Back to skill

Security audit

xiaohongshu-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches its stated Xiaohongshu automation purpose, but it needs review because it can act on a real social account and includes under-scoped local deletion plus silent browser-script override behavior.

Review before installing. Use a dedicated Xiaohongshu account, prefer ClawHub or a pinned/reviewed source over the unpinned git pip install, keep ~/.xiaohongshu private, check that ~/.xiaohongshu/stealth.js is absent or intentionally trusted, and do not pass arbitrary paths to --cookie when using logout. Confirm every public post, comment, like, collect, or account-state change yourself, and consider platform rules for browser automation.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/login.py:311
Finding

Arbitrary File Deletion Through the Custom Cookie Path During Logout

Content
View full analysis
str: profile = _profile(args) paths = profile_paths(profile) if profile: os.environ["XHS_PROFILE"] = profile if getattr(args, "cookie", None): return args.cookie return str(paths.cookie_path) ``` ```python # scripts/__main__.py:185 result = login.logout( cookie_path=_cookie_path(args), user_data_dir=_user_data_dir(args), ) ``` ```python # scripts/__main__.py:576 parser.add_argument("--cookie", "-c", help="Cookie file path", default=None) ``` ```python # scripts/login.py:311-323 def logout(cookie_path=None, user_data_dir=None): """Delete persistent browser data and Cookie file to reset login state.""" import shutil paths = profile_paths(env_profile()) data_dir = user_data_dir or str(paths.user_data_dir) if os.path.exists(data_dir): shutil.rmtree(data_dir) path = cookie_path or DEFAULT_COOKIE_PATH if os.path.exists(path): os.remove(path) ``` ### Technical Analysis The global `--cookie` option accepts an unrestricted path. The logout command passes this value through `_cookie_path()` to `login.logout()`, where the path is deleted with `os.remove()`. The deletion target is not canonicalized or checked against the selected Xiaohongshu profile directory. The code also does not verify that the target is the expected cookie backup, a regular file, or a non-symlink. Consequently, any existing file writable by the process can be selected as the alleged cookie file and deleted. This behavior exceeds the legitimate scope of logout, which should only remove Xiaohongshu session artifacts. ### Attack Path 1. An attacker influences an Agent, automation w ...[truncated 1222 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Warning
Location
scripts/client.py:115
Finding

Implicit Execution of an Undocumented Local JavaScript Override in Authenticated Browser Sessions

Content
View full analysis
str: """Build stealth JS from a stable profile seed and optional local overrides.""" seed_number = int.from_bytes( hashlib.sha256(seed.encode("utf-8")).digest()[:4], "big", ) js = self.STEALTH_JS.replace( "__XHS_FINGERPRINT_SEED__", str(seed_number), ) if os.path.exists(self.STEALTH_JS_PATH): try: with open(self.STEALTH_JS_PATH, "r", encoding="utf-8") as handle: external = handle.read() if external.strip(): js += "\n// === External stealth.js overrides ===\n" + external log.info("Loaded external stealth.js overrides") except Exception: log.warning("Unable to load external stealth.js overrides") return js ``` ```python # scripts/client.py:251-253 seed = resolve_fingerprint_seed(self.session_path) self._stealth_js = self._load_stealth_js(seed) ``` ```python # scripts/client.py:281-283 # Inject anti-detection script before every new page loads self.context.add_init_script(self._stealth_js) ``` ### Technical Analysis Whenever the browser starts, the client checks the fixed path `~/.xiaohongshu/stealth.js`. If the file exists, its complete contents are appended to the built-in script and registered through Playwright's `add_init_script()`. The supplied JavaScript therefore executes automatically before page scripts in every page created by the persistent browser ...[truncated 2225 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (103)

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.md (reported line 65)May include surrounding context.

