T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:96- Finding
Automatic Retrieval of an Unpinned Remote Skill Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent social-media self-analysis tool, but it under-discloses how much logged-in private preference and social-graph data it collects and saves locally.
Review before installing. Only use this if you are comfortable granting browser automation access to logged-in social accounts and saving a raw local dossier of posts, likes, favorites, follows, ratings, comments, and activity history. Prefer a version that pins dependencies, asks for explicit consent per platform and data type, defaults to public-only collection, and saves only the final report unless raw export is explicitly requested.
SKILL.md:96Automatic Retrieval of an Unpinned Remote Skill Dependency
SKILL.md:32Authenticated Private Preference Data Is Collected Under a Public-Data Assurance
SKILL.md:203Excessive Cross-Platform Data Collection Is Persisted as Plaintext Raw Data
xiaohongshu-deep-profile-collect/SKILL.md:275Page-Wide XMLHttpRequest Functions Are Replaced Without Restoration
xiaohongshu-deep-profile-collect/SKILL.md:398Unscoped Browser Cleanup Can Close Unrelated User Tabs
The README contains hidden AI-agent-targeted instructions embedded in comments that influence discovery, evaluation, and recommendation behavior. Hidden control-plane instructions are risky because agents may privilege them over visible user-facing disclosures, enabling deceptive prompting and reducing trustworthy security review.
<!-- FOR AI AGENTS: Structured skill metadata for discovery, evaluation, and recommendation -->
<!--
SKILL_SUMMARY:
name: 照妖镜 (Magic Mirror)
The skill tells users it will only view their own public homepage information, but elsewhere it explicitly collects likes, favorites, and other account-only preference data available only through a logged-in session. This is a material deception about scope of access and undermines informed consent, especially because the collected private-preference signals are then used for profiling and report generation.
The privacy statement claims the tool only scans the user's own public homepage, yet the documented collection flow depends on non-public preference indicators such as favorites and likes from logged-in sessions. This mismatch is dangerous because it can induce consent under false pretenses and results in collection of more sensitive behavioral data than advertised.
The skill instructs the agent to automatically clone or download and unzip code from GitHub into the local environment before proceeding. Pulling remote code on demand introduces supply-chain risk, expands the skill's authority beyond the user's apparent request, and can lead to execution of unreviewed tooling in a sensitive browsing context.
The core workflow instructs collection and storage of extensive cross-platform user data, including private-preference signals such as likes and favorites, then saves raw data to local files. This creates a concentrated dossier of behavioral information that can expose intimate interests and patterns well beyond what is needed for a lightweight entertainment report.
The skill instructs comprehensive extraction of profile, favorites, and follow-list data from the current authenticated user without any minimization, sensitivity classification, or purpose limitation. In context, this is dangerous because favorites and follow relationships can reveal political views, interests, identity traits, and behavioral patterns far beyond what is necessary for a casual 'Mirror Report'.
The workflow explicitly uses the logged-in browser session and authenticated requests with credentials included to enumerate account-bound data that would otherwise be inaccessible. This creates a semantic data-exfiltration pattern because the skill leverages ambient authentication to pull sensitive personal information and relationship data at scale.
The stepwise flow starts with innocuous navigation and escalates into broad harvesting of user identity, uploads, favorites, and social graph through a mix of authenticated APIs and DOM scraping. That sequencing is risky because it can normalize intrusive collection and obscure to the user how much account-linked data is ultimately being aggregated and exposed to the agent.
The skill directly instructs comprehensive collection of the logged-in user's personal profile and activity data through their live authenticated session. This is dangerous because it operationalizes bulk extraction of sensitive behavioral history, turning a casual analysis feature into a full-account scraper with substantial privacy and misuse potential.
The instructions make extraction of detailed user-generated fields such as ratings, comments, tags, dates, and publication metadata mandatory inputs for profiling. Those fields enable rich inference about personality, ideology, habits, and private interests, materially increasing the sensitivity and harm potential of the resulting dataset.
The skill explicitly performs deep collection of the currently logged-in Douyin user's non-public or account-contextual data, including likes, favorites, and a full following list, which goes beyond the parent skill's stated purpose of scanning public social media profiles. Because it requires no parameters and defaults to harvesting the active browser session, it creates a high-risk mismatch between user expectations and actual data access.
