Back to skill

Security audit

Xiaohongshu Proxy Manager

Security checks for vulnerabilities and agentic risk

Overview

This proxy manager is disclosed, but it is aimed at evading Xiaohongshu account-abuse controls and handles proxy credentials unsafely.

Only install this if you intentionally want a Chinese-language Xiaohongshu proxy/account-isolation tool and understand the platform-policy risk. Do not use it for deceptive multi-account automation or ban evasion, avoid entering paid proxy passwords through command-line flags, restrict permissions on the config file, and treat any printed proxy URL as a secret.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
source/proxy_manager.py:54
Finding

Proxy credentials are exposed through command-line arguments, plaintext storage, and unredacted output

Content
View full analysis

Vulnerability Details

File Location: source/proxy_manager.py:54-56, source/proxy_manager.py:95-97, source/proxy_manager.py:188-203, source/proxy_manager.py:220-228, and source/proxy_manager.py:338-339
Vulnerability Type: Plaintext sensitive-data storage and credential disclosure
Risk Level: Medium

Vulnerable Code

Plaintext configuration storage at source/proxy_manager.py:54-56:

python
CONFIG_DIR.mkdir(parents=True, exist_ok=True)
with open(CONFIG_FILE, "w", encoding="utf-8") as f:
    json.dump(config, f, indent=2, ensure_ascii=False)

Credentials embedded in proxy URLs at source/proxy_manager.py:95-97:

python
if proxy.get("username") and proxy.get("password"):
    proxy_url += f"{proxy['username']}:{proxy['password']}@"
proxy_url += f"{proxy['host']}:{proxy['port']}"

Unredacted account-proxy output at source/proxy_manager.py:188-203:

python
proxy_url = f"{proxy['protocol']}://"
if proxy.get("username") and proxy.get("password"):
    proxy_url += f"{proxy['username']}:{proxy['password']}@"
proxy_url += f"{proxy['host']}:{proxy['port']}"

print(f"📦 账号 {account_id} 的代理配置:")
print(f"   HTTP_PROXY={proxy_url}")
print(f"   HTTPS_PROXY={proxy_url}")
print()
print("💻 Python requests 用法:")
print(f"   proxies = {{'http': '{proxy_url}', 'https': '{proxy_url}'}}")
print(f"   response = requests.get(url, proxies=proxies)")
print()
print("🐘 curl 用法:")
print(f"   curl -x '{proxy_url}' https://example.com")

Unredacted random-proxy output at source/proxy_manager.py:220-228:

python
proxy_url = f"{proxy['protocol']}://"
if proxy.get("username") and proxy.get("password"):
    proxy_url += f"{proxy['username']}:{proxy['password']}@"
proxy_url += f"{proxy['host']}:{proxy['port']}"

print(f"🎲 随机代理:{proxy.get('name', proxy.get('id', ''))}")
print(f"   HTTP_PROXY={proxy_url}")
print(f"   HTTPS_PROXY={proxy_url}")

Password ...[truncated 2626 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove or deprecate the --password command-line option. Prompt interactively with Python's getpass.getpass() or retrieve the password from a dedicated secret manager.
  2. If noninteractive operation is required, accept a reference to a protected secret rather than the secret itself. Avoid ordinary environment variables where stronger secret-injection mechanisms are available.
  3. Create the configuration file atomically with owner-only mode 0600, and ensure the configuration directory is not accessible to unrelated users.
  4. Check permissions on existing configuration files at startup. Refuse to use insecurely permissioned files or warn the operator and correct their mode.
  5. Do not print authenticated proxy URLs by default. Redact passwords, for example by displaying username:******@host:port.
  6. Provide an explicit, security-gated export operation only when a caller genuinely requires the complete URL. Document that its output must not be logged.
  7. Separate nonsensitive proxy metadata from credentials. Store only a credential reference in proxies.json, with the actual password held in an operating-system keyring or secret manager.
  8. Review and rotate existing proxy credentials because they may already exist in shell histories, configuration files, or captured command output.
  9. Update documentation and examples so they do not encourage passing passwords on the command line or printing authenticated URLs.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
83% confidence
Finding

The declared description promises a functional proxy isolation/management tool with proxy switching, latency control, and user-behavior simulation. However, the supplied code chunk does not implement those behaviors; it only installs/prepares the environment by creating directories and a configuration template and validating the presence of another script. While the printed instructions suggest the broader tool may support proxy management and latency testing elsewhere, this specific code chunk’s actual behavior is setup/scaffolding, and it does not demonstrate simulated user behavior at all. Therefore, the supplied code does not accurately match the declared functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

整体上,代码的核心目的与“多账号IP隔离/代理池管理”基本一致,因此主方向是匹配的。但描述包含两项明显未实现的能力:一是“延迟控制”,实际只有代理延迟测试;二是“模拟真实用户行为”,代码中完全没有相关逻辑。此外,实际代码还会访问外部测试网址(默认百度)并将代理配置、账号映射写入本地 JSON 文件,这些资源访问在描述中未体现。按评估标准,这属于描述与实际行为存在一定程度的不一致,尤其是功能性表述夸大。

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
98% confidence
Finding

The code performs outbound network access using requests.get() to test proxies, but that capability is not covered by declared permissions. Undeclared network access is risky because it can transmit user traffic, metadata, and proxy credentials to external systems outside expected platform controls.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
98% confidence
Finding

The code performs outbound network access using requests.get() to test proxies, but that capability is not covered by declared permissions. Undeclared network access is risky because it can transmit user traffic, metadata, and proxy credentials to external systems outside expected platform controls.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
98% confidence
Finding

The code performs outbound network access using requests.get() to test proxies, but that capability is not covered by declared permissions. Undeclared network access is risky because it can transmit user traffic, metadata, and proxy credentials to external systems outside expected platform controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill description and usage guidance are presented only in Chinese, and the file does not offer an alternative language or indicate that the skill is intentionally limited to Chinese-speaking users for a documented regional reason. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 191)May include surrounding context.

'http': 'http://1.1.1.1:8080', 'https': 'http://1.1.1.1:8080' } response = requests.post(api_url, json=data, proxies=proxies)

text

### 场景 2:负载均衡(随机代理)

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The skill explicitly frames proxy usage to support multi-account Xiaohongshu activity, including reducing bans, appearing as different users, and avoiding detection as '刷量'. In this context, the outbound request capability is more dangerous because it facilitates platform-evasion and potentially deceptive automation against a third-party service, exposing users to account sanctions and abuse workflows.

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

PROXY=$(xiaohongshu-proxy-manager --random | grep HTTPS_PROXY | cut -d= -f2)

在 curl 中使用

curl -x "$PROXY" https://api.xiaohongshu.com/publish

text

### 场景 3:代理健康检查

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

md
print("未找到代理,直接连接")
        proxies = None

    response = requests.post(url, json=data, proxies=proxies)
    return response

# 使用示例

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This example shows posting content to Xiaohongshu through account-specific proxies as part of a multi-account operational pattern designed to avoid same-IP linkage. In context, the network transmission is not merely generic HTTP use; it operationalizes account-farm style behavior and abuse-evasion, which materially increases misuse risk even though the snippet itself is simple.

Content

Scanner excerpt · SKILL.md (reported line 278)May include surrounding context.

使用示例

response = post_with_proxy( 'main_account', 'https://api.xiaohongshu.com/publish', {'title': '装修干货', 'content': '...'} )

text

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script's user-facing comments and status/error messages are entirely in Chinese, including operational guidance and errors. This imposes a specific language on all users without any opt-in, fallback, or documentation that the skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The proxy test sends an outbound HTTP request through the configured proxy to a third-party test URL, which reveals request metadata and potentially sensitive proxy usage patterns to both the proxy provider and destination. Without explicit warning or consent, users may not realize that testing a proxy transmits traffic externally and may leak IP, headers, or operational details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Proxy usernames and passwords are stored in proxies.json in plaintext, which exposes credentials to any local user, process, backup system, or malware with access to the home directory. Because these credentials may grant access to paid proxy infrastructure or be reused elsewhere, plaintext storage materially increases the chance of credential theft.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file documents a --remove operation and identifies the persistent config file location, which implies user data in the proxy configuration can be deleted. Although the command is part of the tool's purpose, the documentation does not include any warning that removal changes the saved configuration or may be irreversible.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The proxy name is specified as "代理1", which indicates a fixed Chinese-language label in configuration. For a general-purpose skill configuration, this imposes a specific language choice without any visible opt-in or documented locale scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file contains user-facing comments and printed installation/use instructions entirely in Chinese, which imposes a specific language on users. Under the policy, a forced language without opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The module docstring and all user-facing CLI messages are exclusively in Chinese, with no indication that the language is configurable or intentionally restricted to a region-specific audience. Under the stated policy, forcing a single language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.