kills add DeliciousBuding/xiaohongshu-skill

text

### Reproducible local environment

```bash
git clone https://github.com/DeliciousBuding/xiaohongshu-skill.git
cd xiaohongshu-skill
uv sync --frozen --no-dev
uv run playwright install chromium

Development environment:

bash
uv sync --frozen --group dev
uv run python -m scripts.quality check

Global CLI

bash
pip install git+https://github.com/DeliciousBuding/xiaohongshu-skill.git
playwright install chromium
xiaohongshu-skill --help

Docker

bash
docker compose build
docker compose run --rm xiaohongshu qrcode --headless=false

See installation guide for system and platform details.

Quick start

1. Login

bash
uv run python -m scripts qrcode --headless=false
uv run python -m scripts check-login

2. Search and read

bash
uv run python -m scripts search "coffee" --limit=5
uv run python -m scripts feed <feed_id> <xsec_to

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README_EN.md (reported line 65)May include surrounding context.

kills add DeliciousBuding/xiaohongshu-skill

text

### Reproducible local environment

```bash
git clone https://github.com/DeliciousBuding/xiaohongshu-skill.git
cd xiaohongshu-skill
uv sync --frozen --no-dev
uv run playwright install chromium

Development environment:

bash
uv sync --frozen --group dev
uv run python -m scripts.quality check

Global CLI

bash
pip install git+https://github.com/DeliciousBuding/xiaohongshu-skill.git
playwright install chromium
xiaohongshu-skill --help

Docker

bash
docker compose build
docker compose run --rm xiaohongshu qrcode --headless=false

See installation guide for system and platform details.

Quick start

1. Login

bash
uv run python -m scripts qrcode --headless=false
uv run python -m scripts check-login

2. Search and read

bash
uv run python -m scripts search "coffee" --limit=5
uv run python -m scripts feed <feed_id> <xsec_to

