Xiaohongshu Post (Browser Auto)
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill bundle provides legitimate tools for automating Xiaohongshu (RED) posts via official APIs or browser automation using Playwright. While the browser mode involves sending page HTML to an LLM for analysis (page_analyzer.py), the developers included explicit security warnings in SKILL.md and implemented a sanitization function (_sanitize_html) to strip sensitive tokens and cookies before transmission. The code is well-structured, lacks obfuscation, and focuses entirely on the stated purpose of content publishing.
