Back to skill

Security audit

Xiaohongshu Matrix Notes

Security checks across malware telemetry and agentic risk

Overview

This skill is not malware, but it meaningfully enables large-scale account-style mimicry, third-party platform scraping, and possible real-person likeness reuse without adequate guardrails.

Install only if you are comfortable with third-party API use and have rights to every account dataset, product image, model image, and face reference used. Do not use it to impersonate real creators or copy a benchmark account's identity; use licensed or consented references, review platform rules for Xiaohongshu/RedNote data collection, and set your own retention and deletion practices for scraped notes and generated assets.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The skill's stated purpose is image-and-caption production, but it also includes benchmark-account scraping via a third-party API. That hidden expansion of scope matters because it collects third-party content and metadata, potentially violating user expectations, platform rules, or internal review boundaries for what the skill is allowed to do.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
This section gives concrete operational instructions for collecting Xiaohongshu content through third-party endpoints, including endpoint selection, pagination behavior, required headers, and explicit WAF-avoidance guidance ('must use a normal User-Agent, otherwise WAF 403'). In the context of a skill for producing matrix-account content at scale, this materially enables unauthorized scraping and platform-evasion behavior rather than merely documenting benign data handling.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The description explicitly promotes large-scale mimicry of benchmark accounts and AI-generated content for matrix accounts without any warning about impersonation, deceptive marketing, or account-integrity abuse. In context, the skill is optimized for scalable cloning of style and persona, which materially increases the likelihood of misleading audiences and violating platform authenticity policies.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The data-collection workflow specifies scraping benchmark notes using a third-party tokenized API but provides no privacy, consent, or data-handling guidance. That omission makes it easy to collect, store, and reuse third-party content or metadata without documenting lawful basis, retention limits, or access controls.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill instructs users to lock a face/identity across generated images and even use a benchmark account's face if provided, but it lacks any consent or likeness-rights safeguard. This directly enables identity-based impersonation and unauthorized commercial use of a real person's appearance, which is especially risky in a marketing workflow intended for scale.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The script sends prompts and optional reference images to an external image-generation provider, which can expose sensitive business data, personal images, or proprietary content if operators use confidential inputs. In this skill's context—mass content generation using product and model images—that risk is elevated because reference images may include identifiable people, unreleased products, or licensed assets.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.