T09 · Insecure Skill Coding Practices
- Location
scripts/run.js:17- Finding
Unbounded Result Count Enables Resource Exhaustion
- Content
View full analysis
Vulnerability Details
File Location:
scripts/run.js:17, with the affected allocation loop inscripts/fetch.js:15-28and equivalent CLI input handling atscripts/fetch.js:47
Vulnerability Type: Improper Input Validation / Resource Exhaustion
Risk Level: MediumVulnerable Code
scripts/run.js:17:js const maxResults = parseInt(process.env.XHS_MAX_RESULTS || '3');scripts/fetch.js:15-28:js function generateMockNotes(count) { console.log('[抓取] MCP 不可用,使用模拟数据'); const notes = []; for (let i = 0; i < count; i++) { notes.push({ original_title: `小红书热点标题 ${i + 1}`, original_content: `这是第 ${i + 1} 条热点笔记的内容,包含了当前流行的话题和趋势...`, author: `热门博主${i + 1}`, likes: Math.floor(Math.random() * 50000) + 10000, images: [], url: `https://www.xiaohongshu.com/explore/mock${i + 1}`, timestamp: new Date().toISOString() }); } return notes; }scripts/fetch.js:47:js const count = parseInt(process.argv[2]) || 3;Technical Analysis
The package metadata describes
XHS_MAX_RESULTSas accepting values from 1 through 100, but the implementation does not enforce this range. Both the environment-variable path and direct CLI path accept arbitrarily large positive integers.The supplied value controls a synchronous loop that creates an array of note objects. When invoked through
scripts/run.js, every generated note is then copied into another result object, augmented with a rewriting prompt, serialized as JSON, and synchronously written to disk.Because there is no upper bound, a sufficiently large value can cause excessive memory allocation, CPU usage, event-loop blocking, and disk consumption.
parseInt()also accepts partially numeric strings rather than validating that the entire input is a canonical integer.Attack Path
- The attacker or an untrusted execution environment obtains control over
XHS_MAX_RESULTSor the argument passed toscripts/fetch.js. - A ...[truncated 1178 chars]
- The attacker or an untrusted execution environment obtains control over
- Remediation
View remediation
Remediation Suggestions
Validate the value before passing it to
fetchNotes()and reject anything outside the documented range:js function parseResultCount(rawValue) { const value = Number(rawValue); if (!Number.isSafeInteger(value) || value < 1 || value > 100) { throw new RangeError('XHS_MAX_RESULTS must be an integer from 1 to 100'); } return value; } const maxResults = parseResultCount(process.env.XHS_MAX_RESULTS ?? '3');Apply the same validation to the direct CLI entry point:
js const count = parseResultCount(process.argv[2] ?? '3');Additional hardening measures should include:
- Centralize validation so the environment-variable and CLI execution paths cannot diverge.
- Validate again inside
fetchNotes()orgenerateMockNotes()so exported functions remain safe when called programmatically. - Prefer rejection over silent clamping so configuration mistakes are visible.
- Avoid synchronous serialization and file writes for potentially large collections.
- Consider streamed output if the supported result limit is increased later.
- Configure process-level memory, CPU, execution-time, and output-size limits in the Agent runtime.