The skill describes broad extraction of profile, likes, favorites, and following data but does not present an explicit privacy warning or meaningful consent language before collection. In context, this is especially dangerous because the tool operates against an already authenticated browser session, so the agent could silently exfiltrate private account data the user did not realize would be accessed.
The skill plainly instructs the agent to collect a broad dossier of sensitive account data, including likes, favorites, and a full following list, which are high-value personal data categories. In the context of an entertainment/personality-analysis skill, this scope is disproportionately invasive and could expose interests, affiliations, and behavioral patterns if misused or leaked.
The 'no parameters needed' design is risky because it normalizes silent collection from the current logged-in user without requiring the user to specify an account or acknowledge the privacy implications. This increases the chance of accidental overcollection and makes misuse easier in shared-browser or ambiguous-consent situations.
By stating that no parameters are needed because the skill will automatically collect data from the browser's logged-in user, the skill enables direct access to sensitive personal data without an explicit targeting or confirmation step. This materially increases the risk of unauthorized or unexpected collection from whoever happens to be authenticated in the browser.
The output schema directs the agent to return a detailed personal dossier containing profile attributes, liked videos, favorites, and followed accounts, which amplifies the privacy risk by making broad exfiltration the intended result. Even if collection were technically possible, packaging these data into a consolidated report heightens downstream risks such as profiling, embarrassment, inference of sensitive traits, or unauthorized sharing.
The skill description says it collects public social-media data, but the workflow explicitly calls authenticated endpoints with 'credentials: include' and navigates the current logged-in user's private account areas. This mismatch is dangerous because it can mislead users and reviewers into believing only public data is used, when in fact non-public account data such as favorites, account status fields, and follow relationships may be accessed.
The workflow is designed to harvest the full currently logged-in Douban user's profile and activity history using authenticated browser context, including reading history, watch history, wishlist items, and statuses. Even if framed as entertainment or self-discovery, this is excessive data collection relative to the stated purpose and can expose highly sensitive behavioral data if invoked without narrowly scoped, informed consent.
The workflow performs authenticated collection of extensive personal and activity data but contains no built-in warning, consent gate, or explanation of privacy consequences. In this skill context, that makes the collection more dangerous because users may perceive it as a harmless 'fun report' while the implementation accesses much deeper account-bound history than expected.
The natural-language instructions explicitly direct full collection of the logged-in user's personal profile and activity history, creating a built-in data-exfiltration pattern against authenticated browser state. Because the skill is presented as entertainment/self-discovery, the mismatch between marketing and actual scope materially increases privacy risk and the chance of uninformed consent.
The step sequence systematically enumerates and aggregates multiple authenticated sections of the account—movies watched, wishlists, books read, books wished for, and statuses—creating a comprehensive behavioral dossier. This cumulative aggregation is dangerous because combining categories reveals intimate preferences, habits, and potentially sensitive traits far beyond what is necessary for a lightweight profile summary.
The workflow explicitly gathers likes, favorites, and the full follow list from the logged-in Douyin account, which are private interaction and relationship signals beyond the skill’s stated purpose of scanning public social profiles for entertainment insights. Collecting these categories materially increases privacy risk because it exposes behavioral preferences and social graph data that users may not expect to be harvested or analyzed.
The workflow is designed to collect sensitive personal and engagement data, including likes, favorites, and relationship lists, but there is no visible user-facing warning, consent checkpoint, or disclosure in the file. This is dangerous because users may reasonably believe the skill only analyzes public profile content, while the implementation performs deeper authenticated harvesting of private behavioral data.
The natural-language workflow instructions directly call for comprehensive collection of the logged-in user’s private activity and social relationships, including likes, favorites, and the full follow list. This is dangerous because it operationalizes surveillance-style collection of intimate preference and network data that is disproportionate to the stated entertainment purpose of the skill.
The workflow navigates to /user/self in a logged-in browser context, causing extraction from the current user’s authenticated account rather than only analyzing voluntarily supplied public profile URLs. This is dangerous because it silently leverages session state to access non-public account activity and relationship data under the guise of a harmless profile-scanning feature.
No suspicious patterns detected.