Back to skill

Security audit

Xiaohongshu Data

Security checks for vulnerabilities and agentic risk

Overview

The skill asks for a live Xiaohongshu session cookie and advertises real scraping, but the inspected code only generates demo reports and does not use the credential.

Review carefully before installing. Do not provide a Xiaohongshu Cookie unless the skill is updated to clearly implement authenticated scraping, explain exactly how the credential is used, and protect it appropriately. Expect the current artifact to produce demo markdown reports rather than verified live Xiaohongshu data.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:29
Finding

Unnecessary Collection of an Authenticated Session Cookie

Content
View full analysis
Remediation
View remediation

other

Note
Location
fetcher.py:114
Finding

Unconditional Promotional Content Injected into Generated Reports

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill description does not accurately match the documented/observed behavior: it claims live Xiaohongshu scraping and hot-search monitoring while analysis indicates simulated data, extra report/export behavior, and unrelated marketing content. Behavior-description mismatch is dangerous because it undermines trust boundaries, making it harder for users and platform controls to assess what the skill actually does and whether it handles data safely.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

The skill advertises output to a local file (./xiaohongshu-data.xlsx) but does not declare any explicit tool scope or permissions for file writing. In an agent ecosystem, undeclared file-write capability weakens least-privilege controls and can lead users or reviewers to underestimate what the skill may modify on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users to extract and provide their Xiaohongshu session cookie, which is effectively an authentication credential that can grant account access if exposed. Although it says '不要泄露 Cookie', it does not clearly communicate the severity of session hijacking risk, safe handling requirements, or safer alternatives, so users may paste a highly sensitive secret into insecure contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring presents the skill name, functionality, and caution text only in Chinese. This imposes a specific language on users without any indication that other languages are supported or that Chinese is a documented requirement.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description says it performs 小红书数据抓取, 笔记数据/博主分析/热搜词监控, which implies real collection and monitoring functionality. In this file, the implemented fetch/search functions return static mock data and generated results, so the actual behavior does not match the claimed operational capability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The main user interaction flow prints all headings, prompts, status messages, and feature descriptions in Chinese only. For an all-file-types language policy check, this is a locale/language constraint without user opt-in or an explicit justified regional limitation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The docstring asserts a policy-level behavior—only collecting public data and complying with platform rules. However, the code is purely a demo implementation with no checks, validation, or enforcement logic for data visibility or platform-rule compliance, so the documentation overstates what the code guarantees.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file uses Chinese throughout, including the title and table headers, with no indication that the user can choose another language or locale. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file uses a single fixed language throughout and does not state that the skill is Chinese-only, region-specific, or user-selectable. Under the language/locale policy check, forcing one language without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.