Back to skill

Security audit

小红书热门账号推荐

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Xiaohongshu ranking/reporting tool with an API key, report files, and optional subscriptions that fit its stated purpose.

Before installing, confirm you trust RedFoxHub with your REDFOX_API_KEY and queries. Expect the skill to call the RedFox API, write HTML reports in the workspace, and optionally create recurring subscription automation or calendar entries if you ask for ongoing delivery.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill requires network access, reads an API key from environment variables, and writes local report files, yet declares no permissions or equivalent user-visible capability disclosure. This is dangerous because it obscures sensitive operations from users and platform policy checks, increasing the chance of silent exfiltration, unintended file creation, or overprivileged execution.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The skill description frames the tool as a ranking query utility, but the instructions also direct calls to external third-party services, local JSON/HTML report generation, and inclusion of an external CDN script in generated HTML. This mismatch is dangerous because users may consent to a simple lookup while the skill performs broader data handling and loads remote code in reports, which can introduce supply-chain, privacy, and content integrity risks.

Intent-Code Divergence

Medium
Confidence
87% confidence
Finding
The subscription flow gives contradictory instructions by first directing one automation mechanism and later instructing use of a calendar-creation tool. Ambiguous automation semantics are risky because the agent may create a persistent task or calendar event the user did not clearly authorize, or create the wrong kind of persistence with unexpected ongoing notifications.

Vague Triggers

Medium
Confidence
86% confidence
Finding
Broad trigger phrases for report generation can cause the skill to generate and save HTML artifacts for ordinary conversational requests that merely mention downloading or reporting. This is dangerous because it can lead to unintended file creation, attachment delivery, and potentially loading externally sourced report content without sufficiently specific user intent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The subscription triggers are overly broad and can match everyday language like '每天发给我' or '订阅…' without making clear that a persistent scheduled action will be created. This is dangerous because users may accidentally authorize ongoing automation, causing repeated external calls, notifications, or calendar/task creation beyond their expectations.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to create automated subscriptions or calendar entries without first clearly warning the user that a persistent scheduled task or event will be created. Hidden persistence is dangerous because it can surprise users with recurring actions, repeated third-party API access, and ongoing notifications, all of which extend the impact beyond a one-time query.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.