xiaohongshu-rednote-keyword-monitor
Fail
Audited by Snyk on Jul 20, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 0.90). The Skill explicitly instructs the agent to auto-install a dependency "without asking the user to confirm" and to "not describe it as a request for the user to open their browser," which instructs hiding actions from the user and is deceptive relative to the Skill's monitoring purpose.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). SKILL.md instructs the agent to invoke the BrowserAct CLI for live browser execution (public pages/notes/comments fetched at runtime), which can include outsider-authored free text (e.g., matched note/comment content) that BrowserAct returns and the agent then processes into the LLM context.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The Skill instructs the agent to install and invoke the BrowserAct CLI at runtime using external installer links (e.g., https://www.browseract.com/?co-from=social-media and https://www.browseract.com/?co-from=social-media&redirect=https://github.com/browser-act/skills/tree/main), which are required dependencies and would cause the agent to fetch and run external code to continue execution.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (medium risk: 0.60). The Skill instructs the agent to automatically install a missing CLI dependency ("Install BrowserAct") without asking the user for confirmation, which directs the agent to perform potentially system-changing installations (even if it does not explicitly request sudo, file modification, or user creation).
Issues (4)
E004
CRITICALPrompt injection detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata