Back to skill

Security audit

Xiaohongshu Search Full

Security checks across malware telemetry and agentic risk

Overview

This skill is a logged-in Xiaohongshu scraping workflow with disclosed extraction behavior, but it includes rate-limit evasion guidance and broad personal-content collection that warrant Review before installation.

Install only if you intend to automate logged-in Xiaohongshu search extraction and are comfortable with the privacy and platform-policy implications. Avoid using the stealth multi-session throughput guidance, keep searches narrowly scoped, do not collect more personal data than needed, and ensure the user completes login knowingly without exposing credentials or session control unnecessarily.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
83% confidence
Finding
The instruction to invoke remote assistance for QR-code login expands the skill from passive data extraction into interactive account-access facilitation. That creates additional exposure around credential handling, session takeover, and unnecessary operator access to an authenticated user session, especially if the remote-assist channel is broader than strictly needed for local user action.

Context-Inappropriate Capability

Medium
Confidence
79% confidence
Finding
Reading and appending to a persistent local memory file introduces data persistence outside the core task, creating a channel for unintended retention of operational context and possible leakage across runs. Even though the text says not to store keywords or results, this kind of sidecar memory can still accumulate sensitive environment details, workflow history, or attacker-planted instructions that later influence behavior.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The recommendation to open multiple stealth browser sessions with independent fingerprints to increase throughput and avoid anti-scraping limits is a strong indicator of deliberate evasion behavior. This materially increases the skill's abuse potential by helping operators bypass platform defenses, scale collection, and reduce the effectiveness of anti-automation controls designed to protect the target service.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The script extracts and returns user-identifying and content-rich fields such as userId, nickname, avatar, IP-derived location, timestamps, body text, and engagement metrics from Xiaohongshu page state without any built-in notice, minimization, or access control. In the context of a scraping/search skill explicitly designed for bulk collection of XHS notes and full-field extraction, this increases the risk of privacy-invasive monitoring, profiling, or downstream misuse of personal data.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.