Back to skill

Security audit

AI Content — Xiaohongshu Content Production

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent, but its setup instructions ask users to run an unpinned external project with Docker and npm, which needs careful review before installation.

Install only in an isolated development environment after reviewing the upstream repository, Docker Compose file, npm scripts, dependency lockfiles, and container images. Pin a reviewed commit or release before running it, avoid putting administrator passwords on the command line, and do not add real API keys or account-connected publishing credentials until you understand what data the app stores and sends to model providers or other services.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:57
Finding

Unpinned Remote Project Retrieval and Execution

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:71
Finding

Administrator Password Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
cd ai-content

# 2. 配置环境变量
cp backend/.env.example backend/.env
cp frontend/.env.example frontend/.env.local

# 3. 启动数据库与 Redis

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
# 2. 配置环境变量
cp backend/.env.example backend/.env
cp frontend/.env.example frontend/.env.local

# 3. 启动数据库与 Redis
docker compose up -d

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill promotes automated collection, AI processing, and multi-platform content workflows but does not warn users that scraped data, prompts, or account-related content may be transmitted to third-party model providers or external services. In this context, the missing disclosure increases the risk of privacy leakage, compliance issues, and unintended account-impacting actions if users supply sensitive materials or configure publishing-related integrations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger list is excessively broad and includes generic phrases such as content collection, material management, topic mining, and article templates, which can cause accidental activation in unrelated conversations. In an agent environment, overbroad matching can route benign user requests into a workflow that performs scraping, data processing, or other higher-risk actions without clear user intent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The capability boundary states '直接发布到小红书(需手动复制发布)' and '微信公众号直连发布' are not supported, framing the skill as content creation and planning only. However, the rest of the file describes a full application stack with backend services, database initialization, admin bootstrap, and '发布管理'/'定时发布' workflow, which suggests operational publishing-management functionality beyond simple prompt/content assistance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.