Back to skill

Security audit

Auto Redbook Content

Security checks for vulnerabilities and agentic risk

Overview

This is a small Xiaohongshu content workflow that writes local JSON and generates rewrite prompts; I found no malicious behavior, though its real-scraping claims and result limit need clearer handling.

Install only if you want a Chinese/Xiaohongshu-oriented workflow that writes generated JSON files under output. Treat current results as mock/sample data unless the OpenClaw environment supplies a reviewed Xiaohongshu MCP integration, and keep XHS_MAX_RESULTS small until range validation is added.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run.js:17
Finding

Unbounded Result Count Enables Resource Exhaustion

Content
View full analysis

Vulnerability Details

File Location: scripts/run.js:17, with the affected allocation loop in scripts/fetch.js:15-28 and equivalent CLI input handling at scripts/fetch.js:47
Vulnerability Type: Improper Input Validation / Resource Exhaustion
Risk Level: Medium

Vulnerable Code

scripts/run.js:17:

js
const maxResults = parseInt(process.env.XHS_MAX_RESULTS || '3');

scripts/fetch.js:15-28:

js
function generateMockNotes(count) {
  console.log('[抓取] MCP 不可用,使用模拟数据');
  const notes = [];
  for (let i = 0; i < count; i++) {
    notes.push({
      original_title: `小红书热点标题 ${i + 1}`,
      original_content: `这是第 ${i + 1} 条热点笔记的内容,包含了当前流行的话题和趋势...`,
      author: `热门博主${i + 1}`,
      likes: Math.floor(Math.random() * 50000) + 10000,
      images: [],
      url: `https://www.xiaohongshu.com/explore/mock${i + 1}`,
      timestamp: new Date().toISOString()
    });
  }
  return notes;
}

scripts/fetch.js:47:

js
const count = parseInt(process.argv[2]) || 3;

Technical Analysis

The package metadata describes XHS_MAX_RESULTS as accepting values from 1 through 100, but the implementation does not enforce this range. Both the environment-variable path and direct CLI path accept arbitrarily large positive integers.

The supplied value controls a synchronous loop that creates an array of note objects. When invoked through scripts/run.js, every generated note is then copied into another result object, augmented with a rewriting prompt, serialized as JSON, and synchronously written to disk.

Because there is no upper bound, a sufficiently large value can cause excessive memory allocation, CPU usage, event-loop blocking, and disk consumption. parseInt() also accepts partially numeric strings rather than validating that the entire input is a canonical integer.

Attack Path

  1. The attacker or an untrusted execution environment obtains control over XHS_MAX_RESULTS or the argument passed to scripts/fetch.js.
  2. A ...[truncated 1178 chars]
Remediation
View remediation

Remediation Suggestions

Validate the value before passing it to fetchNotes() and reject anything outside the documented range:

js
function parseResultCount(rawValue) {
  const value = Number(rawValue);

  if (!Number.isSafeInteger(value) || value < 1 || value > 100) {
    throw new RangeError('XHS_MAX_RESULTS must be an integer from 1 to 100');
  }

  return value;
}

const maxResults = parseResultCount(process.env.XHS_MAX_RESULTS ?? '3');

Apply the same validation to the direct CLI entry point:

js
const count = parseResultCount(process.argv[2] ?? '3');

Additional hardening measures should include:

  1. Centralize validation so the environment-variable and CLI execution paths cannot diverge.
  2. Validate again inside fetchNotes() or generateMockNotes() so exported functions remain safe when called programmatically.
  3. Prefer rejection over silent clamping so configuration mistakes are visible.
  4. Avoid synchronous serialization and file writes for potentially large collections.
  5. Consider streamed output if the supported result limit is increased later.
  6. Configure process-level memory, CPU, execution-time, and output-size limits in the Agent runtime.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 27)May include surrounding context.

md
- 口语化、真实细节、避免 AI 连接词

### 🔒 Security
- 移除 .env 文件读取
- 移除 dotenv 依赖
- 仅读取必要环境变量(XHS_MAX_RESULTS)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- 口语化、真实细节、避免 AI 连接词

