Back to skill

Security audit

小红书热门账号推荐

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Xiaohongshu ranking purpose, but its generated HTML reports can run unsafe web content, so users should review it before installing.

Install only if you trust RedFox with the API key and are comfortable with local report files and scheduled pushes. Treat generated HTML reports as active web pages: open them cautiously, avoid using reports built from untrusted JSON/API data, and be aware they may contact a third-party CDN when opened.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_report.py:532
Finding

Stored HTML and URI-Scheme Injection in Generated Reports

Content
View full analysis
{rank} {account_name} {score} {followers} {new_notes} {new_fans} {new_likes}
Remediation
View remediation
str: return html_utils.escape(str(value), quote=True) ``` 2. Parse metric fields into strict numeric types before formatting. Reject values that are not valid integers, decimals, or supported numeric suffixes instead of preserving arbitrary strings. 3. Validate profile URLs with `urllib.parse.urlparse` and enforce an explicit allowlist: ```python from urllib.parse import urlparse def safe_profile_url(value: str) -> str: parsed = urlparse(value) if ( parsed.scheme == "https" and parsed.hostname in {"www.xiaohongshu.com", "xiaohongshu.com"} and parsed.path.startswith("/user/profile/") ): return html_utils.escape(value, quote=True) return "#" ``` 4. Explicitly reject `javascript:`, `data:`, `file:`, and other non-HTTPS schemes. 5. Escape top-level values such as `category_label`, `date_str`, and `fetch_time` before inserting them into `HTML_TEMPLATE`. 6. Add a restrictive Content Security Policy. If inline JavaScript remains necessary, use a nonce or hash rather than broadly permitting inline execution. 7. Add regression tests containing HTML tags, quotes, event handlers, and unsafe URI schemes in every externally derived field. ]]>

T03 · Remote Payload Retrieval and Execution

Warning
Location
scripts/generate_report.py:408
Finding

Generated Reports Retrieve and Execute Third-Party JavaScript Without Integrity Verification

Content
View full analysis
``` ### Technical Analysis Every generated HTML report contains a script reference to a third-party CDN. When a user opens the report with network access, the browser downloads and executes the remote `html2canvas` resource. The dependency version is pinned, which reduces accidental version drift, but the report does not provide a Subresource Integrity hash. It also lacks a Content Security Policy restricting script origins and other outbound connections. The effective executable code can therefore differ from the code reviewed in this Skill package if the CDN, package artifact, distribution path, or associated infrastructure is compromised. This also means the supposedly local report makes an external network request when opened. That behavior is not required for viewing the rankings or exporting them through the browser's print-to-PDF functionality. ### Attack Path 1. An attacker compromises the hosted package artifact, its CDN distribution channel, or another component capable of changing the response at the referenced URL. 2. The Skill generates and delivers an HTML report containing the remote script reference. 3. The user opens the report while connected to the network. 4. The browser retrieves the modified JavaScript from the CDN. 5. The malicious JavaScript executes with access to the generated report's DOM and normal browser capabilities available to scripts in that document. ### Impact Assessment A compromised dependency could: - Read and modify all ranking information displayed in the report. - Replace the report with phishing or deceptive content. - Issue outbound network requests and disclose report data. - Redirect users or create maliciou ...[truncated 332 chars]
Remediation
View remediation
``` 3. Verify the integrity hash against an independently obtained, trusted release artifact before deployment. 4. Add a restrictive Content Security Policy limiting scripts to the exact approved source. Prefer nonce- or hash-based authorization for the report's inline script. 5. Document that opening the report performs a third-party network request and provide an offline-report option. 6. Consider removing the image-export dependency entirely if print-to-PDF and ordinary browser screenshots sufficiently satisfy the declared report-export functionality. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/generate_report.py (reported line 144)May include surrounding context.

python
for rule in CATEGORY_INFER_RULES:
        for kw in rule["keywords"]:
            if kw.lower() in combined:
                return rule["category"]

    # 3. 兜底关键词
    for category, keywords in FALLBACK_KEYWORDS.items():

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README says users can simply describe requests in natural language with 'no commands to memorize,' but it does not define clear activation boundaries or permitted actions. In an agent setting, overly broad natural-language triggering can cause the skill to act on ambiguous or indirectly phrased requests, increasing the risk of unintended data retrieval, report generation, or subscription setup.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs the agent to use environment secrets, make external network requests, write HTML files, and deliver attachments, but it declares no explicit tool scope or permissions boundary. This increases the chance of unintended tool access, broader-than-necessary execution, and secret exposure through over-privileged runtime behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly generates HTML reports and delivers them as attachments, but it provides no warning that data will be written to disk and shared as a file artifact. This creates data-residency and inadvertent disclosure risk, especially if user queries or API-returned content are embedded in the report or retained in the workspace.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Overly broad trigger phrases can cause the skill to activate on casual language and perform external API calls, generate files, or start subscription-related flows without sufficiently specific user intent. In this skill, accidental activation is more concerning because the documented behavior includes network access, file generation, and proactive follow-up prompts.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

L111-L115 的日期计算写明月榜取“每月1日”,而 L301 与 L354 又写成月榜参数必须使用 YYYY-MM-02,例如 2026-04-02。对于同一 rankDate 规则,文档给出了互相冲突的值,这会直接影响技能查询到的数据是否与描述一致。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

L173-L177 明确要求用 automation_update 创建自动化订阅任务,但 L214-L221 又写成用户回复“需要订阅”时使用 calendar_create 创建日程。这不是单纯信息不完整,而是对同一“定时订阅”能力给出了相互冲突的实现指令,容易导致技能实际行为从自动化推送退化为普通日历事件创建。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

L187-L239 的标准输出模板以及全文触发词、订阅文案均固定为中文,且包含“必须按以下顺序输出”等强制性要求,没有说明可根据用户语言偏好切换。根据规则,强制特定语言而未提供 opt-in 或合理地域限定,属于自然语言政策问题。

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api_docs.md (reported line 200)May include surrounding context.

md
"source": "小红书指数榜-ClawHub"
}

resp = requests.post(url, json=payload_day, timeout=15)
data = resp.json()

if data["code"] == 2000:        # 注意:成功码是 2000

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains natural-language documentation and examples exclusively in Chinese, and later user-facing help/output strings follow the same pattern. Under the policy, forcing a specific language without giving the user a language or locale choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function documentation states '月榜:每月 2号 9:00 更新', which directly conflicts with the actual code path that checks 'now.day == 1' and comments '每月 1日 9:00 更新'. This is an active contradiction in intent/documentation that could mislead developers and users about when 'latest' monthly data becomes available.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings that force a specific language and locale, including the module docstring and all generated report text in Chinese. Under the policy, language constraints should either be optional for the user or explicitly documented as a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The feature description advertises 'hands-free subscriptions' and scheduled pushes without clearly warning that enabling this creates ongoing notifications. Users may unintentionally enroll in recurring pushes, leading to persistent unsolicited messages, confusion, or notification fatigue, especially if activation is done through casual natural-language requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README content, examples, and usage guidance are all presented only in Chinese, which can amount to a language/locale policy issue when no user opt-in or alternative language option is provided. The document does not state that the skill is region-specific or limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The document title and all operational instructions are written entirely in Chinese, with no indication that another language is available or that the language choice is optional. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes a tool for querying and analyzing Xiaohongshu daily/weekly/monthly top-account rankings and hot accounts. In addition to fetching and presenting rankings, the code can write JSON output files and generate HTML reports on disk, and its user-facing output promotes subscription-style follow-up actions; these are extra behaviors not conveyed by the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.