Back to skill

Security audit

小红书视频下载

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it sends Xiaohongshu links containing xsec_token values to a third-party API and lacks strong privacy and authorization guardrails.

Review this skill before installing. Use it only with Xiaohongshu links you are authorized to process, understand that full token-bearing links are sent to redfox.hk, and avoid saving the API key locally unless you accept that it will persist on disk.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (13)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README tells users to provide Xiaohongshu links containing xsec_token and to use a third-party RedFoxHub API key, but it does not clearly warn that submitted links and embedded tokens will be transmitted to an external service. Because xsec_token values and full content URLs may be sensitive or time-limited access artifacts, failing to disclose this data flow can cause users to unknowingly expose account-linked or private browsing/share data to a third party.

Content

No source excerpt is available for this finding.

Unbounded Output

Medium
Category
Output Handling
Confidence
60% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · README.en.md (reported line 37)May include surrounding context.

md
- **Batch Parsing**: paste multiple links at once — each is parsed sequentially with a success/failure summary at the end.
- **Smart Validation**: automatically detects Xiaohongshu video links and validates the `xsec_token` parameter — non-compliant links prompt a retry with the official example.
- **API Error Fallback**: when the Xiaohongshu API returns a link format error, the official example link is shown automatically to guide the user.
- **Complete Information**: displays resource type, duration, download link, cover link, and full description line by line without truncation.
- **Dual Link Support**: recognizes both www.xiaohongshu.com web links and xhslink.com short links (both must carry `xsec_token`).

---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README says users can 'Just describe what you want in natural language' and gives examples like 'Help me save this Xiaohongshu video' and 'Download this viral video'. These phrases overlap with common everyday speech and do not clearly bound when this skill should activate versus when general assistance is intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill prominently advertises downloading watermark-free Xiaohongshu videos for saving, backup, and secondary creation, but it omits any warning about copyright, authorization, platform terms, or consent. In this context, the absence of guardrails materially increases misuse risk because the skill is specifically designed to facilitate copying and reuse of third-party media.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README says users can '直接用自然语言描述需求' and provides generic phrases such as '下载这条小红书视频', '保存这个小红书视频', and '帮我把这条小红书视频存下来'. These overlap with common everyday requests and the file does not provide negative examples or explicit boundaries for when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill appears to require network access and handling of environment variables/API keys, but it does not declare any explicit tool scope or permissions. That creates an unnecessary trust gap: an agent or runtime may grant broader capabilities than users expect, increasing the chance of unintended network calls, file access, or command execution during skill operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to submit Xiaohongshu URLs containing xsec_token to a third-party service (redfox.hk) to obtain download links, but it does not clearly warn that these user-provided links and tokens will be transmitted off-platform. Tokens embedded in URLs may function as access-bearing or session-like parameters, so sharing them with a third party can expose private access context, user activity, or content metadata.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The line states that all documentation, error prompts, and sample code must uniformly use the provided content, and the surrounding file is written entirely in Chinese with prescribed Chinese error messages. This imposes a specific language on users without documenting a locale-specific requirement or offering a language/locale choice, which matches the language policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation instructs users to supply and optionally persist an API key via CLI, environment variable, or a plaintext file in the home directory, but provides no warning about credential sensitivity, shell history exposure, file permissions, or shared-machine risk. This can lead to accidental disclosure of the key through terminal history, screenshots, logs, backups, or overly permissive local files, enabling unauthorized API use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script can persist the API key to a local file when --save-key is used, but it does not present a clear warning that credentials will be stored on disk. Even with 0600 permissions, local secret storage increases exposure to compromise from backup leakage, shared accounts, malware, or users who do not realize the credential is being retained beyond the current session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The setup instructions tell users to place an external API key in an environment variable but provide no warning about safe credential handling, rotation, or avoiding exposure in logs and shared shells. While using environment variables is common, the omission can lead to accidental leakage through terminal history, screenshots, debugging output, or misconfigured deployment environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstring, CLI descriptions, status messages, and user guidance are written exclusively in Chinese, which imposes a specific language on all users. There is no documented opt-in, locale selection, or justification that this tool is intended only for a Chinese-language environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a narrowly scoped Xiaohongshu video parsing/downloading helper. After processing, the script prints promotional guidance about 'full database' enterprise services, which is outside the stated purpose of downloading or extracting direct video links.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.