write-xiaohongshu

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The research-and-writing purpose is coherent, and Firecrawl usage is broadly consistent, but the publishing path relies on a non-official Xiaohongshu MCP with third-party login/session handling and download-execute installation. That makes the skill’s actual trust footprint disproportionate for a publishing workflow and creates high supply-chain and credential-forwarding risk, even though it waits for user confirmation before posting.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
Sep 16, 2026, 04:17 AM
Package URL
pkg:socket/skills-sh/adjfks%2Fcorner-skills%2Fwrite-xiaohongshu%2F@bbb25d314836aa5e47dd349982063e747f872deb8f2e3fbbc6cac452f1710f49
Security Audit — socket — write-xiaohongshu