Back to skill

Security audit

Xiaohongshu Demand Discovery

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Xiaohongshu collection purpose, but it should go through Review because it stores login cookies locally and includes authenticated posting/publishing paths with unsafe edge cases.

Install only if you are comfortable giving the skill access to an authenticated Xiaohongshu browser session. Use a dedicated or low-risk account, keep runs small, restrict permissions on the cookie file, do not share or commit the cookie directory, review local output before reuse, avoid untrusted Markdown with publish-md, and use publishing/comment commands only when you explicitly intend to post under your account.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/client.py:135
Finding

Authentication Cookies Are Persisted in Plaintext Without Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/publish.py:475
Finding

Untrusted Markdown Can Cause Chromium to Make Arbitrary Network Requests

Content
View full analysis
{full_css} {html_content}""" os.makedirs(output_dir, exist_ok=True) from playwright.sync_api import sync_playwright with sync_playwright() as pw: browser = pw.chromium.launch(headless=True) page = browser.new_page(viewport={"width": width, "height": 800}) page.set_content(full_html) page.wait_for_load_state("networkidle") time.sleep(0.5) ``` ### Technical Analysis Python-Markdown permits raw HTML by default. Consequently, attacker-controlled Markdown may include HTML elements that load remote resources, such as images, stylesheets, frames, media, or scripts. When `page.set_content(full_html)` renders that output, Chromium can initiate ...[truncated 2514 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (25)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The reply API claims to reply to a specific comment/user, but reply_user_id is never used to verify or bind the action to the intended target. If locating the target comment fails, the function explicitly falls back to typing into the generic comment box, which can post a top-level comment or reply to the wrong thread, causing unintended actions under the user's authenticated account.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring explicitly characterizes the module as read-only, yet the implementation persists collected data to disk by creating an output directory and writing notes, comments, summary JSON, and a markdown report. This is an active contradiction in the code documentation, not merely an omitted detail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The default keywords are hard-coded Chinese phrases, and the collector also uses Chinese platform-specific values such as Chinese publish-time strings and sort labels elsewhere in the file. This creates a natural-language/locale constraint that is imposed by default rather than offered as a user choice or clearly documented as an opt-in regional mode.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This function collects public notes and comments and persists them to local JSONL files without any user-facing notice or confirmation at the collection entry point. In an agent skill context, silent local storage of scraped third-party content can create privacy, compliance, and data-governance risk because operators may not realize content is being retained on disk, potentially including usernames-derived identifiers, post text, and comment text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and method/class docstrings are entirely in Chinese, with no indication that the skill is region-specific or that users may choose another language. This is a natural-language locale constraint visible in the file and matches the policy-violation category for language/locale requirements without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language documentation and user-facing status messages exclusively in Chinese, beginning with the module docstring. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The stderr messages shown during execution, such as page-opening, retry, comment-loading, and failure notices, are all emitted only in Chinese. Because these are user-visible runtime messages and the file does not offer any language choice or opt-in, they violate the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains natural-language descriptions entirely in Chinese, starting with the module docstring, and provides no indication that the skill is limited to a Chinese-speaking or region-specific context. Under the language/locale policy, forcing a specific language without user opt-in or clear justification is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code includes natural-language documentation and runtime status messages exclusively in Chinese, which can impose a language choice on users without opt-in. The policy specifically calls out language or locale constraints as violations unless the skill offers a choice or clearly documents a justified regional scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code saves authenticated session cookies after detecting a successful login via self.client._save_cookies(), but this file provides no explicit disclosure, consent flow, or safeguards around persistence. In an agent skill context, silently storing reusable auth material can expose accounts if the cookie file is readable by other processes, reused unexpectedly, or left on disk longer than intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code presents its purpose and operational messages entirely in Chinese, including the primary module description and later user-facing status strings, with no indication that language selection is configurable or that the skill is explicitly limited to Chinese-speaking users. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring explicitly claims a safer manual-confirmation publishing model, but both publish_image and publish_video accept auto_publish=True and will click the final publish button with no enforced human checkpoint. This mismatch can mislead operators or downstream agents into assuming a review gate exists when the code is capable of fully automated posting, increasing the risk of unintended or unauthorized content publication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code navigates a browser client to a Xiaohongshu search URL using the user-supplied keyword, which sends the query to an external service. Although the module has docstrings, there is no explicit disclosure here that the action contacts a third-party site and uses the authenticated browser/session context when doing so.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The top-level search helper accepts a cookie_path and constructs a client with it, indicating that stored authentication material may be loaded and used. The file does not include an explicit warning to users that local cookie/session data will be accessed for this operation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill description and usage are presented entirely in Chinese and the examples assume Chinese-language interaction patterns and Chinese Xiaohongshu keyword inputs. The file does not indicate that language choice is optional or that the skill is intentionally limited to Chinese-speaking users, which can conflict with a policy requiring user opt-in for language or locale constraints.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency specification uses a lower-bound constraint (playwright>=1.40.0) instead of pinning an exact version, which makes builds non-reproducible and can pull in unexpected upstream releases. While this is not an immediately exploitable code flaw by itself, it increases supply-chain risk because a compromised or breaking future release could be installed without review.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
playwright>=1.40.0
markdown>=3.5
pytest>=7.0
pytest-mock>=3.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The markdown dependency is not pinned to a specific version, so installations may resolve to different releases over time. This weakens reproducibility and makes it harder to determine whether the environment is affected by known vulnerable versions, increasing supply-chain uncertainty.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
playwright>=1.40.0
markdown>=3.5
pytest>=7.0
pytest-mock>=3.0

