Back to skill

Security audit

Rednote Creator

Security checks for vulnerabilities and agentic risk

Overview

This is a RedNote/Xiaohongshu content creation skill with disclosed image-generation and optional posting features, and no evidence of hidden or malicious behavior.

Install only if you want an assistant that can generate RedNote/Xiaohongshu drafts, create or fetch cover images, and optionally help publish through a browser session. Review all generated text and images before posting, prefer your own photos for originality claims, and only allow the browser publishing step when you are ready for the post to go live.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Broad trigger phrases like everyday requests to 'write/post Xiaohongshu' increase the chance of accidental invocation in unrelated conversations. Because this skill includes image handling and optional browser-based publishing, unintended activation could escalate from harmless style guidance into external actions the user did not mean to initiate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill mandates a fixed voice and persona, including speaking like a Xiaohongshu blogger and using a ‘girly friend-chat’ tone, rather than offering this as an optional style. This is a natural-language policy concern because it imposes a specific language/register choice on all users without opt-in or accommodation for different preferences.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The fallback directs the agent to fetch third-party images from Unsplash/Pexels and save them locally, which expands the skill from content drafting into external network/file operations. That creates licensing/compliance risk, provenance confusion, and a path for unintended handling of untrusted remote content on disk, even though the text warns users these images are poor for originality review.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

One-click posting through a browser agent gives the skill account-affecting automation capability beyond passive content assistance. Even with a confirmation step, this can perform authenticated actions in a user's Xiaohongshu session, so prompt confusion or unsafe invocation could lead to unintended publication or misuse of browser privileges.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The documentation later states '不生成虚假效果对比图(如伪造Before & After)' as a hard constraint, yet earlier sections promote 'Before & After 对比图' and '减肥前后对比图' as ideal cover directions. This creates intent ambiguity in the documentation because the recommended format overlaps with the prohibited deceptive variant without clarifying that only genuine user-supplied comparisons are allowed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The later constraints prohibit fabricated comparison imagery, but the fitness section markets '减肥前后对比图(最暴力涨粉)' as a recommended cover style. Because the recommendation does not specify that only truthful, user-owned progress photos are permitted, the documentation sends conflicting signals about acceptable behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.