Back to skill

Security audit

小红书搜索雷达

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a disclosed Xiaohongshu API command skill, but it handles credentials and access-bearing URLs unsafely enough that users should review it before installing.

Install only if you trust the guaikei.com API provider and are comfortable sending it your API token, search terms, and note URLs. Treat generated logs as sensitive because they may contain xsec_token-bearing Xiaohongshu links and collected result data; delete or protect them after use. The publisher should move the API token out of query strings, strengthen URL parsing, redact sensitive URL parameters, and make log persistence opt-in or configurable.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
src/utils/request.js:41
Finding

API Credential Exposed in Request Query Strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/validate/url.js:6
Finding

Bypassable Xiaohongshu URL Allowlist

Content
View full analysis
{ return await postJson( "/api/xiaohongshu/detail/url", { _: Date.now(), token: token }, { url: url }, ); }, ``` `src/api/detail.js:41-49`: ```js async function getDetailTask(token, url) { return await withRetry( async () => { const res = await getJson("/api/xiaohongshu/detail/info", { _: Date.now(), token: token, url: url, }); ``` ### Technical Analysis The validator uses substring searches rather than parsing the URL and comparing its canonical hostname and path. A URL is accepted if the expected Xiaohongshu text occurs anywhere in the supplied string. For example, the following attacker-controlled URL starts with HTTPS and contains the required substrings, but its actual host is `attacker.example`: ```text https://attacker.example/?next=https://www.xiaohongshu.com/explore/test?xsec_token ...[truncated 2071 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/log.js:5
Finding

Access-Bearing URLs and API Results Stored in Plaintext Logs

Content
View full analysis
|]/g, "_"); const outputFilename = path.join( path.dirname(__filename), "..", "..", ...[truncated 2314 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个更广泛的“小红书搜索/分析雷达”产品,核心能力应包括搜索、挖掘、分析与筛选等高层功能。但给定代码块只实现了 detail-cli:它接受笔记链接而非关键词,校验 URL 后调用 detail.createDetailTask / getDetailTask 获取单条笔记详情,并输出 JSON 结果。这与声明中的主要用途明显不一致。代码没有展示关键词搜索、爆款挖掘、竞品分析、KOL筛选或趋势洞察逻辑。虽然帮助文本提到 search-cli 的输出 URL 可作为输入,但本代码本身并不是搜索雷达,而是一个下游的“详情抓取”组件。因此应判定为描述与该代码块行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The code is clearly related to Xiaohongshu search, so the core domain matches part of the description. However, the implemented behavior in this chunk is narrower than the declared purpose: it performs keyword search task creation/retrieval and formatting of results, but does not show dedicated logic for爆款笔记挖掘,竞品分析,KOL筛选, or趋势洞察. Also, while '无需登录小红书账号' is not strictly contradicted, the code does require a separate environment API token, which is an access requirement not reflected in the description. Finally, it writes logs/results to disk, an undeclared auxiliary capability. Overall, the description overstates the implemented capabilities in this code chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
- "分析这篇笔记的评论区情绪: node src/xiaohongshu/detail-cli.js 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy'"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
- "分析这篇笔记的评论区情绪: node src/xiaohongshu/detail-cli.js 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy'"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

This manifest uses broad activation-oriented description terms such as content planning, competitor analysis, trend insights, and generic marketing keywords without any narrowing constraints or exclusion conditions. In a manifest file, such broad phrasing can overlap with common user intents and increase the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends a token and note URL to remote API endpoints via postJson, which is a safety-relevant data transmission operation. While the docstring names the token parameter, there is no explicit user-facing warning, confirmation, or comment disclosing that these values are transmitted to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function performs an HTTP GET request containing the user's token and URL, which is a relevant privacy and safety-sensitive operation under the rule. The surrounding comments describe parameters and errors but do not explicitly warn that these values are transmitted over the network to an external API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This utility builds and sends GET and POST HTTPS requests, including serialized request parameters and JSON bodies, but the file contains no user-facing warning, logging, confirmation, or explanatory comment/docstring about transmitting data to a remote service. For code files, network calls that transmit user or system data should have some visible disclosure unless clearly covered elsewhere or obviously inherent to the skill's stated purpose, which is not evident from this file alone.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s comments and user-facing validation/error messages are entirely in Chinese, including examples and constraints, which effectively forces a specific language for users interacting with this validator. The provided policy says locale constraints should be flagged unless the skill offers user choice or clearly documents a justified region-specific limitation, which is not present in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

All visible usage instructions, examples, notices, and runtime messages in this file are presented only in Chinese. This imposes a locale/language choice on users without opt-in or documented justification, which matches the policy-violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI always writes the full search results to a local JSON file regardless of the selected output mode, while the help text suggests output is controlled by the --output flag. This creates an undisclosed persistence channel for potentially sensitive search terms and harvested results, which can surprise users and leak data to other local users, backup systems, or downstream tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The program writes search results to a local JSON file without warning the user in help text or normal output, which is a covert data-retention behavior. Because searches may include commercially sensitive topics, competitor analysis, or user research terms, silent local logging increases the chance of privacy, confidentiality, and compliance issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill documentation and examples are entirely in Chinese, and no language choice or opt-in is offered. Per the policy rule, a skill should not force a specific language or locale unless it provides user choice or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill writes search and detail results to local logs files, but this persistence is not clearly disclosed up front where users decide whether to run it. Silent or under-disclosed local logging can expose sensitive search terms, note URLs, analysis targets, and potentially regulated business intelligence to other local users, backups, or downstream processes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest consistently describes this as a Xiaohongshu search and analysis skill, including name, examples, and parameter docs. Line L118 explicitly says it only captures Douyin public data, which directly conflicts with the declared target platform and intended behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The natural-language metadata is entirely in Chinese and targets a Chinese platform, but the manifest does not indicate that language choice is optional or that the skill is intentionally limited to Chinese-speaking users. This may conflict with language/locale policy expectations when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

Comments and parameter descriptions in this file are exclusively in Chinese, with no indication that language selection is configurable or intentional for a region-specific skill. Under the policy, forcing a specific language without user opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code sends the provided token in outbound HTTP requests as a query/body parameter when creating a search task. Although network access is part of the module's purpose, this file does not include any user-facing warning, confirmation, or disclosure that credentials are being transmitted to an external API.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The user-facing warning and guidance text is hard-coded entirely in Chinese, and the file provides no indication that the skill is region-specific or that users can choose another language. This is a natural-language locale policy concern because it imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code emits user-facing status and error messages only in Chinese ("已保存到" and "日志写入失败") with no indication that the skill is intentionally region-specific or that users can choose another language. This can violate language/locale policy expectations when a skill is meant for general use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The code explicitly references the GUAIKEI_API_TOKEN environment variable in an authentication failure path, indicating the skill depends on a credential, but this file provides no comment or disclosure about handling sensitive environment variables. For code files, access to or dependency on credentials should have some visible warning or explanation unless clearly documented elsewhere.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The thrown error string uses Chinese text (重试${maxAttempts}次后失败) with no indication that the skill is region-specific or that users can choose their preferred language. This is a natural-language locale policy concern because it forces a specific language in user-visible output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The log output calls toLocaleString() with no user-configurable locale, which means the displayed language/date formatting is implicitly determined by the runtime environment rather than an explicit user choice. Given the rest of the file uses Chinese-language output, this creates a locale policy concern because the skill presents language/locale behavior without documented opt-in or selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JavaScript file contains user-facing error messages and comments entirely in Chinese, such as the validation errors on L10, L14, L19, and L24. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.