xiaohongshu-mcp-integration

Warn

Audited by Socket on May 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated Xiaohongshu automation purpose, but its footprint is high-risk: it installs and runs third-party upstream binaries/containers from a different publisher than the skill author, stores authenticated session state, accesses local media, and enables autonomous public posting and engagement. This is not confirmed malware, but it is a materially risky automation skill that should only be used with strong user oversight and preference for source build or pinned verified artifacts.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
May 16, 2026, 04:24 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Fxiaohongshu-mcp-integration%2F@4725181c897330d5d35d67c3cfcfdda7ac9e269e
Security Audit — socket — xiaohongshu-mcp-integration