Back to skill

Security audit

xhs-search

Security checks for vulnerabilities and agentic risk

Overview

The skill’s search purpose is understandable, but it asks users to install and keep running an unverified logged-in account service that can also post, like, and favorite content.

Install only if you are comfortable running an unaudited third-party binary tied to your logged-in Xiaohongshu account. Prefer pinning and verifying the binary, binding the service to 127.0.0.1 only, avoiding launchd/systemd autostart, and using explicit confirmation before any like, favorite, or publish action.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:15
Finding

Unverified Mutable Third-Party Binaries Are Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15-40
Vulnerability Type: Remote retrieval and execution of unverified binaries
Risk Level: High

Vulnerable Code

bash
curl -L -o ~/Downloads/xhs-mcp.tar.gz \
  "https://github.com/xpzouying/xiaohongshu-mcp/releases/latest/download/xiaohongshu-mcp-darwin-amd64.tar.gz"

cd ~/Downloads && tar -xzf xhs-mcp.tar.gz
mkdir -p ~/.local/bin
mv xiaohongshu-login xiaohongshu-mcp ~/.local/bin/
chmod +x ~/.local/bin/xiaohongshu-*

~/.local/bin/xiaohongshu-login -bin "/Applications/Google Chrome.app/Contents/MacOS/Google Chrome"

~/.local/bin/xiaohongshu-mcp -bin "/Applications/Google Chrome.app/Contents/MacOS/Google Chrome" -port ":18060"

Technical Analysis

The installation procedure retrieves precompiled executables from a mutable GitHub latest release and then grants and invokes executable permissions. It does not pin a release version or commit, verify a cryptographic checksum, validate a digital signature, establish artifact provenance, or inspect archive entries before extraction.

Consequently, the effective code executed by users can change after the Skill itself has been reviewed. Although the hosting platform is GitHub, the asset comes from a third-party personal repository and remains outside the audited project. TLS protects the transfer channel but does not establish that the publisher or release artifact is trustworthy.

The login executable is especially sensitive because it launches a browser for account authorization and creates a persistent authenticated session. A compromised executable would run with the installing user's privileges and could access the resulting cookies as well as other files available to that user.

Attack Path

  1. An attacker compromises the third-party repository, its maintainer account, release workflow, or release artifact.
  2. The attacker replaces the asset targeted by the mutable `releases/ ...[truncated 914 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the mutable latest URL with an immutable, explicitly reviewed release version.
  • Publish a trusted SHA-256 or stronger digest and require verification before extraction.
  • Prefer signed releases and verify the signature against a documented maintainer key.
  • Use provenance verification, such as Sigstore attestations, where available.
  • Validate archive entries before extraction to reject absolute paths, traversal entries, links, and unexpected files.
  • Avoid broad glob-based permission changes; verify exact filenames and grant execution permission only to those files.
  • Prefer reproducible builds from pinned, reviewed source over opaque precompiled binaries.
  • Clearly document that the downloaded executable is outside the Skill's audit boundary.
  • Execute the component under a dedicated, restricted account or sandbox with minimal filesystem and network access.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:40
Finding

Authenticated Account-Control Service May Be Exposed Beyond the Local Host

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 40-64
Vulnerability Type: Excessive network exposure and missing documented access control
Risk Level: High

Vulnerable Code

bash
~/.local/bin/xiaohongshu-mcp -bin "/Applications/Google Chrome.app/Contents/MacOS/Google Chrome" -port ":18060"

The documented service exposes the following MCP tools:

text
check_login_status
search_feeds
list_feeds
get_feed_detail
user_profile
like_feed
favorite_feed
publish_content

The bundled client expects a local endpoint:

python
MCP_URL = "http://localhost:18060/mcp"

Technical Analysis

The documented :18060 address commonly instructs servers to listen on port 18060 across all available network interfaces. This conflicts with the bundled client, which only needs a loopback service at localhost.

The service operates with a persistent authenticated Xiaohongshu session and exposes state-changing operations, including publishing, liking, and favoriting content. The documented MCP initialization only establishes a session identifier; the supplied material does not document an independent authentication credential, authorization policy, or network-origin restriction.

Exposing these capabilities to a LAN or other reachable network exceeds the minimum privileges needed for the declared search functionality. The implementation of the downloaded MCP server is not included in the project, so its precise authentication behavior cannot be independently verified. Nevertheless, the documented broad bind and absence of required access-control configuration create a concrete unsafe deployment recommendation.

Attack Path

  1. A user starts the MCP service with -port ":18060".
  2. The server binds to non-loopback interfaces on a host where the port is reachable from a LAN, shared network, container network, or the Internet.
  3. An attacker discovers or otherwise reaches port ...[truncated 805 chars]
Remediation
View remediation

Remediation Suggestions

  • Bind the MCP server explicitly to 127.0.0.1:18060 or an equivalent loopback-only address.
  • Confirm the server's actual binding semantics and fail closed if a loopback bind cannot be enforced.
  • Require strong client authentication using a randomly generated credential stored with restrictive permissions.
  • Add per-tool authorization and expose only read-only search tools required by this Skill.
  • Disable publish_content, like_feed, and favorite_feed unless the user explicitly enables them for a specific task.
  • Apply host firewall rules that deny non-loopback access to the port.
  • Reject untrusted origins and remote clients where the protocol implementation supports origin checks.
  • Run the service under a dedicated, least-privileged account or sandbox.
  • Document how users can verify that the port is not externally reachable.

