Back to skill

Security audit

小红书关键词搜索

Security checks for vulnerabilities and agentic risk

Overview

The skill largely does what it claims, but it automatically saves complete query results and tokenized Xiaohongshu URLs into a predictable temporary log location without clear retention or opt-out controls.

Review this before installing if you will run searches involving sensitive campaign plans, competitor research, or URLs with xsec_token values. The skill sends query data and its API token to guaikei.com and stores full returned datasets locally in temporary logs; run it only in a private user environment, periodically clear those logs, and consider disabling or fixing logging before collecting large comment/profile datasets.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/log.js:24
Finding

Plaintext Sensitive Data Logging in a Predictable Temporary Directory

Content
View full analysis
/xiaohongshu-guaikei/logs/YYYY-MM-DD/ ``` The serialized data includes the submitted request URL and the complete API result. Xiaohongshu URLs can contain an `xsec_token` query parameter, while returned detail, comment, search, and profile records may contain user-generated content, account identifiers, interaction information, and addi ...[truncated 3522 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (48)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是面向小红书公开数据抓取/检索与分析的业务能力,但实际代码片段仅实现了通用 CLI 参数解析与帮助信息生成,没有任何小红书相关的数据访问、检索、分析、网络请求、公开内容处理或平台交互逻辑。该代码的主要用途与声明的核心功能明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The declared description focuses on querying and analyzing public Xiaohongshu content and interaction data. The actual code shown does not perform any network requests, scraping, API access, or content analysis related to Xiaohongshu. Instead, it writes supplied content to local files in a temp/logs directory. While logging can be a supporting implementation detail, this chunk exposes a concrete file-writing capability that is not reflected in the declared permissions, and the chunk by itself does not match the declared primary purpose. Therefore this is a description-behavior mismatch for the supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description describes a network/data-retrieval skill focused on Xiaohongshu public content analysis. The supplied code chunk does not implement any of those capabilities. It merely reads package.json from the local filesystem, caches the package name, and returns it. This is materially different from the declared primary purpose and accesses a different resource type than implied by the description. While this could be a supporting utility in a larger skill, based on this code chunk alone the behavior does not match the declared functionality.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
- "这条小红书笔记评论区在吐槽什么 → node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 200"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
- "这条小红书笔记评论区在吐槽什么 → node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 200"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
- "这条小红书笔记评论区在吐槽什么 → node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 200"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 297)May include surrounding context.

md
- "这条小红书笔记评论区在吐槽什么 → node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 200"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
- "看这个小红书博主最近 30 条作品发什么 → node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 30"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

md
- "看这个小红书博主最近 30 条作品发什么 → node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 30"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 300)May include surrounding context.

md
- "看这个小红书博主最近 30 条作品发什么 → node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 30"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 303)May include surrounding context.

md
- "看这个小红书博主最近 30 条作品发什么 → node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 30"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
- "分析这篇小红书爆款笔记为什么火 → node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy'"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
- "分析这篇小红书爆款笔记为什么火 → node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy'"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
- "分析这篇小红书爆款笔记为什么火 → node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy'"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
- "分析这篇小红书爆款笔记为什么火 → node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy'"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 294)May include surrounding context.

md
- "分析这篇小红书爆款笔记为什么火 → node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy'"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill requires access to the environment variable GUAIKEI_API_TOKEN but does not declare an explicit tool scope such as permissions or allowed-tools. In agent environments, undeclared capability use weakens least-privilege controls and can allow broader-than-expected secret exposure or execution behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The primary description is written entirely in Chinese and presents the skill's invocation and use context only in Chinese, without offering a language choice or stating that the skill is intended exclusively for a Chinese-language audience. This can violate a language/locale policy when skills are expected to avoid forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly advertises collection of comment content and user information from public Xiaohongshu data, but it does not provide a clear privacy warning, data-handling guidance, retention limits, or restrictions on processing personal data. Even if the data is publicly accessible, aggregating and exporting user-linked content increases privacy and compliance risk by making profiling, redistribution, and secondary use easier.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/options.md (reported line 179)May include surrounding context.

md
| --------------- | ------------------------ | --------------------------------------------------------------------------------- |
| `--url`, `-u`   | 小红书博主主页链接,必填 | 建议使用主页链接或可解析的短链                                                    |
| `--limit`, `-l` | 返回作品数量上限         | 建议显式传入 `0-10000`;若为0,则获取该博主的互动数据(粉丝量、点赞量、收藏量等) |
| `--help`, `-h`  | 显示帮助信息             | 无                                                                                |

### 4.4 链接建议

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file contains natural-language content such as the module description and runtime-visible retry/error messages exclusively in Chinese. Under the stated policy, forcing a specific language without user opt-in or documented locale justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code sends the user-provided keyword and API token to an external service via postJson, which is a privacy-relevant network operation. Although the function comments describe parameters, there is no user-facing confirmation, warning, or disclosure here about transmitting search terms and credentials off-system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The getSearchTask function performs a network request that includes the keyword, filters, limit, and token. For code-file review, this is a safety-relevant external transmission of user/system data, and there is no visible prompt, print, or warning explaining that these details are sent to a remote service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits all user-facing warning and informational text exclusively in Chinese. Because the file provides no opt-in, fallback language, or indication that the skill is intentionally limited to Chinese-speaking users, it conflicts with the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code performs outbound HTTPS GET and POST requests and includes a TOKEN header, while also sending request parameters and JSON payload data to a remote host. There is no confirmation prompt, user-facing log/print, or inline warning in this file disclosing that user/system data and credentials may be transmitted over the network.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16