Back to skill

Security audit

Xiaohongshu Assistant Operator

Security checks across malware telemetry and agentic risk

Overview

This skill is transparent about automating one Xiaohongshu creator account, but it can publish posts and interact publicly without clear approval or stop controls.

Install only if you are authorized to operate the named Xiaohongshu account. Use draft or preview mode unless you add explicit approval before each post and comment, set clear limits and a stop mechanism for scheduled cycles, and review any separately supplied helper script before running it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly describes fully automated content publishing and scheduled comment interaction on a real external account, but it does not present a clear user-facing warning or confirmation boundary before taking those actions. In an agent setting, this can cause unintended posts, reputation damage, platform-policy violations, or misuse of a third party's account if the skill is invoked in the wrong context.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The manual trigger section instructs the agent to immediately execute a full daily cycle, publish 3 posts, and run interaction activity without any explicit confirmation or warning to the user. That makes accidental invocation especially dangerous because a single trigger could immediately perform irreversible external actions at scale on the linked Xiaohongshu account.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The template hard-requires Chinese identity text and a specific handle in every generated post, with no user choice, locale fallback, or opt-in. This creates unauthorized attribution and forced branding behavior that can override user intent, reduce transparency, and cause the agent to emit unwanted promotional or identity-bearing content in contexts where it is inappropriate.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.