T06 · System Persistence

Warning
Location
SKILL.md:42
Finding

Unnecessary Boot-Time Persistence Is Recommended for an Authenticated Service

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 42
Vulnerability Type: Persistent background service with unnecessary lifetime
Risk Level: Medium

Vulnerable Instruction

text
Keep the service resident in the background and start it automatically at boot by adding it to launchd or systemd.

This is an English rendering of the instruction at the cited source location.

Technical Analysis

The Skill recommends configuring the downloaded MCP executable as a persistent boot service. Boot-time execution is not required for an on-demand content-search capability. It extends the lifetime of an unaudited third-party binary and leaves an authenticated account-control endpoint running even when no search is being performed.

No hardened service definition, dedicated service identity, sandbox configuration, loopback-only enforcement, resource restrictions, credential protections, or uninstall procedure is supplied. This recommendation therefore increases both persistence and exposure beyond the minimum privileges and duration needed by the declared functionality.

The instruction does not itself install a backdoor, and persistence requires an additional action by the user. The risk arises from encouraging cross-session automatic execution of a sensitive external component without corresponding hardening guidance.

Attack Path

  1. A user follows the recommendation and creates a launchd or systemd startup entry.
  2. The third-party MCP binary starts automatically after login or boot.
  3. The service retains access to the persistent Xiaohongshu session and continues listening even when the Skill is not actively used.
  4. A vulnerability in the service, an unsafe network bind, or a later-compromised binary remains continuously available for exploitation.
  5. An attacker exploits that enlarged exposure window to access the service or execute the compromised component across sessions.

Impact Assessmen

...[truncated 427 chars]

Remediation
View remediation

Remediation Suggestions

  • Start the MCP service only when a search operation is requested and stop it immediately afterward.
  • Remove the recommendation to configure automatic boot or login startup unless persistence is essential and explicitly requested.
  • If persistent operation is necessary, provide hardened launchd and systemd definitions.
  • Use a dedicated unprivileged account, loopback-only networking, filesystem restrictions, process sandboxing, and resource limits.
  • Configure automatic restart conservatively rather than indefinitely restarting a failing or compromised process.
  • Protect session files with restrictive ownership and permissions.
  • Document service status checks, log locations, disablement steps, and complete uninstall procedures.
  • Require explicit user confirmation before creating any cross-session startup configuration.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill notes that it uses an already logged-in Xiaohongshu account, while later instructions state that cookies are stored locally and remain valid long-term, but the user-facing warning is not prominent or explicit enough. This is dangerous because users may not realize the skill can act as their account across sessions and potentially perform account-level operations or expose private browsing context.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill performs network-capable actions through a local MCP endpoint and installs/runs external binaries, but it does not declare any explicit tool scope or allowed-tools boundary. This weakens least-privilege controls and makes it harder for users or the platform to understand what external access and actions the skill may perform.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad and overlap with normal conversational requests such as '分析小红书' or '生成小红书报告', increasing the chance of accidental invocation. In this skill's context, accidental invocation is more dangerous because it can access a persistent logged-in session and expose write-capable operations through the same interface.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

This duplicate finding points to the same persistent authenticated-session behavior: the login flow leaves reusable account state on disk for later MCP operations. In a skill that can do more than search, persistence makes accidental or unauthorized reuse of the account materially more risky.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

"https://github.com/xpzouying/xiaohongshu-mcp/releases/latest/download/xiaohongshu-mcp-darwin-amd64.tar.gz"

cd ~/Downloads && tar -xzf xhs-mcp.tar.gz mkdir -p ~/.local/bin mv xiaohongshu-login xiaohongshu-mcp ~/.local/bin/ chmod +x ~/.local/bin/xiaohongshu-*

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

This duplicate finding points to the same persistent authenticated-session behavior: the login flow leaves reusable account state on disk for later MCP operations. In a skill that can do more than search, persistence makes accidental or unauthorized reuse of the account materially more risky.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

"https://github.com/xpzouying/xiaohongshu-mcp/releases/latest/download/xiaohongshu-mcp-darwin-amd64.tar.gz"

cd ~/Downloads && tar -xzf xhs-mcp.tar.gz mkdir -p ~/.local/bin mv xiaohongshu-login xiaohongshu-mcp ~/.local/bin/ chmod +x ~/.local/bin/xiaohongshu-*

text

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as a search/reporting capability, but the documented toolset includes state-changing account actions such as like, favorite, and publish_content. This creates a capability mismatch that can lead to unintended posting or interaction using the user's logged-in account, especially if invoked under the expectation of read-only analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code transmits the user's search term in an HTTP request to a local MCP endpoint via the search_feeds tool. For code files, network calls that transmit user data should have some visible disclosure, confirmation, or explanatory comment unless the warning is otherwise clearly provided; here the script performs the transmission silently.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.