T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:29- Finding
Unnecessary Collection of an Authenticated Session Cookie
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill asks for a live Xiaohongshu session cookie and advertises real scraping, but the inspected code only generates demo reports and does not use the credential.
Review carefully before installing. Do not provide a Xiaohongshu Cookie unless the skill is updated to clearly implement authenticated scraping, explain exactly how the credential is used, and protect it appropriately. Expect the current artifact to produce demo markdown reports rather than verified live Xiaohongshu data.
SKILL.md:29Unnecessary Collection of an Authenticated Session Cookie
fetcher.py:114Unconditional Promotional Content Injected into Generated Reports
The skill description does not accurately match the documented/observed behavior: it claims live Xiaohongshu scraping and hot-search monitoring while analysis indicates simulated data, extra report/export behavior, and unrelated marketing content. Behavior-description mismatch is dangerous because it undermines trust boundaries, making it harder for users and platform controls to assess what the skill actually does and whether it handles data safely.
The skill advertises output to a local file (./xiaohongshu-data.xlsx) but does not declare any explicit tool scope or permissions for file writing. In an agent ecosystem, undeclared file-write capability weakens least-privilege controls and can lead users or reviewers to underestimate what the skill may modify on disk.
The skill instructs users to extract and provide their Xiaohongshu session cookie, which is effectively an authentication credential that can grant account access if exposed. Although it says '不要泄露 Cookie', it does not clearly communicate the severity of session hijacking risk, safe handling requirements, or safer alternatives, so users may paste a highly sensitive secret into insecure contexts.
The module docstring presents the skill name, functionality, and caution text only in Chinese. This imposes a specific language on users without any indication that other languages are supported or that Chinese is a documented requirement.
The skill description says it performs 小红书数据抓取, 笔记数据/博主分析/热搜词监控, which implies real collection and monitoring functionality. In this file, the implemented fetch/search functions return static mock data and generated results, so the actual behavior does not match the claimed operational capability.
The main user interaction flow prints all headings, prompts, status messages, and feature descriptions in Chinese only. For an all-file-types language policy check, this is a locale/language constraint without user opt-in or an explicit justified regional limitation.
The docstring asserts a policy-level behavior—only collecting public data and complying with platform rules. However, the code is purely a demo implementation with no checks, validation, or enforcement logic for data visibility or platform-rule compliance, so the documentation overstates what the code guarantees.
This markdown file uses Chinese throughout, including the title and table headers, with no indication that the user can choose another language or locale. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.
This markdown file uses a single fixed language throughout and does not state that the skill is Chinese-only, region-specific, or user-selectable. Under the language/locale policy check, forcing one language without opt-in can be a natural-language policy issue.
No suspicious patterns detected.