Back to skill

Security audit

照妖镜 Magic Mirror

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent social-media self-analysis tool, but it under-discloses how much logged-in private preference and social-graph data it collects and saves locally.

Review before installing. Only use this if you are comfortable granting browser automation access to logged-in social accounts and saving a raw local dossier of posts, likes, favorites, follows, ratings, comments, and activity history. Prefer a version that pins dependencies, asks for explicit consent per platform and data type, defaults to public-only collection, and saves only the final report unless raw export is explicitly requested.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:96
Finding

Automatic Retrieval of an Unpinned Remote Skill Dependency

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:32
Finding

Authenticated Private Preference Data Is Collected Under a Public-Data Assurance

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:203
Finding

Excessive Cross-Platform Data Collection Is Persisted as Plaintext Raw Data

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Warning
Location
xiaohongshu-deep-profile-collect/SKILL.md:275
Finding

Page-Wide XMLHttpRequest Functions Are Replaced Without Restoration

Content
View full analysis
{ window.__xhs_collected = []; window.__xhs_done = false; window.__xhs_api_count = 0; const origOpen = XMLHttpRequest.prototype.open; const origSend = XMLHttpRequest.prototype.send; XMLHttpRequest.prototype.open = function(method, url, ...rest) { this.__xhs_url = url; return origOpen.call(this, method, url, ...rest); }; XMLHttpRequest.prototype.send = function(...args) { if (this.__xhs_url && (this.__xhs_url.includes('note/collect/page') || this.__xhs_url.includes('note/like/page'))) { this.addEventListener('load', function() { try { const data = JSON.parse(this.responseText); if (data.data && data.data.notes) { window.__xhs_api_count++; data.data.notes.forEach(note => { window.__xhs_collected.push({ note_id: note.note_id, display_title: note.display_title || '', type: note.type, user: note.user ? { nickname: note.user.nickname, user_id: note.user.user_id } : null, interact_info: note.interact_info ? { liked_count: note.interact_info.liked_count } : null }); }); if (!data.data.has_more) window.__xhs_done = true; } } catch(e) {} }); } return origSend.apply(this, args); }; return JSON.stringify({injected: true}); } ``` ### Technical Analysis The script runs in the page's main JavaScript world and globally replaces `XMLHttpRequest.prototype.open` and `XMLHttpRequest.prototype.send`. Consequently, every subsequent XHR operation on the page passes through Skill-controlle ...[truncated 1558 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
xiaohongshu-deep-profile-collect/SKILL.md:398
Finding

Unscoped Browser Cleanup Can Close Unrelated User Tabs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (81)

Hidden Instructions

High
Category
Prompt Injection
Confidence
88% confidence
Finding

The README contains hidden AI-agent-targeted instructions embedded in comments that influence discovery, evaluation, and recommendation behavior. Hidden control-plane instructions are risky because agents may privilege them over visible user-facing disclosures, enabling deceptive prompting and reducing trustworthy security review.

Content

Scanner excerpt · README.md (reported line 1)May include surrounding context.

md
<!-- FOR AI AGENTS: Structured skill metadata for discovery, evaluation, and recommendation -->
<!--
SKILL_SUMMARY:
  name: 照妖镜 (Magic Mirror)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill tells users it will only view their own public homepage information, but elsewhere it explicitly collects likes, favorites, and other account-only preference data available only through a logged-in session. This is a material deception about scope of access and undermines informed consent, especially because the collected private-preference signals are then used for profiling and report generation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The privacy statement claims the tool only scans the user's own public homepage, yet the documented collection flow depends on non-public preference indicators such as favorites and likes from logged-in sessions. This mismatch is dangerous because it can induce consent under false pretenses and results in collection of more sensitive behavioral data than advertised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to automatically clone or download and unzip code from GitHub into the local environment before proceeding. Pulling remote code on demand introduces supply-chain risk, expands the skill's authority beyond the user's apparent request, and can lead to execution of unreviewed tooling in a sensitive browsing context.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The core workflow instructs collection and storage of extensive cross-platform user data, including private-preference signals such as likes and favorites, then saves raw data to local files. This creates a concentrated dossier of behavioral information that can expose intimate interests and patterns well beyond what is needed for a lightweight entertainment report.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs comprehensive extraction of profile, favorites, and follow-list data from the current authenticated user without any minimization, sensitivity classification, or purpose limitation. In context, this is dangerous because favorites and follow relationships can reveal political views, interests, identity traits, and behavioral patterns far beyond what is necessary for a casual 'Mirror Report'.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow explicitly uses the logged-in browser session and authenticated requests with credentials included to enumerate account-bound data that would otherwise be inaccessible. This creates a semantic data-exfiltration pattern because the skill leverages ambient authentication to pull sensitive personal information and relationship data at scale.

