xhs-note-creator

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of Playwright and the subsequent download of Chromium browser binaries (playwright install chromium) to support its image rendering features.
  • [CREDENTIALS_UNSAFE]: The skill processes sensitive Xiaohongshu session cookies (XHS_COOKIE). The publish_xhs.py script contains an 'API mode' that transmits these credentials over the network to a configurable XHS_API_URL. While the default is localhost, this capability creates a potential exposure vector for session tokens if the endpoint is redirected or misconfigured.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the following evidence chain:
  • Ingestion points: User-provided materials are ingested and converted into Markdown documents to be used as templates for image generation.
  • Boundary markers: Absent; the rendering pipeline does not use delimiters or instructions to ignore embedded code in the Markdown content.
  • Capability inventory: The skill uses Playwright to open and render HTML in a browser environment and can perform network POST requests to external APIs.
  • Sanitization: Absent; the conversion from Markdown to HTML in scripts/render_xhs.py and scripts/render_xhs.js does not include sanitization, allowing potential XSS payloads to execute within the local headless browser.
  • [COMMAND_EXECUTION]: The SKILL.md instructs the AI agent to execute local Python and Node.js scripts using shell commands to perform the core functions of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:24 AM
Security Audit — agent-trust-hub — xhs-note-creator