xiaohongshu-ops
Warn
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install a third-party plugin from a public marketplace via the command
/plugin marketplace add mvanhorn/last30days-skill. This introduces a supply chain risk, as the plugin is hosted under an unverified user account. It also recommends installingyt-dlpfor media handling. - [COMMAND_EXECUTION]: The documentation encourages the use of local automation tools such as
xhs_ai_publisher(Playwright-based) andAutoxhsfor automated content publishing. These involve running scripts that interact with the host system and external web interfaces. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of fetching data from untrusted external sources.
- Ingestion points: Social media content fetched from Reddit, X (Twitter), TikTok, Instagram, and YouTube via the
/last30daystool. - Boundary markers: None documented to prevent the agent from following instructions embedded in the scraped content.
- Capability inventory: Generates content strategies, titles, and image prompts based on the fetched data.
- Sanitization: No evidence of sanitization or filtering of external input before it is processed by the LLM.
Audit Metadata