write-xiaohongshu

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data by searching for top-performing posts and analyzing user comments on Xiaohongshu (Steps 1 and 2). It also uses Firecrawl to fetch background information from the web (Step 3). This creates a surface for indirect prompt injection, where malicious instructions embedded in social media content or web pages could attempt to influence the agent's output.
  • Ingestion points: Xiaohongshu post content, comment sections, and web content fetched via Firecrawl.
  • Boundary markers: The instructions do not define strict delimiters for the data returned by tools.
  • Capability inventory: The skill has read capabilities (Xiaohongshu search, Firecrawl) and write capabilities (Xiaohongshu publishing).
  • Sanitization: No explicit sanitization or filtering of the ingested content is mentioned.
  • Mitigation: The risk is significantly mitigated by Step 6, which requires explicit user confirmation ('确认' or '发布') before any content is published.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to find and use images from external web sources such as Pexels or Unsplash (Step 5) and uses Firecrawl MCP to retrieve data from arbitrary URLs (Step 3).
  • [COMMAND_EXECUTION]: The skill coordinates actions across multiple external tools (Xiaohongshu MCP and Firecrawl MCP) to perform its primary functions, including account status checks and content publishing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:17 AM
Security Audit — agent-trust-hub — write-xiaohongshu