Back to skill

Security audit

Xiaohongshu Store

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Xiaohongshu Store connector, but its fallback setup tells the agent to install an external CLI by executing a remote script without verification.

Install only if you are comfortable giving the OOMOL connector access to your Xiaohongshu Store account and letting the agent perform confirmed store operations. Before using the first-time setup commands, verify the oo CLI installer through OOMOL's official documentation or install it manually instead of letting the agent pipe a remote script directly into a shell.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
- `list_supported_ports` — List the customs ports supported by Xiaohongshu for cross-border clearance.
- `modify_order_express` — Change the express tracking number of a shipped Xiaohongshu order. Only available after shipment and before receipt. [write]
- `modify_order_remark` — Modify the seller remark and flag of a Xiaohongshu order. [write]
- `refresh_token` — Refresh the access token using the refresh token stored in the connection credential. Xiaohongshu only issues new tokens when the access token has under 30 minutes left or has expired; otherwise it returns the current ones unchanged. A changed token set must be saved back to the connection, and the old access token stays valid for only 5 more minutes. Access tokens expire after 7 days. [write]
- `resend_payment_record` — Ask Xiaohongshu to notify the payment company to push the payment record to customs again for a bonded cross-border order. [write]
- `search_brands` — Search the brands available for a leaf Xiaohongshu category.
- `search_items` — Search Xiaohongshu items with full publish fields using keywords, item codes, or availability filters.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
- `list_supported_ports` — List the customs ports supported by Xiaohongshu for cross-border clearance.
- `modify_order_express` — Change the express tracking number of a shipped Xiaohongshu order. Only available after shipment and before receipt. [write]
- `modify_order_remark` — Modify the seller remark and flag of a Xiaohongshu order. [write]
- `refresh_token` — Refresh the access token using the refresh token stored in the connection credential. Xiaohongshu only issues new tokens when the access token has under 30 minutes left or has expired; otherwise it returns the current ones unchanged. A changed token set must be saved back to the connection, and the old access token stays valid for only 5 more minutes. Access tokens expire after 7 days. [write]
- `resend_payment_record` — Ask Xiaohongshu to notify the payment company to push the payment record to customs again for a bonded cross-border order. [write]
- `search_brands` — Search the brands available for a leaf Xiaohongshu category.
- `search_items` — Search Xiaohongshu items with full publish fields using keywords, item codes, or availability filters.

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs users to install software via curl ... | bash, which executes remote script content directly without verification. If the hosting domain, transport, or script supply chain is compromised, this can lead to arbitrary code execution on the user's machine under their account.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

Static analysis

No suspicious patterns detected.