Unverifiable Dependency: markdown has 2 known advisory(ies) (CVE-2025-69534 (Python-Markdown has an Uncaught Exception); CVE-2025-69534 (Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like se)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The manifest references markdown without pinning a specific version, and advisories exist for some markdown releases. Because the installed version is unconstrained above the minimum, it is impossible to verify from this file alone whether a vulnerable release could be selected, creating an avoidable supply-chain risk.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The pytest dependency is declared with a minimum version only, allowing newer versions to be installed automatically. This can introduce vulnerable or incompatible releases and prevents reliable auditing of the dependency set.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
playwright>=1.40.0
markdown>=3.5
pytest>=7.0
pytest-mock>=3.0

Unverifiable Dependency: pytest has 2 known advisory(ies) (CVE-2025-71176 (pytest has vulnerable tmpdir handling); CVE-2025-71176 (pytest has vulnerable tmpdir handling)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
86% confidence
Finding

The pytest entry is not pinned, and known advisories exist for some pytest versions. Without an exact version or lockfile, consumers cannot determine whether installation will pull a safe release, leaving security posture ambiguous and potentially unsafe.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

pytest-mock is also unpinned, which contributes to non-deterministic builds and broader supply-chain exposure. Even for test-only packages, unreviewed upstream changes can affect CI behavior, development workflows, or transitive dependency safety.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
playwright>=1.40.0
markdown>=3.5
pytest>=7.0
pytest-mock>=3.0

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring and the command help text throughout the file are written only in Chinese, which establishes a fixed language for user-facing interaction. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless a locale-specific constraint is explicitly documented, which is not present here.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/interact.py (reported line 210)May include surrounding context.

python
try:
        client.start()
        action = InteractAction(client)
        method = getattr(action, action_name)
        return method(feed_id, xsec_token)
    finally:
        client.close()

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module description is written in Chinese, and the file consistently uses Chinese-only user-facing strings and comments. Under the policy rule for language/locale, this is a violation because the skill does not provide any user opt-in or alternative language handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The print statements shown to the user/operator, such as status and error messages, are hard-coded in Chinese throughout this section. The file does not offer a language choice or indicate that a Chinese-only locale restriction is intentional and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.