Back to skill

Security audit

Deepsop Xiaohongshu 助手

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its Xiaohongshu posting purpose, but it automatically downloads and runs unverified third-party code and can publish through a user account.

Install only if you trust the social-auto-upload upstream and accept that first use downloads code, dependencies, and a Chromium browser, then uses local cookies/session state to publish to Xiaohongshu. Prefer a pinned, verified upstream commit, avoid mirror/fork fallbacks, and confirm the exact account and media before any upload.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/runtime-requirements.md:38
Finding

Unverified Remote Source Fallback Is Installed and Executed

Content
View full analysis

Vulnerability Details

File Location: references/runtime-requirements.md:38-71, 84-94, 101-112, 121-139; also mandated by SKILL.md:41-46
Vulnerability Type: Unverified remote payload retrieval and supply-chain execution
Risk Level: Critical

Vulnerable Code

bash
# Direct upstream
git clone https://github.com/dreammis/social-auto-upload.git <SAU_HOME>

# Automatic fallbacks
git clone https://gitee.com/lonycn/social-auto-upload.git <SAU_HOME>
git clone https://gh-proxy.org/https://github.com/dreammis/social-auto-upload.git <SAU_HOME>
git clone https://gh-proxy.com/https://github.com/dreammis/social-auto-upload.git <SAU_HOME>
git clone https://hub.gitmirror.com/https://github.com/dreammis/social-auto-upload.git <SAU_HOME>

The downloaded project is subsequently installed and executed:

bash
cd <SAU_HOME>
cp conf.example.py conf.py
uv sync --python 3.12
bash
uv run --project <SAU_HOME> python sau_cli.py --help

A browser binary is also downloaded through a third-party mirror:

bash
PLAYWRIGHT_DOWNLOAD_HOST="https://npmmirror.com/mirrors/playwright" \
  uv run --project "$HOME/.openclaw/social-auto-upload" patchright install chromium

Technical Analysis

The setup workflow requires the agent to retrieve executable source code at runtime and execute it without pinning or verifying an immutable revision. The fallback Gitee repository belongs to lonycn, rather than the declared upstream owner dreammis. The other fallback URLs route source retrieval through third-party proxy or mirror services.

No required control verifies a commit hash, signed tag, repository identity, source archive checksum, or downloaded browser digest. Consequently, the effective code can change after this Skill has been reviewed. A compromised fork, mirror, proxy, upstream branch, or associated dependency metadata could provide a modified pyproject.toml, lockfile, build component, or sau_cli.py.

Running uv sync processes dependenc ...[truncated 1784 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the unrelated Gitee fork and untrusted proxy or mirror fallbacks.
  2. Retrieve source only from the declared upstream repository over authenticated HTTPS.
  3. Pin a specifically audited, immutable commit and verify HEAD against the expected full commit hash before running any setup command.
  4. Require signed-tag or signed-commit verification where the upstream supports it.
  5. Verify the expected repository origin and reject unexpected owners, remotes, redirects, or repository identities.
  6. Validate the reviewed lockfile before dependency synchronization and use locked/frozen dependency resolution.
  7. Audit build backends and dependency installation behavior before allowing project setup.
  8. Verify browser artifacts against cryptographic hashes published through a trusted, independent channel.
  9. Require explicit user approval before downloading and executing remote software.
  10. Prefer vendoring a reviewed source snapshot and verified dependencies when reproducible source verification cannot be guaranteed.
  11. Run the external automation in a restricted environment with minimal filesystem access and no unnecessary credentials.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/cli-contract.md (reported line 1)May include surrounding context.

md
# 假设 social-auto-upload 已 clone 到 $SAU_HOME,且已经跑过 `uv sync --python 3.12`。
$SAU_HOME = "$env:USERPROFILE\.openclaw\social-auto-upload"

# PowerShell examples for the installed sau CLI.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/runtime-requirements.md (reported line 1)May include surrounding context.

md
# 假设 social-auto-upload 已 clone 到 $SAU_HOME,且已经跑过 `uv sync --python 3.12`。
$SAU_HOME = "$env:USERPROFILE\.openclaw\social-auto-upload"

# PowerShell examples for the installed sau CLI.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 1)May include surrounding context.

md
# 假设 social-auto-upload 已 clone 到 $SAU_HOME,且已经跑过 `uv sync --python 3.12`。
$SAU_HOME = "$env:USERPROFILE\.openclaw\social-auto-upload"

# PowerShell examples for the installed sau CLI.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/examples/xiaohongshu_commands.ps1 (reported line 1)May include surrounding context.

text
# 假设 social-auto-upload 已 clone 到 $SAU_HOME,且已经跑过 `uv sync --python 3.12`。
$SAU_HOME = "$env:USERPROFILE\.openclaw\social-auto-upload"

# PowerShell examples for the installed sau CLI.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states that the skill will automatically clone an external repository and prepare dependencies on first use, but it does not present this as a prominent warning with clear trust and supply-chain implications. Because the skill fetches and executes code from an external project at runtime, users may unknowingly permit network access and dependency execution they did not explicitly consent to. The later 'SAFE' audit language is a red flag that can further reduce user caution rather than mitigate the risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly instructs the agent to use shell-capable operations such as cloning a repository, syncing dependencies, and running Python commands, yet it declares no tool scope or allowed-tools restrictions. This creates an authorization and transparency gap: an agent may invoke shell actions broader than the user expects, including filesystem and network operations, without explicit manifest-level limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill states that it will automatically clone the external social-auto-upload project and prepare dependencies with uv on first use, but it does not present this as a prominent user-facing warning. Pulling and executing third-party code from external sources introduces supply-chain and remote code execution risk, especially because the workflow also instructs retrying through multiple GitHub mirror domains.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill supports login, cookie validation, and content uploads to Xiaohongshu, which necessarily transmit account/session data and user-provided media/text to a third-party service, but it does not give an explicit warning about that data transfer. In this context, the omission is security-relevant because the skill handles authentication state and publication actions that may expose private content, metadata, or account control to an external platform.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document title and all user-facing contract text are written exclusively in Chinese, which imposes a specific language/locale on skill use. The file does not offer any language choice, opt-in, or explanation that this skill is region-specific and therefore intentionally limited to Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains all operational instructions and quoted user-facing messages only in Chinese, including prescribed phrases the agent should tell the user. That can violate language/locale policy when used in a broader product context because it forces a specific language without any documented user opt-in or alternative locale support.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该 markdown 文件整体以中文提供操作说明,但未说明这是面向特定中文用户群体的受限技能,也未提供其他语言选项。根据语言/locale 政策,强制单一语言且没有用户 opt-in 或合理限定,属于自然语言策略违规。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script performs login, account checking, and content uploads in sequence with no interactive confirmation, dry-run mode, or warning before publishing actions. In the context of a social-media automation skill, this increases the risk of unintended posting, misuse of the wrong account, and accidental publication of sensitive or non-final content once the script is executed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This PowerShell file executes login, account checks, and content upload operations against Xiaohongshu, including headless mode, but provides no user-facing warning, confirmation prompt, or explanatory comment about the side effects of authenticating and publishing content. Because these are external account-affecting operations, the lack of disclosure in the script is a safety concern under the code-file warning criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The README is entirely written in Chinese and the invocation examples assume Chinese-language interaction, but it does not state that this is optional or provide any language/locale choice. This can amount to a language-policy issue if users are expected to interact in a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Line 1 contains a Chinese-language instruction, while the file does not indicate that the skill is region-specific or provide an option for users to choose language. This can violate the language/locale policy when a specific language is imposed without documented justification or opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.