Back to skill

Security audit

小红书图文生成器

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Xiaohongshu content generator, but it needs review because unsafe input handling can write files outside the chosen output folder and inject active HTML into browser-rendered output.

Review before installing. Use only trusted topic values, choose an isolated output directory, and avoid running it in a workspace with sensitive writable files until path containment, filename slugging, HTML escaping, dependency pinning, and browser rendering restrictions are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
index.js:53
Finding

Path Traversal Allows Files to Be Written Outside the Intended Output Directory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
index.js:275
Finding

Unescaped Topic Input Enables HTML and Script Injection in Rendered Content

Content
View full analysis
${copywriting.title} - 小红书图文 ``` It is also inserted directly into the document body: ```javascript
${topic}
破防了!
``` The generated file is subsequently passed to the image conversion dependency: ```javascript const { convertPagesToImages } = await import('../html-pages-to-images/lib/convert-pages.js'); const result = await convertPagesToImages({ htmlFile, outputDir, pageWidth: DEFAULT_CONFIG.pageWidth, pageHeight: DEFAULT_CONFIG.pageHeight, selector: DEFAULT_CONFIG.selector }); ``` ### Technical Analysis The application interpolates externally controlled `topic` content into an HTML template without context-aware HTML escaping. An attacker can terminate the existing element or title context and introduce arbitrary HTML, scripts, iframes, images, styles, or other active browser content. For example, a payload containing a closing tag followed by a new element can escape the intended text context. Since the generated HTML is rendered by a browser-based image converter, injected active content may execute during image generation. The audited project imports the main converter from a sibling dependency that was not included in the project folder. Therefore, protections in that dependency—such as JavaScript disabling, request interception, local-file restrictions, and browser sandbox settings—could not be verified. ### Attack Path 1. An attacker supplies a malicious `topic` through the CLI or exported API, such as a value containing: ```html ``` 2. The value becomes part of `copywriting.title` and is interpolated into t ...[truncated 993 chars]
Remediation
View remediation
', '>') .replaceAll('"', '"') .replaceAll("'", '''); } const safeTopic = escapeHTML(topic); const safeTitle = escapeHTML(copywriting.title); ``` 2. Use escaped values in both text and title contexts: ```javascript `${safeTitle} - Xiaohongshu Article` `
${safeTopic}
...
` ``` 3. Validate topic length and reject control characters or unexpected markup. 4. Disable JavaScript in the image-rendering page unless it is strictly necessary. 5. Intercept browser requests and deny external HTTP, HTTPS, WebSocket, and other unnecessary schemes. 6. Permit only explicitly required local resources and prevent arbitrary `file:` navigation. 7. Render in an isolated, low-privilege environment with no credentials, cookies, tokens, or sensitive mounted directories. 8. Add regression tests using payloads that attempt to escape title, element-text, and attribute contexts. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
temp-convert.js:31
Finding

Standalone Puppeteer Converter Disables Chromium Sandbox Protections

Content
View full analysis
Remediation
View remediation
{ if (request.url() === 'about:blank') { request.continue(); } else { request.abort(); } }); ``` 6. Keep Puppeteer and its bundled Chromium release patched. 7. Remove `temp-convert.js` from production packages if it is only a local debugging utility. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 388)May include surrounding context.

md
import { generateXiaohongshuArticle } from './index.js';

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file title and all usage examples are written as a Chinese-only Xiaohongshu content generation workflow, with no indication that users can choose another language or locale. This is a natural-language policy concern because the examples implicitly constrain output language and platform style without documenting opt-in or a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. The README consistently assumes Chinese with no mention of alternative language support or that the skill is intended only for Chinese-speaking users, which can amount to forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to collect hot-topic data from third-party platforms like 脉脉、微博、知乎 without clearly disclosing that external browsing or content sourcing will occur. In a skill with browser, shell, and filesystem access, this can lead to unexpected outbound access, opaque data provenance, and potential ingestion of untrusted or copyrighted content into generated outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file description and generated output are explicitly hardcoded for 小红书-style Chinese content, and the HTML also fixes the locale to zh-CN. There is no user opt-in, language selection, or documented region-specific justification, which violates the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description states the skill generates '小红书风格' content and is written entirely as a Chinese-language capability, with no indication that users can choose another language or locale. This can violate language/locale policy when a skill implicitly constrains output language without explicit opt-in or documented regional limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language metadata is entirely Chinese and positions the skill around a Chinese-platform workflow, but it does not explicitly state that the skill is Chinese-only or offer any user language/locale choice. Under the policy, forcing a specific language or locale without opt-in can be a violation unless clearly justified and documented.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The trigger "图文生成" is generic and not clearly limited to Xiaohongshu-specific usage. In a manifest file, such a broad activation phrase can match ordinary user requests and cause unintended invocation of this specific skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest grants shell access to a content-generation skill even though the declared functionality only describes generating Xiaohongshu-style copy, HTML, and images. Unnecessary shell capability expands the attack surface significantly: if downstream code uses user-controlled inputs with shell commands, it could enable command execution or filesystem abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file includes natural-language comments and runtime console output in Chinese, such as the configuration and status messages. The policy requires flagging language or locale constraints when the skill forces a specific language without offering user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The example command writes HTML, markdown, and image files to a local output directory, but the surrounding documentation does not explicitly warn users that running the skill will create files on disk. For markdown guidance, data-affecting behavior should be disclosed clearly so users understand the side effects before running the command.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This is a markdown file, so SQP-2 applies to missing user-facing warnings about behaviors affecting user data or system state. The README documents output paths and generated files, but it does not explicitly warn that execution will create directories and overwrite or populate files under the chosen output path.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The trigger field lists short phrases like “小红书生成” and “图文生成”, which can overlap with generic content-generation requests and do not specify boundaries for when this skill should or should not activate. The file also does not provide negative examples or narrower context limits to reduce unintended invocation.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
85% confidence
Finding

Using a caret version for puppeteer allows installation of newer minor/patch releases without explicit review, which can introduce unexpected vulnerable or breaking dependency changes into the skill. In an automation package that renders/generated HTML and may launch a browser, dependency drift increases supply-chain risk even if the manifest itself does not prove exploitability.

Content

Scanner excerpt · package.json (reported line 21)May include surrounding context.

json
"author": "OpenClaw",
  "license": "MIT",
  "dependencies": {
    "puppeteer": "^21.0.0"
  },
  "peerDependencies": {
    "html-pages-to-images": "file:../html-pages-to-images"

Unverifiable Dependency: puppeteer has 1 known advisory(ies) (CVE-2019-5786 (Use-After-Free in puppeteer)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.