Back to skill

Security audit

Xiaohongshu Search Suggest Keywords Collection

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated keyword-collection purpose, but it includes under-disclosed anti-bot and CAPTCHA-bypass guidance for a third-party platform.

Review this carefully before installing. Use it only where automated collection is allowed by Xiaohongshu's rules and applicable law, avoid CAPTCHA-bypass behavior, run Playwright in a limited environment, and pin dependencies before installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Playwright Dependency and Browser Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20–21
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

bash
npm install playwright
npx playwright install chromium

Technical Analysis

The installation instructions retrieve Playwright and its Chromium browser components without specifying an exact package version, lockfile, integrity hash, or trusted registry configuration. Consequently, the effective components installed when a user follows these instructions may differ from those reviewed during the audit.

The unqualified npm install playwright command resolves a mutable package version according to npm registry state and local configuration. Package installation can run npm lifecycle scripts with the privileges of the invoking user. The subsequent npx playwright install chromium command also downloads a browser binary associated with the resolved Playwright release.

Exploitation requires compromise or malicious substitution within the dependency delivery chain, such as a compromised package release, registry or configuration manipulation, or another supply-chain failure. The audit found no evidence that the current Playwright package itself is malicious; the risk arises from installation instructions that do not provide reproducible or integrity-verified dependency resolution.

Attack Path

  1. An attacker compromises a package release or influences the npm dependency-resolution path or configured registry.
  2. A user follows the documented prerequisite and runs npm install playwright.
  3. npm resolves and installs the attacker-controlled or compromised component because no audited version or lockfile constrains resolution.
  4. Malicious package lifecycle code may execute during installation with the privileges of the user running npm.
  5. Alternatively, the following npx playwright install chromium command may retrieve an unexpected browser artifa ...[truncated 639 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin Playwright to a reviewed exact version rather than relying on the current registry default:
    bash
    npm install --save-exact playwright@<reviewed-version>
    
  2. Commit package.json and package-lock.json, including npm integrity metadata, to make dependency resolution reproducible.
  3. In automated or production environments, use npm ci against the committed lockfile instead of an unconstrained npm install.
  4. Configure npm to use an explicitly trusted registry and verify that project-level or user-level npm configuration cannot redirect dependency retrieval to an untrusted source.
  5. Review dependency changes and browser-binary updates before modifying the pinned version or lockfile.
  6. Run installation and browser automation as a dedicated, non-privileged user in an isolated environment with only the filesystem and network access required for the task.
  7. Where supported by the delivery process, verify downloaded package and browser artifact provenance or checksums.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to run npx playwright without pinning an exact package version, which can cause execution of whatever version is current at install time. This creates a supply-chain risk: a compromised upstream release, typo-resolved package, or breaking change could lead to unexpected code execution or unsafe behavior on the analyst or operator machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file explicitly recommends anti-crawling evasion tactics such as mimicking a real browser, introducing randomized delays, and using non-headless mode to bypass CAPTCHA, but provides no warning about platform terms, account sanctions, or legal/compliance risks. In the context of a browser-automation skill for collecting search suggestions from a third-party platform, this guidance materially enables policy evasion and lowers the barrier to abusive scraping behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.