Back to skill

Security audit

Xiaohongshu Copy

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Chinese Xiaohongshu copywriting helper with trend-search guidance and no hidden code, persistence, or data access.

Install this if you want Chinese Xiaohongshu-style marketing drafts that may use web search to incorporate current weekly trends. Review generated copy before publishing, especially hashtags and trend references, because the skill provides posting suggestions but does not itself publish content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad and include common user phrasing such as '写小红书' and references to '小红书文案/笔记', which can cause the skill to activate in situations where the user is merely discussing content rather than explicitly requesting this workflow. Over-broad activation increases the chance of unintended tool use, web searches, and context hijacking, especially because the skill automatically performs weekly hot-topic searches and generates marketing-style output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructions and output requirements are entirely specified in Chinese for generating Xiaohongshu copy, with no indication that the user may choose another language or opt in to Chinese-only behavior. Under the stated policy, forcing a specific language without user choice is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file presents all guidance and examples exclusively in Chinese, which may amount to a language-policy violation if skills are expected to avoid forcing a specific language without user opt-in. No alternative locale, translation note, or user choice is provided anywhere in the file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.