Back to skill

Security audit

HotBee 小红书数据采集

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it asks the agent to run unaudited code from a personal GitHub repository while using a local API key.

Install only if you trust the GitHub repository and HotBee endpoint handling your API key and note URLs. Prefer a version pinned to an immutable commit or registry package with integrity metadata, and use a narrowly scoped, revocable `HOTBEE_API_KEY` with quota limits.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:13
Finding

Automatic Execution of Remotely Retrieved GitHub Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:13
Vulnerability Type: Remote payload retrieval and execution through an unverified dependency
Risk Level: High

Vulnerable Code Snippet:

bash
npx -y github:shanye1402-hash/hotbee-social-data-skills#v1.1.0 call rednote --url "https://www.xiaohongshu.com/explore/xxxx"

Technical Analysis

The skill directs the agent to use npx -y to download and execute a package from a personal GitHub repository. The -y option suppresses the interactive installation confirmation, so invoking the skill can immediately execute remotely obtained package code.

Although the dependency references the v1.1.0 Git tag, a tag is not equivalent to an integrity-verified artifact or an immutable commit hash. The reviewed project does not contain the dependency's implementation, a lockfile, a cryptographic integrity value, or vendored source through which its behavior could be verified. The effective code executed by the skill therefore exists outside the audited project.

This is principally a remote payload retrieval and execution issue because skill invocation creates a direct channel from an external repository to local code execution. It also carries supply-chain risk: compromise of the repository, its maintainer account, the referenced tag, the dependency tree, or package lifecycle scripts could change the behavior executed by the command.

Attack Path

  1. An attacker compromises the external GitHub repository, a maintainer account, the referenced tag, or a transitive dependency used by the remote package.
  2. The attacker introduces malicious package code, a lifecycle script, or malicious CLI behavior.
  3. A user requests collection of a Rednote URL, causing the agent to follow the instruction in SKILL.md.
  4. npx -y retrieves the external package without an installation confirmation.
  5. npm lifecycle logic or the package CLI executes with the permissions and env ...[truncated 774 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not execute remotely fetched code directly with npx -y.
  2. Vendor the required CLI source into the reviewed project and audit all executable code and transitive dependencies.
  3. If external retrieval is unavoidable, pin the dependency to an immutable commit and verify a cryptographic digest before execution.
  4. Publish the package through a controlled registry with provenance attestations, signed releases, a lockfile, and integrity metadata.
  5. Disable or strictly control npm lifecycle scripts during installation.
  6. Run the CLI in a restricted sandbox with minimal filesystem access, an allowlisted network destination, no unnecessary environment variables, and a short-lived, least-privilege API credential.
  7. Require an explicit user confirmation before installation or execution and display the exact pinned source that will run.

T09 · Insecure Skill Coding Practices

Warning
Location
references/api.md:3
Finding

API Credential Transmitted in a URL Query Parameter

Content
View full analysis

Vulnerability Details

File Location: references/api.md:3-7
Vulnerability Type: Sensitive credential exposure through URL query parameters
Risk Level: Medium

Vulnerable Code Snippet:

markdown
Verified from HotBee public bundle:

- Endpoint: `POST https://www.smsz.xyz/prod-api/tool/rednote/xhs_note_content`
- Parameters: `key`, `note_url`
- Transport in the package CLI: query parameters with POST.

Related credential-handling instructions in SKILL.md:10-16 include:

markdown
Read `HOTBEE_API_KEY` from the local environment only, never echo it, and redact signed query parameters from errors.

Use the package CLI:

```bash
npx -y github:shanye1402-hash/hotbee-social-data-skills#v1.1.0 call rednote --url "https://www.xiaohongshu.com/explore/xxxx"

Use HOTBEE_API_KEY only.

text

### Technical Analysis

The documented transport places the `key` and `note_url` parameters in the request URL even though the HTTP method is POST. Using POST does not protect query parameters: the complete URL can still be recorded by the destination server, reverse proxies, gateways, observability platforms, error trackers, debugging tools, or other URL-level telemetry.

The instruction to redact signed query parameters from errors reduces one disclosure route but does not address logging or retention elsewhere in the request path. Furthermore, the endpoint uses the `smsz.xyz` domain while the skill is branded HotBee and links to `hotbee.cn`. The reviewed files do not establish the relationship between these domains or document the external processor's credential-handling and retention guarantees.

The user-provided note URL is also sent to this service. While the skill limits collection to public URLs, users should still be informed that the URL and associated request metadata are disclosed to an external processor.

### Attack Path

1. A user supplies a public Xiaohongshu note URL and approves a live 
...[truncated 1051 chars]
Remediation
View remediation

Remediation Suggestions

  1. Transmit the API credential in an Authorization header or another documented security header rather than in the query string.
  2. If headers are not supported, use a protected POST body and configure infrastructure not to log sensitive request bodies.
  3. Use an explicitly documented and verified service domain. Document the relationship between HotBee and smsz.xyz before sending credentials.
  4. Redact credentials from application logs, proxy logs, traces, exceptions, command output, and monitoring telemetry.
  5. Use short-lived, narrowly scoped API credentials with quota limits, rotation support, and immediate revocation capability.
  6. Inform users before a live request that the note URL will be sent to the named external processor and that quota may be consumed.
  7. Add automated tests confirming that credentials never appear in URLs, logs, errors, or dry-run output.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs execution of code directly from a GitHub repository via npx -y github:...#v1.1.0, which is not a cryptographically pinned, immutable package artifact and can introduce supply-chain risk if the referenced repository, tag, or dependency chain is altered. Because the skill also says to read HOTBEE_API_KEY from the local environment, a compromised install/run path could access sensitive credentials or execute arbitrary code on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The example uses npx -y github:...#v1.1.0, which pulls and executes code from a remote GitHub repository rather than from a registry package with a lockfile-backed integrity check. Even though a tag is present, Git tags can be moved or the referenced repository can change, creating a supply-chain risk where users may execute unexpected code during installation or runtime.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.