xiaohongshu-ops

Warn

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install a third-party plugin from a public marketplace via the command /plugin marketplace add mvanhorn/last30days-skill. This introduces a supply chain risk, as the plugin is hosted under an unverified user account. It also recommends installing yt-dlp for media handling.
  • [COMMAND_EXECUTION]: The documentation encourages the use of local automation tools such as xhs_ai_publisher (Playwright-based) and Autoxhs for automated content publishing. These involve running scripts that interact with the host system and external web interfaces.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of fetching data from untrusted external sources.
  • Ingestion points: Social media content fetched from Reddit, X (Twitter), TikTok, Instagram, and YouTube via the /last30days tool.
  • Boundary markers: None documented to prevent the agent from following instructions embedded in the scraped content.
  • Capability inventory: Generates content strategies, titles, and image prompts based on the fetched data.
  • Sanitization: No evidence of sanitization or filtering of external input before it is processed by the LLM.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 15, 2026, 03:23 AM
Security Audit — agent-trust-hub — xiaohongshu-ops