xiaohongshu-images

Warn

Audited by Socket on Aug 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core local HTML/screenshot behavior is coherent and mostly benign, and Playwright install steps are official. However, the skill depends on an unverified external /baoyu-cover-image skill and forwards article content to it, creating a transitive trust boundary that is not auditable from this skill alone; URL ingestion also adds prompt-injection risk. No confirmed malware or credential theft is shown, but the dependency and trust model raise medium risk.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:45 AM
Package URL
pkg:socket/skills-sh/iamzifei%2Fxiaohongshu-images-skill%2Fxiaohongshu-images%2F@0d4eeba9771d02a27e157c080d4593b48e847891
Security Audit — socket — xiaohongshu-images