Back to skill

Security audit

小红书爆款笔记查询

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Xiaohongshu trend-search skill that uses a Redfox API key, writes local HTML reports, and offers opt-in calendar subscriptions; no malicious behavior is evident.

Install only if you are comfortable giving this skill a Redfox API key and sending your Xiaohongshu search terms and date filters to redfox.hk. Expect local HTML report files to be created in the working directory, and use the subscription option only when you intentionally want recurring calendar reminders.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill is presented as a search/recommendation tool, but the documentation also instructs creation of calendar subscriptions and timed pushes. This is a scope expansion beyond the advertised function, which can surprise users and trigger persistent actions without clear up-front disclosure in the skill description.

Description-Behavior Mismatch

Low
Confidence
89% confidence
Finding
The documented functionality includes automatic generation of a local HTML report, but this file-writing behavior is not disclosed in the description. Undisclosed local output can create privacy, storage, and artifact-management risks, especially in agent environments where users may not expect files to be written.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The README explicitly says users can invoke the skill with unrestricted natural language, which makes activation boundaries ambiguous and increases the chance the tool is triggered by incidental conversational text rather than clear user intent. Because this skill performs external data retrieval and supports subscription creation, overly broad triggering can cause unintended tool use, unnecessary external requests, or accidental state-changing actions.

Vague Triggers

Low
Confidence
84% confidence
Finding
The example phrase for site-wide search is very generic and close to normal conversational wording, so an agent may misinterpret casual discussion as a command to run the skill. In a multi-tool or autonomous-agent setting, this raises the risk of accidental broad searches and unnecessary external API calls, though the direct security impact is limited because the action is primarily read-only.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
Automatic local HTML report generation is a side effect with persistence, but the documentation does not provide a prominent user-facing warning at the point of use. Silent file creation can leave sensitive search terms or retrieved data on disk, creating privacy and operational risk in shared or managed environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.