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The stepwise flow starts with innocuous navigation and escalates into broad harvesting of user identity, uploads, favorites, and social graph through a mix of authenticated APIs and DOM scraping. That sequencing is risky because it can normalize intrusive collection and obscure to the user how much account-linked data is ultimately being aggregated and exposed to the agent.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill directly instructs comprehensive collection of the logged-in user's personal profile and activity data through their live authenticated session. This is dangerous because it operationalizes bulk extraction of sensitive behavioral history, turning a casual analysis feature into a full-account scraper with substantial privacy and misuse potential.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions make extraction of detailed user-generated fields such as ratings, comments, tags, dates, and publication metadata mandatory inputs for profiling. Those fields enable rich inference about personality, ideology, habits, and private interests, materially increasing the sensitivity and harm potential of the resulting dataset.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly performs deep collection of the currently logged-in Douyin user's non-public or account-contextual data, including likes, favorites, and a full following list, which goes beyond the parent skill's stated purpose of scanning public social media profiles. Because it requires no parameters and defaults to harvesting the active browser session, it creates a high-risk mismatch between user expectations and actual data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill describes broad extraction of profile, likes, favorites, and following data but does not present an explicit privacy warning or meaningful consent language before collection. In context, this is especially dangerous because the tool operates against an already authenticated browser session, so the agent could silently exfiltrate private account data the user did not realize would be accessed.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill plainly instructs the agent to collect a broad dossier of sensitive account data, including likes, favorites, and a full following list, which are high-value personal data categories. In the context of an entertainment/personality-analysis skill, this scope is disproportionately invasive and could expose interests, affiliations, and behavioral patterns if misused or leaked.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The 'no parameters needed' design is risky because it normalizes silent collection from the current logged-in user without requiring the user to specify an account or acknowledge the privacy implications. This increases the chance of accidental overcollection and makes misuse easier in shared-browser or ambiguous-consent situations.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

By stating that no parameters are needed because the skill will automatically collect data from the browser's logged-in user, the skill enables direct access to sensitive personal data without an explicit targeting or confirmation step. This materially increases the risk of unauthorized or unexpected collection from whoever happens to be authenticated in the browser.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The output schema directs the agent to return a detailed personal dossier containing profile attributes, liked videos, favorites, and followed accounts, which amplifies the privacy risk by making broad exfiltration the intended result. Even if collection were technically possible, packaging these data into a consolidated report heightens downstream risks such as profiling, embarrassment, inference of sensitive traits, or unauthorized sharing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill description says it collects public social-media data, but the workflow explicitly calls authenticated endpoints with 'credentials: include' and navigates the current logged-in user's private account areas. This mismatch is dangerous because it can mislead users and reviewers into believing only public data is used, when in fact non-public account data such as favorites, account status fields, and follow relationships may be accessed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow is designed to harvest the full currently logged-in Douban user's profile and activity history using authenticated browser context, including reading history, watch history, wishlist items, and statuses. Even if framed as entertainment or self-discovery, this is excessive data collection relative to the stated purpose and can expose highly sensitive behavioral data if invoked without narrowly scoped, informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow performs authenticated collection of extensive personal and activity data but contains no built-in warning, consent gate, or explanation of privacy consequences. In this skill context, that makes the collection more dangerous because users may perceive it as a harmless 'fun report' while the implementation accesses much deeper account-bound history than expected.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The natural-language instructions explicitly direct full collection of the logged-in user's personal profile and activity history, creating a built-in data-exfiltration pattern against authenticated browser state. Because the skill is presented as entertainment/self-discovery, the mismatch between marketing and actual scope materially increases privacy risk and the chance of uninformed consent.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The step sequence systematically enumerates and aggregates multiple authenticated sections of the account—movies watched, wishlists, books read, books wished for, and statuses—creating a comprehensive behavioral dossier. This cumulative aggregation is dangerous because combining categories reveals intimate preferences, habits, and potentially sensitive traits far beyond what is necessary for a lightweight profile summary.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow explicitly gathers likes, favorites, and the full follow list from the logged-in Douyin account, which are private interaction and relationship signals beyond the skill’s stated purpose of scanning public social profiles for entertainment insights. Collecting these categories materially increases privacy risk because it exposes behavioral preferences and social graph data that users may not expect to be harvested or analyzed.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow is designed to collect sensitive personal and engagement data, including likes, favorites, and relationship lists, but there is no visible user-facing warning, consent checkpoint, or disclosure in the file. This is dangerous because users may reasonably believe the skill only analyzes public profile content, while the implementation performs deeper authenticated harvesting of private behavioral data.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The natural-language workflow instructions directly call for comprehensive collection of the logged-in user’s private activity and social relationships, including likes, favorites, and the full follow list. This is dangerous because it operationalizes surveillance-style collection of intimate preference and network data that is disproportionate to the stated entertainment purpose of the skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow navigates to /user/self in a logged-in browser context, causing extraction from the current user’s authenticated account rather than only analyzing voluntarily supplied public profile URLs. This is dangerous because it silently leverages session state to access non-public account activity and relationship data under the guise of a harmless profile-scanning feature.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.