小红书长图文发布

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent publishing helper, but it gives an agent control of a logged-in Xiaohongshu browser session and publishes publicly without a required final confirmation.

Install only if you are comfortable letting an agent operate a logged-in Xiaohongshu creator account. Use a dedicated OpenClaw browser profile with no unrelated sessions, review the active account and full post preview yourself, and require explicit confirmation before the agent clicks publish.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent/user to click the final publish button and complete submission to a real Xiaohongshu account, but it does not include a clear confirmation gate or warning that this is an externally visible, potentially irreversible action. In the context of browser automation against a logged-in social media account, this increases the risk of accidental public posting, reputational harm, and unintended use of the account.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal