Back to skill

Security audit

小红书爆款文案创作(红狐数据)

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Xiaohongshu content-generation purpose, but it has under-disclosed and unsafe local HTML file creation that can overwrite unintended files and preserve unescaped remote content.

Review before installing. Use a dedicated low-privilege working directory, avoid sensitive keywords or private writing samples unless you accept third-party processing, and do not open generated HTML reports as trusted files. The publisher should constrain output paths, avoid writing HTML unless explicitly requested, escape all HTML fields, and document data handling more clearly.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fetch_xhs_hot_articles.py:611
Finding

User-Controlled Path Traversal and Unintended File Overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_xhs_hot_articles.py:211
Finding

Stored HTML Injection Through Unescaped API and User-Controlled Values

Content
View full analysis
相关性 {relevance_score} 热度 {popularity_score} 时效 {recency_score} ''' card_html = f'''
{idx + 1}. {title}
{author_name}({fuzzy_count(fans)}粉) · 发布日期:{pub_time}
{sc ...[truncated 2965 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (18)

Tainted flow: 'req' from os.environ.get (line 93, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/fetch_xhs_hot_articles.py (reported line 94)May include surrounding context.

python
body = json.dumps(payload, ensure_ascii=False).encode("utf-8")
            req = urllib.request.Request(url, data=body, headers=headers, method="POST")
            with urllib.request.urlopen(req, timeout=30) as resp:
                status_code = resp.status
                resp_bytes = resp.read()
            resp_text = resp_bytes.decode("utf-8")

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior does not match the detected capabilities and implied implementation: external API calls and possible file writes are not transparently declared, while promised AI analysis and text generation are described as if built into the skill. This mismatch can mislead operators about what the skill actually does, weakening review and consent controls and potentially enabling undisclosed data egress or artifact creation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly invites activation through natural-language descriptions like 'Simply describe your needs,' which creates a very broad trigger surface. In an agent environment, generic everyday phrasing can cause unintended invocation, making the skill run when a user did not clearly intend to access external search/analysis/generation behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example prompts are common user requests such as 'Help me write...' and 'Find me trending...' that overlap heavily with normal conversation. In a multi-skill agent, these broad examples can bias routing and cause accidental skill activation, potentially sending user content to external services or shaping outputs without informed user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README is entirely in Chinese and all example interactions are phrased exclusively for Chinese-language Xiaohongshu content creation, without stating whether other languages are supported or giving users a language choice. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy issue unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states that the skill uses an external API and retrieves external content, but it does not warn users that their prompts, keywords, and topic interests may be transmitted to third-party services. This creates a data exposure risk, especially for sensitive research topics, commercial plans, or personal interests that users may assume remain local to the agent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises '个人风格融合' by allowing users to upload past notes for style analysis, but the README provides no warning about privacy, personal data, or copyrighted/sensitive material that may be included in those notes. Users may unknowingly provide private drafts, account details, or third-party content, which could then be processed or retained without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README instructs users to invoke the skill with broad natural-language phrases such as general content requests, without clear boundaries that distinguish when the skill should or should not activate. In an agent setting, this can cause unintended invocation from ordinary conversation, leading to unnecessary external queries and generation actions based on user text that was not meant as a tool call.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill requests capabilities tied to environment secrets, network access, and implied file operations, but it does not declare any explicit tool scope or permission boundaries. This increases the chance of over-privileged execution and makes it harder for a host agent to constrain API-key exposure and external requests safely.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 2)May include surrounding context.

md
---
name: xiaohongshu-write
description: 专为小红书内容创作打造的一站式笔记生成工具,基于全网每日持续收录的2000+条爆款笔记数据,根据用户输入关键词,精准检索查询平台当下热门爆款笔记,通过AI深度复盘爆款内容的结构、开头逻辑、干货密度与互动话术,提炼核心流量密码与创作要点,严格贴合小红书内容生态与传播逻辑,生成通顺、合规、可直接发布的完整笔记文案,降低创作门槛,高效产出流量内容。仅在主Agent中执行,不派发给子Agent。
---

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 2)May include surrounding context.

md
---
name: xiaohongshu-write
description: 专为小红书内容创作打造的一站式笔记生成工具,基于全网每日持续收录的2000+条爆款笔记数据,根据用户输入关键词,精准检索查询平台当下热门爆款笔记,通过AI深度复盘爆款内容的结构、开头逻辑、干货密度与互动话术,提炼核心流量密码与创作要点,严格贴合小红书内容生态与传播逻辑,生成通顺、合规、可直接发布的完整笔记文案,降低创作门槛,高效产出流量内容。仅在主Agent中执行,不派发给子Agent。
---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger condition is broad enough to activate on generic copywriting requests, which can cause the skill to run in contexts beyond its intended Xiaohongshu-specific use case. Over-broad triggering can lead to unnecessary external searches/API use and accidental handling of user content when a narrower, safer tool would suffice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill actively encourages users to upload personal writing samples for style imitation but provides no privacy notice, retention limits, or warning that the data may be processed alongside external tools. Personal writing samples can contain sensitive personal details, and collecting them without clear handling rules creates privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script transmits user-provided keywords and date filters to a third-party API without any consent, minimization, or user-facing notice at the call site. In a content-writing skill, users may enter sensitive business plans, campaign terms, or personal data, which would then be disclosed externally to the API provider.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This module depends on a REDFOX_API_KEY from the environment to access an external service. While external trend retrieval may support the stated purpose, the manifest does not explicitly mention credentialed third-party API usage, making this capability not fully justified from the declared scope alone.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes an end-to-end note generation tool that analyzes viral content structure and produces compliant, directly publishable copy. In contrast, this file's actual behavior is limited to querying a Redfox API for Xiaohongshu hot-note data and returning formatted JSON/HTML results, without performing any note generation or deep content synthesis itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The output document explicitly forces the Chinese locale and all visible interface/report text is fixed in Chinese. There is no opt-in, locale selection, or documented justification that this skill is intended only for Chinese-language users or a region-specific workflow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest presents the skill as a note-generation tool for creators, but this script also persists an HTML analysis report locally. Local file output is a behavioral aspect beyond the manifest's user-facing description and is not necessary to infer from the stated purpose alone.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.