xiaohongshu-post-generator
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's core purpose matches social-post generation, but its actual data flow relies on a third-party DeepNLP/OneKey gateway that receives the API key, prompts, images, and design data instead of using first-party service APIs directly. Install trust is moderate rather than extreme because the CLI is vendor-documented and npm-published, but the proxy-centered architecture and credential forwarding make the overall risk medium-high.
Confidence: 88%Severity: 72%
Audit Metadata