xiaohongshu
Warn
Audited by Socket on Mar 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s core purpose is coherent, but it combines third-party code execution from an unrelated GitHub repo with autonomous public posting and engagement actions through a logged-in browser profile. The main concerns are supply-chain trust and high-risk real-world actions, not confirmed malware or credential theft.
Confidence: 89%Severity: 76%
Audit Metadata