xhs-note-creator
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of Playwright and the subsequent download of Chromium browser binaries (
playwright install chromium) to support its image rendering features. - [CREDENTIALS_UNSAFE]: The skill processes sensitive Xiaohongshu session cookies (
XHS_COOKIE). Thepublish_xhs.pyscript contains an 'API mode' that transmits these credentials over the network to a configurableXHS_API_URL. While the default islocalhost, this capability creates a potential exposure vector for session tokens if the endpoint is redirected or misconfigured. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the following evidence chain:
- Ingestion points: User-provided materials are ingested and converted into Markdown documents to be used as templates for image generation.
- Boundary markers: Absent; the rendering pipeline does not use delimiters or instructions to ignore embedded code in the Markdown content.
- Capability inventory: The skill uses Playwright to open and render HTML in a browser environment and can perform network POST requests to external APIs.
- Sanitization: Absent; the conversion from Markdown to HTML in
scripts/render_xhs.pyandscripts/render_xhs.jsdoes not include sanitization, allowing potential XSS payloads to execute within the local headless browser. - [COMMAND_EXECUTION]: The
SKILL.mdinstructs the AI agent to execute local Python and Node.js scripts using shell commands to perform the core functions of the skill.
Audit Metadata