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for a Xiaohongshu automation agent with browsing and posting capabilities. The supplied code does none of that. It parses CLI arguments, walks local files/directories such as README/docs/.github, reads text files, matches regex patterns for privacy/secrets and writing style issues, prints findings, and returns a process exit code. This is a documentation lint/privacy scan utility, which is materially different from the declared platform automation purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for a Xiaohongshu automation skill with content operations and guarded write actions. The actual code chunk contains none of that functionality. Instead, it is an internal task runner for development and CI that invokes linting, tests, docs/site checks, contracts, and a local HTTP server. This is a materially different primary purpose and unrelated behavior, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is an AI agent for Xiaohongshu/RedNote automation with browser-based platform actions and guarded write operations. The supplied code does none of that. It only parses command-line arguments, loads pyproject.toml, compares versions against a Git tag and runtime version, and reports consistency. This is a materially different primary purpose and lacks all core declared capabilities, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code does not interact with Xiaohongshu/RedNote at all, does not use Playwright, and does not implement any social-platform operations such as searching, reading content, logging in, publishing, commenting, liking, or favoriting. Instead, it performs local static checks on a website directory, validating SEO metadata, JSON-LD, discovery terms, and required GitHub Pages files like index.html, robots.txt, sitemap.xml, and llms.txt. This is a materially different primary purpose from the declared skill description, so it is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is a Xiaohongshu automation agent with browser-based social platform capabilities. The supplied code instead only validates repository skill metadata/frontmatter for a SKILL.md file. Its primary purpose is entirely different and unrelated to Xiaohongshu, Playwright, social actions, or user-facing agent operations. This is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a full Xiaohongshu automation skill with Playwright-based searching, reading, session management, and direct write operations subject to user confirmation. This code chunk instead implements only SOP planning/orchestration: it creates plans for publishing, comment interactions, and explore-feed interactions, performs quota checks and validation, and returns structured plan dictionaries. The code even states that it does not actually operate the browser and that actual publishing/commenting must be done by other modules. Therefore the behavior is materially narrower and different from the declared end-to-end automation capability. The confirmation requirement is partially aligned in spirit for publishing because it returns a plan with a confirmation message, but the larger mismatch remains because major declared capabilities are missing from this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This is a material description-behavior mismatch. The declared purpose describes an active Xiaohongshu automation agent that interacts with the platform, reads content, manages authentication, and performs write operations subject to confirmation. The supplied code instead provides only offline operational planning and bookkeeping utilities backed by a local JSON file. While the theme is related to Xiaohongshu operations, the primary purpose is substantially different: strategy management rather than platform automation. The code neither accesses Xiaohongshu nor performs the declared actions, and it adds a significant undeclared capability of local persistent strategy/calendar/quota management.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description promises a full Xiaohongshu automation agent with live platform operations and guarded write actions. The actual code chunk only implements a template engine with static data and random generation for titles, content skeletons, tags, and basic validation. This is a materially different primary purpose: content drafting support versus Xiaohongshu automation. There are no network calls, browser controls, authentication flows, or platform-side read/write operations in the supplied code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The supplied code chunk does not implement the declared Xiaohongshu agent capabilities. It only checks whether live tests should run based on the XHS_LIVE_TEST environment variable and returns a skip reason string. While the message references Xiaohongshu and browser sessions, this is only for test control, not platform interaction. Therefore the code's actual purpose is test infrastructure, which materially differs from the declared skill description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about a Xiaohongshu social-media automation agent using Playwright to search, read, post, comment, like, and favorite content. The supplied code does none of that. Instead, it contains unit tests for documentation scanning functions that inspect markdown/HTML/XML/SVG/JSON files for private local paths and writing-pattern issues. This is a materially different primary purpose and unrelated capability set, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a full Xiaohongshu automation skill with read/write platform operations and confirmation safeguards. The actual code chunk does not implement any of those user-facing capabilities. Instead, it contains unit tests for helper functions controlling whether live tests should run based on an environment variable. This is a materially different primary purpose and unrelated to the declared automation behavior, so it is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a full Xiaohongshu automation skill with browsing, publishing, and engagement actions. The supplied code chunk does not implement any of those behaviors. Instead, it contains unit tests for local profile path helpers, checking how cookie.json, browser-data, and session.json paths are constructed and how profiles are listed from the filesystem. While session/profile storage could be a supporting detail for such a skill, this chunk by itself is materially different in primary purpose and shows none of the declared platform-facing capabilities. Therefore, the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear mismatch between the declared purpose and the actual code. The description claims a social-platform automation skill for Xiaohongshu with content operations and session management, but the provided code only contains unit tests for a quality script. Its behavior is limited to asserting command plans, checking child-process environment variables, and validating a local site server command. No code here searches Xiaohongshu, manages login, posts content, comments, likes, favorites, uses Playwright, or emits JSON for user-facing operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is an AI agent for Xiaohongshu automation and content operations. However, the provided code chunk is only a unit test file for release/version checks. It imports version-validation helpers, asserts tag/version matching behavior, and reads a version from a pyproject.toml file. There is nothing in the code related to Xiaohongshu, browser automation, JSON output behavior, user confirmation for write actions, or any social-media functionality. This is a clear material mismatch in primary purpose and implemented capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is for a full Xiaohongshu automation agent that uses Playwright to browse, post, comment, like, and favorite content. The supplied code chunk does not implement or exercise any Xiaohongshu platform actions, browser automation, content reading/writing, or user-confirmation flow. Instead, it is a unit test module focused narrowly on local session-store behavior: persisting a fingerprint seed in a JSON file, allowing process-level override through XHS_FP_SEED, replacing corrupt metadata safely, avoiding logging secrets, and ensuring atomic write semantics. While session management is loosely related to the declared skill, this chunk’s actual purpose is materially different and much narrower, making the description inaccurate for this specific code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code does not implement Xiaohongshu/RedNote automation, Playwright browsing, login/session management, content publishing, commenting, liking, favoriting, or JSON-based agent interactions. Instead, it tests a static site checker concerned with SEO/GEO and crawler-facing files for a GitHub Pages site. This is a materially different primary purpose and capability set from the declared description, so it is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a social media automation skill for Xiaohongshu/RedNote. The actual code chunk contains only unit tests for validating skill metadata/frontmatter and CLI behavior. It does not interact with Xiaohongshu, perform browser automation, manage sessions, read or write platform content, or implement any of the described triggers or safeguards around write confirmation. This is a clear material mismatch in primary purpose and capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a full Xiaohongshu automation agent that interacts with the platform to read and write content. However, the provided code chunk is only a test suite for a local strategy manager module. Its tested behaviors are initializing a persona, storing/loading config, checking daily limits, recording action counts, and managing a scheduled-post calendar. These are adjacent operational-planning utilities, but they do not implement or demonstrate the core declared capabilities such as Playwright-based browsing, platform login, search, reading posts, publishing content, commenting, liking, or collecting/favoriting. Therefore the code chunk's actual behavior is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a full Xiaohongshu automation skill with platform interaction capabilities and safety controls for write actions. The actual code chunk is limited to tests for a template engine that generates titles, content structures, tags, and validates text lengths/content. This is a materially different primary purpose. There are no signs of network access, browser control, account management, or RedNote-specific operational behavior in the provided code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code chunk is a standalone test verifying that time.sleep does not cause real delay in unit tests. It does not implement or support Xiaohongshu functionality, browser automation, JSON output, login/session management, or guarded write actions. Its primary purpose is materially different from the declared description, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
85% confidence
Finding

