expert-xhs
Audited by Socket on Sep 11, 2026
3 alerts found:
Securityx2AnomalySUSPICIOUS. The skill's core publishing behavior broadly matches its stated purpose, and the only explicit package install (Pillow) is benign. However, it relies on local browser cookie/UA harvesting, undocumented web endpoints, and an unverifiable relay signing service rather than clearly official Xiaohongshu integration paths, making the data flow and trust model harder to justify.
该技能的能力与“小红书运营”目的基本一致,不见明显越权读取无关敏感文件或显式外传到陌生域名,因此不像确认恶意内容。但它依赖不透明的本地封装 CLI、真实登录会话和发布能力,且安装信任链依赖 same-org 远程脚本与打包资产,整体应判为 SUSPICIOUS 而非 BENIGN。
The skill’s scraping purpose is plausible, but its actual footprint is high-risk because it relies on unverifiable external CLIs and forwards local XHS session/cookie files into that toolchain. This is more consistent with a suspicious, high-vulnerability skill than a clean, well-scoped integration.