Back to skill

Security audit

开源小红书技能

Security checks for vulnerabilities and agentic risk

Overview

This Xiaohongshu skill is coherent and purpose-aligned, but users should handle account credentials, private messages, publishing, deletion, and blocking actions carefully.

Install only if you intend to let an agent help manage a Xiaohongshu account. Before any publish, delete, block, private-message, profile, or account-binding action, require explicit confirmation and verify the target account, note ID, comment ID, and scope. Treat messages, comments, analytics, and credentials as private data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly advertises destructive actions such as deleting notes, deleting comments, and blacklist management, but does not warn users that some operations may be irreversible or affect live account content. In an account-management skill, this increases the risk of accidental or overly broad destructive actions, especially when batch operations are supported.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill includes access to private messages, comments, and account analytics, but does not disclose privacy implications, consent expectations, or handling requirements for personal data. Because this is a social-media account skill, operators may access sensitive user communications and behavioral data without adequate warning or policy guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file lists operations such as deleting notes and comments, blocking users, and unbinding accounts, but provides no warning that these actions may be destructive, user-impacting, or hard to reverse. Under the markdown-specific SQP-2 criteria, descriptions of behaviors affecting user data or account state should disclose such risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The document presents all guidance exclusively in Chinese, and there is no indication that users can opt into another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the language/locale policy, forcing a specific language without user opt-in can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language content and examples are entirely in Chinese, and the file does not indicate that users may choose another language or that the skill is intentionally restricted to a Chinese-language audience for a documented reason. This can constitute a language-policy issue under the locale-choice rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The entire skill reference is written only in Chinese and does not indicate that language selection is optional or that the skill is intentionally restricted to a Chinese-speaking or region-specific context. This can constitute a natural-language locale policy issue when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The heading publish_note indicates an action to publish a note, but the description says 发布已发布的笔记 ('publish an already published note'), which is internally contradictory. This is an intent/documentation mismatch that could mislead users of the skill about whether the API publishes drafts or re-publishes existing content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.