Back to skill

Security audit

小红书趋势洞察

Security checks for vulnerabilities and agentic risk

Overview

The skill largely does what it claims, but it automatically saves complete Xiaohongshu API results to a shared temporary log location without clear retention or opt-out controls.

Review before installing if you use a shared machine or handle sensitive market research. The skill requires a guaikei.com API token, sends your Xiaohongshu keywords or links to that service, and automatically stores complete results locally; clear or protect those logs and avoid using confidential targets unless this behavior is acceptable.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/log.js:34
Finding

Insecure Storage of Complete API Results in a Shared Temporary Directory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (68)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是高层的趋势分析与内容洞察能力,但提供的代码仅涉及评论数据获取相关API调用,不包含趋势分析、热点判断、线索归纳或营销灵感整理等分析逻辑。虽然评论数据可能被下游用于趋势研究,但该代码块本身的实际功能是评论任务管理与结果获取,这属于未明确声明的具体数据采集能力,且与描述的主要用途存在实质偏差。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是高层分析/洞察类用途(趋势分析、热点观察、营销灵感整理),但代码并未实现任何趋势分析、聚合洞察、热点识别或内容方向判断逻辑。相反,它提供的是底层数据获取能力:为指定笔记URL创建详情/评论任务并轮询结果。这属于与声明相比更具体且不同的主要功能。虽然单条笔记详情数据可能被上层趋势分析所利用,但就此代码片段本身而言,其实际行为与声明的主要用途不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description emphasizes analytical/trend-insight functionality such as trend analysis, hotspot observation, and marketing inspiration. However, the supplied code does not perform analysis or trend inference; it only creates and retrieves task results for a specific Xiaohongshu blogger's published notes via API endpoints. This is a materially different primary purpose: data acquisition for blogger/post details rather than trend insight or content-direction analysis. No harmful extra permissions are visible, but the concrete implemented capability is narrower and different from the declared behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向小红书趋势分析与内容洞察的业务能力,但代码实际只是底层通用工具模块 src/utils/args.js,用于解析命令行参数,并未体现任何与小红书、趋势分析、热点洞察、营销灵感整理相关的数据处理、分析逻辑或外部资源访问。其主要目的与声明的核心功能明显不一致,因此属于描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个内容/趋势分析类技能,但给出的代码片段实际只负责 API Token 的验证和提示信息输出。这不是单纯的底层支持细节,因为当前代码完全没有体现任何趋势洞察、热点分析、内容方向判断等核心能力,反而表明该技能依赖一个未声明的私有 TOKEN 机制来启用服务。就所提供代码而言,其实际行为与声明的主要用途明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

声明的功能是内容/趋势分析类用途,但提供的代码片段实际只实现了日志落盘功能,没有任何与小红书趋势洞察、热点分析、内容方向判断或营销灵感整理相关的分析逻辑。虽然日志记录可能是辅助实现细节,但当前代码暴露了未声明的本地文件写入能力,而声明权限为空,也未提及文件系统访问。因此该代码片段与技能描述存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明的主要用途是进行小红书趋势分析与营销洞察,但提供的代码片段没有任何与趋势数据获取、分析、内容归纳或营销灵感相关的逻辑。相反,它只访问本地文件系统读取 package.json 并导出包名。这属于与声明用途 materially different 的行为;且声明权限为空,但代码实际使用了文件系统读取能力。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是面向小红书趋势分析与内容洞察的业务能力;而代码实际仅实现了一个底层通用重试工具函数,没有任何与小红书、趋势分析、热点观察、营销灵感整理或内容运营相关的逻辑。虽然这类工具代码可能作为更大技能的支持组件存在,但就该代码块本身而言,其实际行为与声明用途明显不一致,属于材料性目的不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是面向小红书趋势分析与营销洞察的业务能力,但给出的代码片段只实现了打印横幅和日志记录的通用工具函数,没有任何与趋势分析、数据处理、洞察归纳、热点判断或营销灵感生成相关的逻辑。虽然这类日志工具可能作为内部支持模块存在,但就该代码片段本身而言,其实际行为与声明的主要用途明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向趋势洞察和内容研究的高层分析型技能,但提供的代码片段只包含底层的输入处理函数:规范化URL、识别小红书笔记/主页链接、以及把URL转换为名称。它没有展示任何趋势抓取、内容分析、热点归纳、营销建议生成或研究流程相关逻辑。虽然这些URL工具可能作为更大系统的辅助组件存在,但就该代码块本身而言,其实际行为与声明的核心用途明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明的核心用途是‘趋势洞察/趋势分析/热点观察/内容方向判断’,这通常意味着对多内容、关键词或主题进行聚合分析与洞察输出。但实际代码并不做趋势分析、热点识别、归纳总结或营销灵感生成;它只是针对单个小红书笔记链接发起评论获取任务,并返回评论数据。虽然评论数据可能是后续趋势分析的输入之一,但当前代码本身的主要功能是评论采集,不是所声明的分析型能力。因此存在明显的描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的核心能力是“趋势洞察/趋势分析/热点观察/营销灵感整理”,这通常意味着对多个内容或数据进行聚合分析、归纳和判断。但实际代码仅处理一个具体的小红书笔记链接,调用 detail API 获取该笔记详情并输出 JSON 结果,没有看到任何趋势分析、聚合统计、热点判断、内容方向推断或营销灵感整理逻辑。因此其主要用途与声明明显不符。代码访问的小红书笔记详情资源与小红书领域相关,但粒度是单条内容详情抓取,不是趋势洞察能力。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明描述强调的是‘趋势洞察/趋势分析/热点观察/营销灵感整理’这类分析型用途,但代码本身并未执行趋势分析、热点归纳、内容方向判断或营销洞察生成。它只是一个面向单个小红书博主主页的采集型 CLI:解析参数、校验主页链接、调用 post.createPostTask/getPostTask 拉取笔记或互动数据,并输出 JSON 结果。因此其主要行为更接近‘获取博主主页内容数据’,而非声明中的‘趋势洞察’能力。虽然这些原始数据可能可被后续用于趋势分析,但该代码块本身没有实现所宣称的核心分析功能,属于描述与实际行为存在实质偏差。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
- "这条小红书笔记评论区在吐槽什么 → node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 200"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
- "这条小红书笔记评论区在吐槽什么 → node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 200"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
- "这条小红书笔记评论区在吐槽什么 → node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 200"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 275)May include surrounding context.

md
- "这条小红书笔记评论区在吐槽什么 → node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 200"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 278)May include surrounding context.

md
- "这条小红书笔记评论区在吐槽什么 → node src/xiaohongshu/comment-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy' --limit 200"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
- "看这个小红书博主最近 30 条作品发什么 → node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 30"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
- "看这个小红书博主最近 30 条作品发什么 → node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 30"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 281)May include surrounding context.

md
- "看这个小红书博主最近 30 条作品发什么 → node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 30"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
- "看这个小红书博主最近 30 条作品发什么 → node src/xiaohongshu/post-cli.js --url 'https://www.xiaohongshu.com/user/profile/xxx?xsec_token=yyy' --limit 30"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
- "分析这篇小红书爆款笔记为什么火 → node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy'"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
- "分析这篇小红书爆款笔记为什么火 → node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy'"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
- "分析这篇小红书爆款笔记为什么火 → node src/xiaohongshu/detail-cli.js --url 'https://www.xiaohongshu.com/explore/xxx?xsec_token=yyy'"

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16