### 🔒 Security
- 移除 .env 文件读取
- 移除 dotenv 依赖
- 仅读取必要环境变量(XHS_MAX_RESULTS)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
- 口语化、真实细节、避免 AI 连接词

### 🔒 Security
- 移除 .env 文件读取
- 移除 dotenv 依赖
- 仅读取必要环境变量(XHS_MAX_RESULTS)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
- 口语化、真实细节、避免 AI 连接词

### 🔒 Security
- 移除 .env 文件读取
- 移除 dotenv 依赖
- 仅读取必要环境变量(XHS_MAX_RESULTS)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This second mismatch finding similarly indicates the skill claims a full scrape→rewrite→store workflow but only implements prompt-generation/rewrite preparation and omits claimed scraping and storage. Such discrepancies undermine the integrity of permission review and can conceal future capability additions under an already-approved description, which is a meaningful agent-security risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This second mismatch finding similarly indicates the skill claims a full scrape→rewrite→store workflow but only implements prompt-generation/rewrite preparation and omits claimed scraping and storage. Such discrepancies undermine the integrity of permission review and can conceal future capability additions under an already-approved description, which is a meaningful agent-security risk.

Content

No source excerpt is available for this finding.

Scope Creep

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest declares only file-write permission, but the skill description and static analysis indicate it performs outbound requests to Xiaohongshu/Baidu. This creates a capability mismatch that hides network behavior from users and policy enforcement, undermining informed consent and making data exfiltration or unreviewed third-party communication harder to detect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language documentation and example invocation are entirely in Chinese, with no indication that other languages are supported or that the Chinese-only scope is intentional and documented. This can constitute a language/locale policy violation when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares environment-variable usage but does not define an explicit tool/permission scope. In an agent setting, undeclared capability needs weaken reviewability and can lead to broader-than-expected access or accidental exposure of runtime secrets through environment access. The skill text also normalizes env use without a formal permission boundary, which is risky even if no secret-reading behavior is explicitly shown here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description and main documentation are written entirely in Chinese and the trigger example is also Chinese-only, which indicates a fixed language/locale expectation. The file does not provide any opt-in, alternative language option, or justification that the skill is intentionally limited to a Chinese-language/regional compliance context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON file contains user-facing natural-language content exclusively in Chinese across multiple title and content fields. Under the policy rule for language/locale, forcing a specific language without offering user choice or documenting a justified regional constraint is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description forces a specific language/locale in user-facing metadata, and the trigger phrases and environment descriptions are likewise only in Chinese. The policy allows locale constraints only when user choice or a clearly justified region-specific limitation is documented, which is not present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The top-level comment states '通过 xiaohongshu MCP 获取真实数据', which asserts real-data retrieval. In practice, the exported fetchNotes function never invokes MCP and always returns generated mock entries, directly contradicting the documented intent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a tool that grabs Xiaohongshu homepage hot topics, but fetchNotes explicitly returns simulated data via generateMockNotes rather than fetching real homepage content. This is a semantic mismatch because the implemented behavior is sample-data generation, not actual hotspot collection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt text is entirely in Chinese and instructs the model to rewrite content specifically as a 小红书 note, which effectively imposes a specific language and locale style. The file does not offer user opt-in, language selection, or any documented justification for restricting output to Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file's natural-language documentation and console output are written only in Chinese, indicating a fixed language choice rather than offering a locale option. Under the policy, language constraints should either be user-selectable or clearly justified as region-specific, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The README states that the skill grabs trending Xiaohongshu homepage content and performs local JSON storage, but it does not warn users that fetched content will be saved on disk. For markdown files, data-affecting behavior should be disclosed when it may impact user data or system state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON file contains user-facing titles, content, author labels, and tags exclusively in Chinese across all entries. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative language or locale choice is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The title and content are presented only in Chinese, with no indication that users can select another language or opt in to this locale. Under the policy for natural-language violations, forcing a specific language without user choice can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.