Back to skill

Security audit

Xiaohongshu Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill appears purpose-built for Xiaohongshu automation, but it needs review because it can publish from a user account and stores authenticated browser sessions locally with weak safeguards.

Install only if you are comfortable granting this skill access to your Xiaohongshu account session and letting it drive a local browser. Treat the stored cookies/profile like credentials, avoid shared or elevated machines, review posts manually before allowing publish actions, and prefer a pinned dependency/lockfile setup without third-party mirrors.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/xhs-core.js:47
Finding

Chromium Sandbox Disabled for Untrusted Web Content

Content
View full analysis

Vulnerability Details

File Location: scripts/xhs-core.js, lines 47-61
Vulnerability Type: Browser sandbox protection disabled
Risk Level: High

javascript
async function launchBrowser(headless = true) {
  const opts = {
    headless,
    args: ['--no-sandbox', '--disable-blink-features=AutomationControlled'],
  };
  // Use a persistent user data directory to retain login state
  const userDataDir = path.join(DATA_DIR, 'browser-profile');
  const context = await chromium.launchPersistentContext(userDataDir, {
    ...opts,
    viewport: { width: 1280, height: 800 },
    userAgent: 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36',
    locale: 'zh-CN',
  });
  return context;
}

Technical Analysis

The --no-sandbox command-line argument explicitly disables Chromium's process sandbox for every browser operation performed by the skill. The browser loads live, externally controlled content from Xiaohongshu and can also navigate to a caller-provided URL through the detail command.

Chromium's sandbox is a defense-in-depth boundary intended to contain renderer compromise. Disabling it does not independently create arbitrary code execution, but it significantly increases the consequences of a browser-engine vulnerability because compromised renderer code may no longer be contained by the normal browser sandbox.

The persistent browser context further contains authenticated session state, increasing the value of a successful browser compromise.

Attack Path

  1. An attacker publishes or injects content that exercises a vulnerability in the installed Chromium version.
  2. The skill navigates the browser to the affected content while processing a search, note detail, or other browser-driven operation.
  3. The attacker exploits the browser renderer vulnerability.
  4. Because Chromium was started with --no-sandbox, the norma ...[truncated 645 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the --no-sandbox argument and retain Chromium's default sandbox protections.
  • Run the skill as a standard, unprivileged operating-system user.
  • Keep Playwright and its bundled Chromium version patched and reproducibly pinned.
  • Isolate browser automation in a dedicated low-privilege account, container, or virtual machine when feasible.
  • Restrict browser navigation to approved HTTPS Xiaohongshu hosts.
  • Avoid exposing sensitive host directories to the browser process.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/xhs-core.js:16
Finding

Authentication Cookies Stored in Plaintext

Content
View full analysis

Vulnerability Details

File Location: scripts/xhs-core.js, lines 16-35
Additional Location: scripts/migrate-and-test.js, lines 4-12
Vulnerability Type: Plaintext storage of reusable session credentials
Risk Level: Medium

javascript
const DATA_DIR = path.join(process.env.USERPROFILE, '.xiaohongshu-win');
const COOKIE_FILE = path.join(DATA_DIR, 'cookies.json');
const STATE_FILE = path.join(DATA_DIR, 'browser-state.json');

const XHS_BASE = 'https://www.xiaohongshu.com';
const XHS_API  = 'https://edith.xiaohongshu.com';

if (!fs.existsSync(DATA_DIR)) fs.mkdirSync(DATA_DIR, { recursive: true });

// Cookie management
function loadCookies() {
  if (!fs.existsSync(COOKIE_FILE)) return null;
  try { return JSON.parse(fs.readFileSync(COOKIE_FILE, 'utf8')); }
  catch { return null; }
}

function saveCookies(cookies) {
  fs.writeFileSync(COOKIE_FILE, JSON.stringify(cookies, null, 2), 'utf8');
}

The migration script also copies the credential file without adding encryption or explicit access restrictions:

javascript
const oldCookieFile = path.join(process.env.USERPROFILE, '.xiaohongshu', 'cookies.json');
const newDir = path.join(process.env.USERPROFILE, '.xiaohongshu-win');
const newCookieFile = path.join(newDir, 'cookies.json');

if (!fs.existsSync(newDir)) fs.mkdirSync(newDir, { recursive: true });

if (fs.existsSync(oldCookieFile) && !fs.existsSync(newCookieFile)) {
  fs.copyFileSync(oldCookieFile, newCookieFile);
  console.log('[OK] Migrated cookies from old location');
}

Technical Analysis

The skill serializes all browser cookies directly into an unencrypted JSON file under the user's profile. This includes the web_session cookie used by the application to determine whether the user is authenticated.

