xiaohongshu-account-recommender

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s general purpose is plausible, but its real data flow is misaligned: instead of using an official Xiaohongshu API, it sends queries to an unrelated third-party domain with unusual no-SNI manual HTTPS behavior. Local report generation is proportionate, but the external endpoint and transport design make the overall skill medium-high risk.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
May 15, 2026, 11:02 PM
Package URL
pkg:socket/skills-sh/redfox-data%2Fredfox-community%2Fxiaohongshu-account-recommender%2F@cbed669eb9f5244a9510e747934147ba285285db
Security Audit — socket — xiaohongshu-account-recommender