T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_xhs_hot_articles.py:611- Finding
User-Controlled Path Traversal and Unintended File Overwrite
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its Xiaohongshu content-generation purpose, but it has under-disclosed and unsafe local HTML file creation that can overwrite unintended files and preserve unescaped remote content.
Review before installing. Use a dedicated low-privilege working directory, avoid sensitive keywords or private writing samples unless you accept third-party processing, and do not open generated HTML reports as trusted files. The publisher should constrain output paths, avoid writing HTML unless explicitly requested, escape all HTML fields, and document data handling more clearly.
scripts/fetch_xhs_hot_articles.py:611User-Controlled Path Traversal and Unintended File Overwrite
scripts/fetch_xhs_hot_articles.py:211Stored HTML Injection Through Unescaped API and User-Controlled Values
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
body = json.dumps(payload, ensure_ascii=False).encode("utf-8")
req = urllib.request.Request(url, data=body, headers=headers, method="POST")
with urllib.request.urlopen(req, timeout=30) as resp:
status_code = resp.status
resp_bytes = resp.read()
resp_text = resp_bytes.decode("utf-8")
The documented behavior does not match the detected capabilities and implied implementation: external API calls and possible file writes are not transparently declared, while promised AI analysis and text generation are described as if built into the skill. This mismatch can mislead operators about what the skill actually does, weakening review and consent controls and potentially enabling undisclosed data egress or artifact creation.
The skill explicitly invites activation through natural-language descriptions like 'Simply describe your needs,' which creates a very broad trigger surface. In an agent environment, generic everyday phrasing can cause unintended invocation, making the skill run when a user did not clearly intend to access external search/analysis/generation behavior.
The example prompts are common user requests such as 'Help me write...' and 'Find me trending...' that overlap heavily with normal conversation. In a multi-skill agent, these broad examples can bias routing and cause accidental skill activation, potentially sending user content to external services or shaping outputs without informed user intent.
The README is entirely in Chinese and all example interactions are phrased exclusively for Chinese-language Xiaohongshu content creation, without stating whether other languages are supported or giving users a language choice. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy issue unless the locale restriction is explicitly justified.
The README states that the skill uses an external API and retrieves external content, but it does not warn users that their prompts, keywords, and topic interests may be transmitted to third-party services. This creates a data exposure risk, especially for sensitive research topics, commercial plans, or personal interests that users may assume remain local to the agent.
The skill advertises '个人风格融合' by allowing users to upload past notes for style analysis, but the README provides no warning about privacy, personal data, or copyrighted/sensitive material that may be included in those notes. Users may unknowingly provide private drafts, account details, or third-party content, which could then be processed or retained without informed consent.
The README instructs users to invoke the skill with broad natural-language phrases such as general content requests, without clear boundaries that distinguish when the skill should or should not activate. In an agent setting, this can cause unintended invocation from ordinary conversation, leading to unnecessary external queries and generation actions based on user text that was not meant as a tool call.
The skill requests capabilities tied to environment secrets, network access, and implied file operations, but it does not declare any explicit tool scope or permission boundaries. This increases the chance of over-privileged execution and makes it harder for a host agent to constrain API-key exposure and external requests safely.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
---
name: xiaohongshu-write
description: 专为小红书内容创作打造的一站式笔记生成工具,基于全网每日持续收录的2000+条爆款笔记数据,根据用户输入关键词,精准检索查询平台当下热门爆款笔记,通过AI深度复盘爆款内容的结构、开头逻辑、干货密度与互动话术,提炼核心流量密码与创作要点,严格贴合小红书内容生态与传播逻辑,生成通顺、合规、可直接发布的完整笔记文案,降低创作门槛,高效产出流量内容。仅在主Agent中执行,不派发给子Agent。
---
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
---
name: xiaohongshu-write
description: 专为小红书内容创作打造的一站式笔记生成工具,基于全网每日持续收录的2000+条爆款笔记数据,根据用户输入关键词,精准检索查询平台当下热门爆款笔记,通过AI深度复盘爆款内容的结构、开头逻辑、干货密度与互动话术,提炼核心流量密码与创作要点,严格贴合小红书内容生态与传播逻辑,生成通顺、合规、可直接发布的完整笔记文案,降低创作门槛,高效产出流量内容。仅在主Agent中执行,不派发给子Agent。
---
The trigger condition is broad enough to activate on generic copywriting requests, which can cause the skill to run in contexts beyond its intended Xiaohongshu-specific use case. Over-broad triggering can lead to unnecessary external searches/API use and accidental handling of user content when a narrower, safer tool would suffice.
The skill actively encourages users to upload personal writing samples for style imitation but provides no privacy notice, retention limits, or warning that the data may be processed alongside external tools. Personal writing samples can contain sensitive personal details, and collecting them without clear handling rules creates privacy and compliance risk.
The script transmits user-provided keywords and date filters to a third-party API without any consent, minimization, or user-facing notice at the call site. In a content-writing skill, users may enter sensitive business plans, campaign terms, or personal data, which would then be disclosed externally to the API provider.
This module depends on a REDFOX_API_KEY from the environment to access an external service. While external trend retrieval may support the stated purpose, the manifest does not explicitly mention credentialed third-party API usage, making this capability not fully justified from the declared scope alone.
The manifest describes an end-to-end note generation tool that analyzes viral content structure and produces compliant, directly publishable copy. In contrast, this file's actual behavior is limited to querying a Redfox API for Xiaohongshu hot-note data and returning formatted JSON/HTML results, without performing any note generation or deep content synthesis itself.
The output document explicitly forces the Chinese locale and all visible interface/report text is fixed in Chinese. There is no opt-in, locale selection, or documented justification that this skill is intended only for Chinese-language users or a region-specific workflow.
The manifest presents the skill as a note-generation tool for creators, but this script also persists an HTML analysis report locally. Local file output is a behavioral aspect beyond the manifest's user-facing description and is not necessary to infer from the stated purpose alone.
No suspicious patterns detected.