The code does not apply operating-system-backed encryption, establish an explicit restrictive ACL, minimize the stored cookie set, or protect the data u ...[truncated 1528 chars]

Remediation
View remediation

Remediation Suggestions

  • Protect persistent credentials using Windows Data Protection API or Windows Credential Manager.
  • Explicitly restrict the data directory and cookie file ACLs to the current user.
  • Store only the minimum cookies required for operation rather than the complete browser cookie collection.
  • Avoid keeping duplicate legacy cookie files after migration; securely remove the source after a verified migration and user confirmation.
  • Provide a logout or credential-purge command that deletes stored cookies and browser authentication state.
  • Do not print cookie values or include the cookie file in backups, diagnostics, or source-control archives.
  • Consider relying exclusively on a protected persistent browser profile rather than maintaining a separate plaintext cookie export.

T08 · Insecure Dependencies

Warning
Location
scripts/package.json:7
Finding

Non-Reproducible Playwright and Chromium Installation Chain

Content
View full analysis

Vulnerability Details

File Location: scripts/package.json, lines 7-10
Additional Locations: SKILL.md, lines 69-74; references/setup.md, lines 17-23 and 49-53
Vulnerability Type: Unpinned dependency and unsafe supply-chain configuration
Risk Level: Medium

json
"scripts": {
  "install-browsers": "npx playwright install chromium"
},
"dependencies": {
  "playwright": "^1.40.0"
}

The primary installation instructions also use an unconstrained package installation:

powershell
npm install --save playwright

$env:PLAYWRIGHT_BROWSERS_PATH = "$env:USERPROFILE\.xiaohongshu-win\browsers"
npx playwright install chromium

The setup reference permits browser downloads through a third-party mirror:

powershell
$env:PLAYWRIGHT_DOWNLOAD_HOST = "https://npmmirror.com/mirrors/playwright"
npx playwright install chromium

Technical Analysis

The Playwright dependency uses the semver range ^1.40.0, and the project does not include an audited lockfile. The documented npm install --save playwright command may resolve a different compatible release depending on when installation occurs. Consequently, the installed dependency tree is not reproducible from the audited source alone.

The npx playwright install chromium command then downloads and installs an executable browser artifact. The documentation optionally redirects this download to a third-party mirror, expanding the supply-chain trust boundary.

No evidence shows that the current Playwright package or mirror is malicious. The vulnerability is that package or mirror compromise, unsafe version drift, or registry account compromise could alter the code and executable artifacts installed after the skill itself has been reviewed.

The setup documentation also refers to Setup-Xhs.ps1, but that script is absent from the audited project and therefore could not be verified.

