xiaohongshu-images
Warn
Audited by Socket on Aug 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core local HTML/screenshot behavior is coherent and mostly benign, and Playwright install steps are official. However, the skill depends on an unverified external /baoyu-cover-image skill and forwards article content to it, creating a transitive trust boundary that is not auditable from this skill alone; URL ingestion also adds prompt-injection risk. No confirmed malware or credential theft is shown, but the dependency and trust model raise medium risk.
Confidence: 84%Severity: 72%
Audit Metadata