This skill is a coherent Xiaohongshu automation tool, but it gives a third-party Docker service persistent ability to act on a live social account with weak scoping and no required confirmation steps.
Install only if you trust the Docker image and are comfortable letting it use your Xiaohongshu account. Require the agent to show the exact post or interaction and get approval before publishing, liking, favoriting, or commenting. Run it only on a trusted machine, keep port 18060 local and protected, stop the container when finished, and delete stored cookies in `./data` if you no longer need the session.