T09 · Insecure Skill Coding Practices
- Location
src/utils/log.js:38- Finding
Automatic Storage of Sensitive Results in a Predictable Shared Temporary Directory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it advertises, but it automatically stores complete query results and tokenized URLs in a predictable temporary folder, so it needs review before use.
Use this only if you are comfortable sending Xiaohongshu keywords, links, and URL query parameters to guaikei.com and storing the returned data locally. Avoid running it on shared machines for sensitive research, strip unnecessary URL parameters where possible, and periodically delete the xiaohongshu-guaikei temp logs.
src/utils/log.js:38Automatic Storage of Sensitive Results in a Predictable Shared Temporary Directory
The declared description says this skill retrieves public Xiaohongshu data for multiple analysis use cases. The actual code chunk only implements reusable CLI argument parsing utilities (parseArgs, readValueAfterFlag, buildHelp). It does not connect to any external service, process Xiaohongshu links/keywords beyond generic argument handling, fetch public data, or analyze comments/sentiment. This is a materially different primary purpose, so the description does not accurately represent the supplied code chunk.
The declared description presents a Xiaohongshu public-data search and analysis capability. The actual code shown is a filesystem logging helper (taskWrite) that creates a temp-directory path and writes provided content to a local file after sanitizing the filename. This is materially different from the declared primary purpose, and the core described capabilities are absent from the supplied code. While logging could be a supporting detail in a larger skill, this chunk itself does not reflect the stated data-retrieval behavior and instead exposes an undeclared local file-write capability.
The declared description presents a full Xiaohongshu data lookup and analysis capability. The supplied code chunk does not implement any such behavior; it merely reads package.json from the local filesystem and returns the package name. This is a materially different purpose from the declared functionality, so it should be flagged as a mismatch.
Referenced artifact was not completely inspected
- "这条小红书笔记评论区在吐槽什么 → node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 200"
Referenced artifact was not completely inspected
- "这条小红书笔记评论区在吐槽什么 → node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 200"
Referenced artifact was not completely inspected
- "这条小红书笔记评论区在吐槽什么 → node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 200"
Referenced artifact was not completely inspected
- "这条小红书笔记评论区在吐槽什么 → node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 200"
Referenced artifact was not completely inspected
- "这条小红书笔记评论区在吐槽什么 → node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 200"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 30 条作品发什么 → node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 30"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 30 条作品发什么 → node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 30"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 30 条作品发什么 → node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 30"
Referenced artifact was not completely inspected
- "看这个小红书博主最近 30 条作品发什么 → node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 30"
Referenced artifact was not completely inspected
- "分析这篇小红书爆款笔记为什么火 → node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy'"
Referenced artifact was not completely inspected
- "分析这篇小红书爆款笔记为什么火 → node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy'"
Referenced artifact was not completely inspected
- "分析这篇小红书爆款笔记为什么火 → node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy'"
Referenced artifact was not completely inspected
- "分析这篇小红书爆款笔记为什么火 → node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy'"
Referenced artifact was not completely inspected
- "分析这篇小红书爆款笔记为什么火 → node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy'"
The skill declares access to an environment variable (GUAIKEI_API_TOKEN) but does not declare an explicit tool scope such as permissions or allowed-tools. That weakens least-privilege guarantees and makes it harder for a host agent or reviewer to understand and constrain what sensitive resources the skill may access.
The skill states that data flows to guaikei.com and requires users to provide Xiaohongshu links and keywords, but it does not prominently warn that user-supplied links, query parameters, and potentially embedded tokens in URLs are transmitted to a third-party service. This creates a privacy and data-handling risk because users may unknowingly send tracking parameters or sensitive business research targets to an external API.
The description and keywords are entirely in Chinese and specifically target the Xiaohongshu platform, which effectively constrains the skill's presentation to a single language/locale. In this manifest there is no indication that users can choose another language or that the locale restriction is explicitly justified as a region-specific tool.
The README instructs users to interact with the agent using a Chinese natural-language example ('然后直接说人话:…') and the entire skill description is Chinese-only, with no indication that other languages are supported or that language choice is optional. This can violate language/locale policy when a skill effectively constrains user interaction to a specific language without opt-in.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
| --------------- | ------------------------ | --------------------------------------------------------------------------------- |
| `--url`, `-u` | 小红书博主主页链接,必填 | 建议使用主页链接或可解析的短链 |
| `--limit`, `-l` | 返回作品数量上限 | 建议显式传入 `0-10000`;若为0,则获取该博主的互动数据(粉丝量、点赞量、收藏量等) |
| `--help`, `-h` | 显示帮助信息 | 无 |
### 4.4 链接建议
The document instructs users to retrieve comments, profile interaction metrics, and other public platform data, but it does not warn about privacy, terms-of-service, or downstream handling risks. In a skill that operationalizes large-scale collection of third-party social data, omission of compliance and data-handling safeguards can enable misuse such as unauthorized profiling, excessive scraping, or inappropriate retention and sharing of user-generated content.
The troubleshooting document is entirely written in Chinese and does not provide any language-selection option or note that the skill is intentionally limited to Chinese-speaking users. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The function sends a user-provided note URL and API token to an external API via postJson, but this file contains no confirmation prompt or user-facing disclosure about that transmission. Because this is a code file, outbound transmission of user or system data should have some visible warning unless clearly disclosed elsewhere.
No suspicious patterns detected.