Back to skill

Security audit

检测并优化AI生成的小红书文案,去除机械感和模板化表达,增加真人口语化和情感化表达,让内容更自然、更有温度。适用于已有AI生成文案但希望提升真实感的场景。

Security checks for vulnerabilities and agentic risk

Overview

The skill performs the advertised text humanization, but it ships a reusable bearer token and can send that token and user text to a configurable remote endpoint.

Review carefully before installing. Do not submit confidential, regulated, or secret-containing text unless you trust the xiaonian.cc Dashboard service and its data handling. The publisher should remove and rotate the embedded token, require user-supplied credentials, restrict authenticated requests to trusted HTTPS hosts, and add a clear upload/privacy warning.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/humanize.py:28
Finding

Hard-Coded Bearer Token Exposes Dashboard API Credentials

Content
View full analysis
Tuple[Optional[str], Optional[str]]: """Return (token, source)""" token = os.getenv("DASHBOARD_TOKEN") or DEFAULT_TOKEN if token: return token, "env:DASHBOARD_TOKEN" ``` ### Technical Analysis The source code contains a bearer token that appears intended to authenticate requests to the Dashboard API. Every person or system with access to the Skill package can extract and reuse this token independently of the script. Because `_get_token()` selects the environment token or the hard-coded default before considering phone/password login, the embedded credential is used automatically whenever `DASHBOARD_TOKEN` is absent. The default token also makes the subsequent login fallback unreachable under the distributed configuration. Bearer tokens confer access based on possession. There is no additional proof that the caller is an authorized installation or user. ### Attack Path 1. An attacker downloads or otherwise obtains access to the Skill package. 2. The attacker opens `scripts/humanize.py` and extracts `DEFAULT_TOKEN`. 3. The attacker constructs requests with an `Authorization: Bearer ` header. 4. The attacker sends requests directly to the Dashboard API outside the intended Skill workflow. 5. The API processes those requests under the identity and authorization scope associated with the embedded token, provided it remains valid. ### Impact Assessment An attacker may obtain all API privileges assigned to the exposed token. Depending on server-side authorization, this can include unauthorized use of the humanization service, consumption of quotas or paid resources, activity attribution to the token owner, and access t ...[truncated 276 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/humanize.py:85
Finding

Unrestricted Base URL Override Can Exfiltrate the Bearer Token and User Content

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/humanize.py:114
Finding

Sensitive User Documents Are Uploaded Without a Clear Privacy Warning or Confirmation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose is harmless text humanization, but the associated behavior includes built-in authenticated access, token handling, and undisclosed authorization against employee/dashboard APIs. That mismatch is dangerous because reviewers and users may trust the skill with sensitive content without realizing it can act with privileged backend access and potentially reach internal resources.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises 'no configuration needed' while invoking a script with network, file-read, and environment access, but it does not declare any tool scope or permissions boundary. This weakens reviewability and consent, making it easier for a seemingly simple text-editing skill to exfiltrate input, consume hidden credentials, or perform unexpected external actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill tells users to pipe content directly into a script and says authentication is built in, but it does not clearly warn that user text is transmitted to a backend API under existing credentials. In a humanization/editing context, users are especially likely to submit drafts, internal documents, or sensitive business text, so lack of disclosure creates meaningful confidentiality and consent risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script contains a hard-coded bearer token and will use it by default whenever DASHBOARD_TOKEN is not set. Embedding credentials in code is dangerous because anyone with access to the skill can reuse the token to call the backend, potentially access protected services, and cause unauthorized usage or billing without the operator's consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The --language argument defaults to Simplified Chinese, which imposes a specific language choice unless the user overrides it manually. The file does not document a justified region-specific requirement or provide an explicit opt-in flow, so this is a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script transmits full user-provided content to a remote service for processing but gives no explicit user-facing notice at execution time that data will leave the local environment. This creates a privacy and data-handling risk, especially if users pass sensitive drafts, internal documents, or regulated content under the assumption the transformation is local.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation states the language default is Simplified Chinese, which sets a specific language/locale behavior by default. The file does not indicate that users are offered a language choice or that this locale restriction is justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The request schema specifies language: "Simplified Chinese" // default, which imposes a locale/language default in the API documentation without indicating user choice or opt-in. Under the policy, language constraints should either be optional with user selection or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.