Back to plugin

Security audit

社媒数据助手 小红书 MCP | Xiaohongshu XHS RedNote MCP

Security checks for vulnerabilities and agentic risk

Overview

This plugin is a disclosed read-only bridge to SocialDataX's hosted Xiaohongshu research MCP service and does not show hidden persistence or local data access.

Install this only if you intend to send XHS/RedNote research queries, provided URLs or IDs, pagination tokens, and the configured SocialDataX API key to SocialDataX's hosted MCP endpoint. Check whether either SOCIALDATAX_API_KEY or the legacy SOCIAL_MEDIA_MCP_API_KEY is set in your environment before use.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
README.md:54
Evidence
export SOCIALDATAX_API_KEY="[REDACTED]"