Back to skill

Security audit

小红书MCP补丁包

Security checks for vulnerabilities and agentic risk

Overview

The skill is a deployment repair guide, but it tells users to handle session cookies and run repair commands in ways that can expose credentials or execute unverified local code.

Review this skill carefully before installing. Do not run the one-click script as-is, do not place cookies in /tmp, and do not execute a binary from /tmp unless you have independently verified its source and checksum. Use a private configuration directory with restrictive permissions for cookies, confirm process identity before stopping anything on port 18060, and prefer a managed service path over nohup background execution.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:54
Finding

Authentication Cookies Copied to Predictable Temporary Paths

Content
View full analysis
/dev/null || true cp "$COOKIE_SOURCE" ~/.cache/rod/browser/cookies.json echo "Cookie 文件已放置到:" find /tmp -name "cookies.json" 2>/dev/null find ~ -name "cookies.json" 2>/dev/null | head -5 ``` ### Technical Analysis The documented repair procedure duplicates an authentication cookie file into several predictable locations, including `/tmp/cookies.json` and `/tmp/cookies/cookies.json`. It does not establish restrictive directory or file permissions, validate the ownership of existing destination paths, reject symbolic links, or ensure atomic file creation. Because `/tmp` is normally shared and writable by multiple local users, an attacker may prepare destination paths or symbolic links before the procedure runs. The `mkdir -p` and `cp` commands do not adequately protect against an attacker-controlled existing path. Copying the same credentials to multiple locations also increases their exposure and makes secure deletion and access control more difficult. ### Attack Path 1. A local attacker predicts that the repair procedure will write to `/tmp/cookies.json` or `/tmp/cookies/cookies.json`. 2. The attacker monitors the destination or prepares an attacker-controlled path or symbolic link where filesystem permissions permit it. 3. A user runs the documented cookie repair procedure. 4. The procedure copies active authentication cookies into the predictable destination without ownership or symlink validation. 5. The attacker reads the copied file or causes it to be written to an ...[truncated 839 chars]
Remediation
View remediation
` or another private service directory. - Create the directory with mode `0700` and cookie files with mode `0600`. - Set a restrictive `umask`, such as `umask 077`, before creating credential files. - Create the destination atomically and reject pre-existing files, symbolic links, and paths with unexpected ownership. - Validate the source file's owner, type, and permissions before copying it. - Copy credentials only to the single location actually required by the application. - Avoid printing or broadly searching credential locations. - Remove obsolete copies securely and rotate the affected session credentials if exposure may already have occurred. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:201
Finding

Unverified Executable Launched from Shared Temporary Directory

Content
View full analysis
/tmp/mcp.log 2>&1 & sleep 3 ``` The one-click repair procedure repeats the same pattern: ```bash echo "[3/4] 启动服务..." cd /tmp if pgrep -f "xiaohongshu-mcp" >/dev/null; then echo "服务已在运行" else nohup ./xiaohongshu-mcp-linux-amd64 >/tmp/mcp.log 2>&1 & ``` ### Technical Analysis The procedure changes into `/tmp` and executes a fixed binary name without verifying its origin, ownership, file permissions, symbolic-link status, signature, or cryptographic checksum. The referenced binary is not included in the audited project, so its contents and provenance cannot be established from the package. A shared temporary directory is not an appropriate installation or execution location for trusted software. An attacker with local write access may be able to place or replace `/tmp/xiaohongshu-mcp-linux-amd64` before the documented command is run. The use of a relative executable path after `cd /tmp` then causes the attacker's file to execute. ### Attack Path 1. A local attacker learns or predicts the expected filename `/tmp/xiaohongshu-mcp-linux-amd64`. 2. Before the user runs the repair procedure, the attacker places a malicious executable at that path or replaces an insufficiently protected existing file. 3. The user executes the documented service-check or one-click repair script. 4. The script changes its working directory to `/tmp`. 5. `nohup ./xiaohongshu-mcp-linux-amd64` executes the attacker-controlled binary. 6. The malicious binary inherits the invoking user's privileges and environment and may continue running in the background. This path depends on the attacker being able to create or replace the target in `/tmp`; ownership and sticky ...[truncated 849 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:16
Finding