Attack Path

  1. An attacker compromises ...[truncated 1029 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin Playwright to an exact reviewed version rather than using a caret range.
  • Generate and commit a reviewed package-lock.json.
  • Document npm ci as the supported installation method so dependency resolution matches the lockfile.
  • Use the official Playwright browser download infrastructure whenever possible.
  • If a mirror is required, use a trusted organizational mirror and independently validate artifact hashes or signatures.
  • Pin and document the expected Chromium revision associated with the selected Playwright version.
  • Run installation without administrative privileges.
  • Include the referenced Setup-Xhs.ps1 in the project so its behavior can be audited, or remove the unsupported reference.
  • Regularly review dependency advisories and update the exact pins and lockfile through a controlled process.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The supplied code matches part of the declared purpose: it is a Windows/Node.js/Playwright-based Xiaohongshu automation core, supports login, content search, note detail retrieval, and publishing notes. However, several prominently declared core features are absent from this code chunk: no Markdown topic report generation, no scheduling/Cron logic, no AI cover generation, and no writing/generation assistance for note content. The code also includes local cookie storage and authenticated browser/API automation, which are consistent supporting details for the declared browser-control purpose, not separate mismatches. Overall, the description overstates the implemented capabilities in this chunk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The automation clicks the publish button immediately after populating the post, with no explicit user confirmation step before performing an externally visible account action. If triggered unintentionally, by prompt injection upstream, or with attacker-controlled content or images, it can cause unauthorized posts from the user's account and reputational or policy consequences.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes Node.js, installs packages, uses Playwright, accesses environment variables, and drives a browser, but it declares no explicit tool or permission boundaries. That makes the effective privilege surface ambiguous and can lead users or hosts to authorize broader environment and network access than they intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The invocation examples are broad and action-oriented, including content publication, without clear guardrails, confirmation requirements, or scope limitations. In an agent setting, vague activation boundaries can cause unintended execution of browser automation and social-media actions from loosely related user requests.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using 'npx playwright' without pinning an exact version makes execution depend on whatever package version resolves at runtime. This creates a supply-chain risk where a compromised, malicious, or breaking upstream release could be fetched and executed on the user's machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill stores login cookies and a persistent Chromium profile locally, but the description does not prominently warn users before use. Those artifacts can contain authenticated session data, and if other local processes or users access them, the account may be hijacked or activity may be impersonated.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The setup instructions invoke npx playwright without pinning an exact package version, which means the installed tooling can change over time and could pull in a compromised or incompatible release. Because this skill drives a real browser and stores authenticated Xiaohongshu session data locally, a poisoned dependency or unexpected upstream update increases supply-chain risk beyond a purely informational tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document states that cookies and a persistent browser profile are saved under the user's home directory, but does not explicitly warn that these files contain sensitive authenticated session material. On a shared or compromised Windows host, theft of these files may allow account takeover or unauthorized use of the logged-in Xiaohongshu session.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The mirrored download command again uses unpinned npx playwright, so users may fetch whatever version is current at execution time rather than a reviewed version. In a skill that automates login and content posting, this creates avoidable supply-chain exposure and reproducibility problems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide includes a forceful recursive deletion command that removes all local skill data, but does not clearly warn the user about the scope of deletion beforehand. While the path is limited to the skill's application directory under the user profile, accidental execution can still erase saved cookies, browser profile data, and local state without recovery.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script copies a cookies.json file, which likely contains authentication material, into a different directory. While it logs that migration occurred, it does not warn the user beforehand or document that sensitive session data will be duplicated on disk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The install script invokes npx playwright install chromium, which can resolve and execute a package version that is not explicitly pinned at execution time. In a supply-chain attack or registry compromise scenario, this increases the chance of pulling an unexpected CLI/package version and then downloading browser binaries during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code persists authenticated Xiaohongshu cookies, including session tokens, to a predictable file under the user's profile in plaintext JSON. If another local process, malware, backup system, or another user account with access to the profile can read that file, the session may be reused to impersonate the user without re-authentication.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The browser context is launched with locale set to zh-CN, which enforces a specific locale choice for all users. The file does not offer a user-selectable locale or document that this is a region-specific tool requiring Chinese locale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function injects stored cookies into the browser context and performs authenticated fetch requests to the Xiaohongshu API, which sends user session data over the network. Although the code comments describe the mechanism, they do not clearly warn the user that their authenticated account context and associated data will be transmitted to the service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code presents the tool description, commands, prompts, and generated timestamps in Chinese only, indicating a fixed language/locale experience. The policy for SQP-3 allows locale constraints only when users are given a choice or the restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language instructions are entirely in Chinese, which can amount to a language policy issue when no user opt-in or locale justification is provided. The file does not state that the skill is intended only for Chinese-speaking or region-specific users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The top-level comment is written only in Chinese, which imposes a specific language in the skill's natural-language content without offering user choice or documenting a justified locale restriction. This can violate language or locale policy for broadly used skills.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The dependency is declared as ^1.40.0, which allows installation of newer compatible releases rather than a single reviewed version. This weakens reproducibility and can silently introduce vulnerable or malicious upstream changes into a tool that controls a local browser and may handle authenticated Xiaohongshu sessions.

Content

Scanner excerpt · scripts/package.json (reported line 10)May include surrounding context.

json
"install-browsers": "npx playwright install chromium"
  },
  "dependencies": {
    "playwright": "^1.40.0"
  }
}

Unverifiable Dependency: playwright has 1 known advisory(ies) (CVE-2025-59288 (Playwright downloads and installs browsers without verifying the authenticity of)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
86% confidence
Finding

The manifest references Playwright without an exact pinned version while the package family has a known advisory related to downloading and installing browser binaries without authenticity verification. Because this skill's core functionality depends on Playwright controlling and provisioning Chromium locally, the context makes supply-chain and binary-tampering risks more relevant than in a purely passive library.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.potential_exfiltration

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/xhs-core.js:16

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
scripts/xhs-core.js:28