xhs-note-creator
Fail
Audited by Snyk on May 18, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). The skill's publish step requires a Xiaohongshu cookie and explicitly tells the agent to set XHS_COOKIE or read the cookie from memory (memory/xhs-cookie.md), which encourages the agent to retrieve and embed a secret cookie value into commands or files—creating an exfiltration risk if the LLM outputs it verbatim.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata