xiaohongshu-ops
Fail
Audited by Snyk on Aug 15, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The document explicitly describes automatic browser cookie extraction and scraping/automation tooling (scrapers, downloaders, Playwright-based publishers), which enables credential theft and covert data exfiltration/unauthorized account access.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). last30days 研究引擎在“每日/每周热点抓取流程”里会根据用户下发的“/last30days [研究主题]”去聚合社区讨论与网页搜索内容(Reddit/X/YouTube等),因此外部作者可通过可被该引擎抓取的来源投喂可读文本从而造成间接提示注入风险。
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill invokes and depends on the external plugin/repo "mvanhorn/last30days-skill" (installed via "/plugin marketplace add mvanhorn/last30days-skill" and used at runtime through /last30days commands), which would fetch and execute external plugin code that directly drives agent research outputs.
Issues (3)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata