Back to skill

Security audit

Xhs Ops

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Xiaohongshu operations helper, but users should be careful because it describes scheduled collection and reuse of a logged-in browser session.

Install only if you intend to automate Xiaohongshu monitoring. Use a separate browser profile, understand that remote debugging can expose the logged-in session locally, review any cron or notification setup before enabling it, and make sure your collection and alerts comply with account, platform, and privacy expectations.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill is user-invocable but its description and scope are broad, lacking explicit triggers, boundaries, or permission constraints. In a skill that performs competitor monitoring, automated collection, notification, and scheduled execution, this ambiguity can cause the agent to over-collect data or act on unintended targets without clear user confirmation.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documentation explicitly describes automated data collection, scheduled execution, and reuse of a logged-in browser session, but provides only a minimal 'personal use' note and no concrete warnings about privacy, account compromise, or session persistence risks. Reusing an authenticated browser context via remote debugging increases the blast radius of misuse, potentially exposing account data, enabling unauthorized actions, or violating platform expectations if invoked carelessly or by another local process.

Static analysis

No suspicious patterns detected.