Unconditional Force-Termination of Any Process Using Port 18060

Content
View full analysis
/dev/null) if [ -n "$PID" ]; then echo "发现占用进程: $PID,正在终止..." kill -9 $PID sleep 2 ``` The one-click repair procedure performs the same destructive action without process verification: ```bash # 1. 修复端口 echo "[1/4] 检查端口..." lsof -ti:18060 | xargs kill -9 2>/dev/null sleep 1 ``` ### Technical Analysis The procedure assumes that every process bound to port 18060 is an unwanted MCP instance. It neither checks the executable path, process owner, command line, service identity, nor whether multiple processes were returned. It then sends `SIGKILL`, which cannot be handled by the target process and prevents graceful shutdown or cleanup. This creates a denial-of-service and data-integrity risk. An unrelated legitimate application may use the same port, or the expected service may be performing a stateful operation when forcibly terminated. Suppressing errors in the one-click command also makes partial or unexpected behavior difficult to detect. ### Attack Path 1. A legitimate, unrelated process binds to port 18060, whether by normal configuration or accidental collision. 2. A user runs the documented repair procedure. 3. `lsof` returns the PID or PIDs associated with that port. 4. The script sends `SIGKILL` without confirming process identity. 5. The unrelated service terminates immediately without cleanup. 6. Requests being processed, buffered data, or transient application state may be lost. A malicious local user could also intentionally cause a target process under the repair user's control to use the port and induce termination when the repair runs, although operating-system permission checks still restrict which processes the invoking user can signal. ### Impact Assessment The direct impact is denial ...[truncated 569 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation instructs users to copy cookies.json into multiple locations including /tmp and cache paths, but provides no privacy or credential-handling warning. Because cookie files often contain authenticated session tokens, this omission materially increases the risk of account compromise and unintended persistence of sensitive data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The one-click repair combines forceful process termination, service launch from /tmp, and automated connectivity testing without any upfront safety warning or confirmation. Bundling destructive and state-changing actions into a single opaque script increases the likelihood of accidental disruption and execution of untrusted local binaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The port-fix guidance force-kills whatever process is bound to port 18060 using kill -9, without validating process identity or warning that the process may be unrelated. This can terminate legitimate services, cause data loss, or disrupt other workloads on the host.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The 'cookie path fix' duplicates a sensitive authentication file into several broad locations, including /tmp and a user cache directory, which expands exposure well beyond a narrowly scoped repair. Cookies commonly represent live session credentials, so scattering them across world-accessible or long-lived paths increases the chance of credential theft, accidental disclosure, or reuse by other local processes.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

Creating cookie storage paths under /tmp and user cache locations supports persistence of live session material beyond immediate troubleshooting needs. Because those files can enable authenticated access, persistent copies materially raise the risk of credential reuse, theft, and forensic residue on the host.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
echo "复制 cookie 文件到多个位置..."

# 创建目录
mkdir -p /tmp/cookies
mkdir -p ~/.cache/rod/browser

# 复制到多个位置

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The service-check script silently starts a background binary from /tmp and sends an automated connection request, but the documentation does not warn users about these side effects. Hidden execution and network-style interaction, even to localhost, can mask risky behavior and make it easier to run unintended or tampered software.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Using nohup to launch a binary from /tmp creates a persistent background process outside direct user supervision. In context, this is risky because /tmp is not a trustworthy installation location, so persistence here can prolong execution of a tampered or misidentified binary.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
else
    echo "服务未运行,正在启动..."
    cd /tmp
    nohup ./xiaohongshu-mcp-linux-amd64 >/tmp/mcp.log 2>&1 &
    sleep 3
    
    if pgrep -f "xiaohongshu-mcp" >/dev/null; then

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
# 测试连接
echo "测试 MCP 连接..."
SESSION=$(curl -s -N -D - -X POST http://localhost:18060/mcp \
    -H "Content-Type: application/json" \
    -H "Accept: application/json, text/event-stream" \
    -d '{"jsonrpc":"2.0","method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test","version":"1.0"}},"id":1}' 2>/dev/null | \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 212)May include surrounding context.

md
# 测试连接
echo "测试 MCP 连接..."
SESSION=$(curl -s -N -D - -X POST http://localhost:18060/mcp \
    -H "Content-Type: application/json" \
    -H "Accept: application/json, text/event-stream" \
    -d '{"jsonrpc":"2.0","method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test","version":"1.0"}},"id":1}' 2>/dev/null | \

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The one-click script uses nohup to keep the service running in the background, creating persistence without explicit user review or process management. Combined with execution from /tmp, this increases the chance of long-lived unintended or unsafe code execution.

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

md
if pgrep -f "xiaohongshu-mcp" >/dev/null; then
    echo "服务已在运行"
else
    nohup ./xiaohongshu-mcp-linux-amd64 >/tmp/mcp.log 2>&1 &
    sleep 3
    echo "服务已启动"
fi

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description is written entirely in Chinese and provides no indication that other languages are supported or that the language choice is intentional and documented. Under the policy, language or locale constraints should be optional or clearly justified, and this file does neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language instructions and operational guidance are fully presented in Chinese, which effectively imposes a single language without stating that this is optional or context-specific. Under the stated policy, forcing a specific language without opt-in can be a locale/language policy issue.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script is presented as a status check but also starts a background binary from /tmp and performs an MCP initialize request. This mismatch reduces operator awareness and can cause unreviewed execution of a potentially untrusted binary, especially because /tmp is a common location for unsafe or replaceable files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.