write-xiaohongshu
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The research-and-writing purpose is coherent, and Firecrawl usage is broadly consistent, but the publishing path relies on a non-official Xiaohongshu MCP with third-party login/session handling and download-execute installation. That makes the skill’s actual trust footprint disproportionate for a publishing workflow and creates high supply-chain and credential-forwarding risk, even though it waits for user confirmation before posting.
Confidence: 88%Severity: 84%
Audit Metadata