Therefore, normal use with no custom configuration reaches the unsafe path automatically. Registration and login session requests also inherit the plaintext default.

An on-path attacker can passively read traffic or actively alter requests and responses because HTTP prov ...[truncated 1624 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the default endpoint with a correctly configured HTTPS service using a certificate whose hostname matches the service domain.
  2. Reject authenticated requests to http:// endpoints instead of merely printing a warning.
  3. If plaintext HTTP is needed for isolated development, require an explicit per-invocation opt-in and restrict it to loopback or otherwise trusted development targets.
  4. Do not permit persisted production credentials to be sent when plaintext transport is selected.
  5. Avoid disabling TLS certificate verification in production. Replace self-signed or mismatched certificates rather than relying on NODE_TLS_REJECT_UNAUTHORIZED=0.
  6. Validate resolved service URLs centrally before registration, login, API requests, and export downloads so every network path enforces the same transport policy.
  7. After deploying HTTPS, notify users to rotate tokens that may previously have traversed plaintext networks and migrate saved configurations to the secure endpoint.
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to use Node CLI commands, persistent config files, network access, and shell execution, but the manifest does not declare any tool/permission scope. This creates a capability transparency gap: an agent or reviewer cannot enforce least privilege, and the skill could invoke broader shell/network actions than users expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s natural-language interface, including the top-level description and command help text, is entirely in Chinese and does not provide any opt-in or alternative locale. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
98% confidence
Finding

Setting NODE_TLS_REJECT_UNAUTHORIZED='0' disables HTTPS certificate validation for the entire Node.js process, not just this client or one host. That allows man-in-the-middle interception of API traffic, including bearer tokens and task data, and the skill context makes this especially dangerous because it handles authenticated requests to a paid external service.

Content

Scanner excerpt · src/client.js (reported line 17)May include surrounding context.

js
/** 忽略 HTTPS 证书校验 (服务端自签/域名不匹配证书时由 insecure 配置开启)。进程级。 */
function allowInsecureTls() {
  process.env.NODE_TLS_REJECT_UNAUTHORIZED = '0';
}

/** 业务错误: code 为后端错误码 (1001/1002/3001/...) */

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill specifically for bulk 小红书 long-link to short-link conversion, polling async jobs, and exporting those conversion results. However, this client exposes generic '/platform/tasks' operations parameterized by arbitrary 'capability', plus export endpoints for broader platform tasks, which is semantically wider than the stated short-link-only scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code includes natural-language comments and user-visible stderr messages in Chinese, including the migration notices later in the file, with no indication that language selection is configurable or limited to a justified region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These stderr messages are directly user-facing operational notices, but they are emitted only in Chinese and the code offers no language or locale selection mechanism. This can violate language/locale policy when the skill is not explicitly documented as region-specific or opt-in for that language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This JavaScript file contains natural-language comments and runtime messages entirely in Chinese, including guidance shown to users on stderr/stdout. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The function emits several user-visible messages such as login guidance, insufficient credits, captcha limitations, retry advice, and backend checks only in Chinese. Because these are operational prompts presented to users and there is no visible mechanism to select or negotiate language, this violates the language/locale policy described in SQP-3.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code constructs new BizError(...) inside pollTask, but BizError is neither defined nor imported in this module. When the timeout path is reached, this will raise a ReferenceError instead of the intended business error, breaking error handling and potentially causing the tool to return an internal failure rather than a controlled timeout response. In this skill context, that can disrupt async task polling and make operational failures harder to distinguish and recover from.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description is entirely in Chinese and states when the skill should be used, but it does not indicate that the user can interact in other languages or opt into Chinese. Under the policy, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The package description is written entirely in Chinese and labels the tool as a specific Chinese-platform skill CLI, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
src/client.js:17