The pip install git+https://github.com/DeliciousBuding/xiaohongshu-skill.git instruction installs and executes code directly from a remote Git repository at the latest state, which creates a supply-chain risk: a compromised repo, malicious force-push, or unexpected upstream change could deliver unreviewed code to users. In a skill ecosystem, this is more dangerous because installation typically grants code execution in the user's local environment and may interact with browser sessions and account state.

Content

Scanner excerpt · docs/INSTALL.md (reported line 40)May include surrounding context.

-skill uv sync --frozen --no-dev uv run playwright install chromium

text

On Linux, install browser system dependencies with:

```bash
uv run playwright install --with-deps chromium

Login and verify:

bash
uv run python -m scripts qrcode --headless=false
uv run python -m scripts check-login
uv run python -m scripts search "咖啡" --limit=3

Global CLI

bash
pip install git+https://github.com/DeliciousBuding/xiaohongshu-skill.git
playwright install chromium
xiaohongshu-skill qrcode --headless=false
xiaohongshu-skill search "咖啡" --limit=3

The cloned uv.lock path is recommended for development and reproducible local runs. The global Git installation is a convenience path.

Agent Skill

Recommended cross-platform installation:

bash
npx skills add DeliciousBuding/xiaohongshu-skill

ClawHub:

bash
clawhub install xiaohongshu-skill

Manual folders:

text
Claude Code: ~/.claude/skills/xiaohongshu-s

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/quality.py (reported line 74)May include surrounding context.

python
def run_task(task: str, *, port: int = 8000) -> int:
    env = None
    if task == "live":
        env = os.environ.copy()
        env["XHS_LIVE_TEST"] = "1"
    return _run_many(command_plan(task, port=port), env=env)

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · site/index.html (reported line 383)May include surrounding context.

html
utton secondary" href="demo.html">Demo Outputs</a>
          </div>
        </div>
        <div class="showcase" aria-label="Project preview">
          <div class="terminal" aria-label="CLI example">
            <div class="terminal-bar"><span class="dot"></span><span class="dot"></span><span class="dot"></span></div>
            <pre><code>npx skills add DeliciousBuding/xiaohongshu-skill
pip install git+https://github.com/DeliciousBuding/xiaohongshu-skill.git
playwright install chromium
xiaohongshu-skill qrcode --headless=false
xiaohongshu-skill --profile brand-a search "上海咖啡" --limit=3
xiaohongshu-skill selectors --owner=publish
xiaohongshu-skill contracts --command=search</code></pre>
          </div>
          <figure class="visual">
            <img src="og-image.svg" alt="xiaohongshu-skill terminal preview with Xiaohongshu and RedNote labels">
          </figure>
        </div>
        <div class="facts" aria-label="Project facts">
          <div class

Static analysis

No suspicious patterns detected.