Back to skill

Security audit

Yq Xiaohongshu Collector

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Xiaohongshu collection assistant, but it directs broad verbatim collection of posts, images, usernames, links, OCR text, and comments without privacy or minimization limits.

Review before installing. This skill does not appear malicious and contains no executable code, but users should only use it for lawful, permissioned research, set narrow collection limits, and redact or summarize usernames, comments, links, and OCR text unless there is a clear need to keep them verbatim.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is explicitly designed to comprehensively collect Xiaohongshu notes, images, comments, usernames, timestamps, and related metadata, yet it provides no privacy guardrails, consent checks, minimization rules, or warning about handling user-generated personal data. This creates a clear risk of over-collection and redistribution of identifying or sensitive content from a third-party platform into structured reports.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction to preserve all collected content verbatim, including comments, image text, usernames, and publication details, encourages indiscriminate capture of potentially sensitive or identifying user-generated data. Verbatim reproduction removes any privacy filtering step and increases the chance of exposing personal information, harassment content, contact details, or other sensitive material in downstream outputs.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Mandating exhaustive browsing of all images and all comments broadens collection scope beyond what is likely necessary for most user requests and increases exposure to sensitive, personal, or abusive content. The instruction effectively operationalizes mass extraction of user-generated material without proportionality limits, purpose restriction, or filtering.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The deep-capture phase explicitly requires full recording of note text, all image content, and all comments in original form, which creates a concrete workflow for large-scale disclosure of third-party content and associated identifiers. In the context of a scraping/collection skill, this is more dangerous because it systematizes extraction and repackaging of potentially sensitive material into a consolidated report.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The output templates require inclusion of verbatim comments, usernames, replies, links, and OCR-extracted text, making the final artifact itself a vehicle for disclosing sensitive or identifying data. This materially increases risk because even if collection were initially limited, the reporting format mandates broad reproduction and persistent exposure of third-party content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.