Back to skill

Security audit

小红书自动排版发布---一键发布

Security checks for vulnerabilities and agentic risk

Overview

This skill’s publishing goal is clear, but it relies on an unaudited external/local script and unpinned Playwright installation to operate an authenticated Xiaohongshu publishing session.

Review before installing. Use only if you trust the separately deployed xhs_publish.cjs script, understand it will operate an authenticated Xiaohongshu browser session, and can tolerate public-posting automation. Prefer a package that includes the script, pins dependencies with a lockfile, and keeps the two explicit publish confirmations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:53
Finding

Execution of an Unaudited External Publishing Script with Unpinned Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 53–117
Vulnerability Type: External executable and unpinned runtime dependencies
Risk Level: Medium

Vulnerable Code

bash
node {baseDir}/scripts/xhs_publish.cjs check-login
bash
node {baseDir}/scripts/xhs_publish.cjs login
bash
node {baseDir}/scripts/xhs_publish.cjs publish content.json
bash
node {baseDir}/scripts/xhs_publish.cjs get-note <note-ID>

The documentation also permits loading the script from this external workspace location:

text
~/.openclaw/workspace-xiaohongshu-publisher/scripts/xhs_publish.cjs

Runtime dependencies are installed through unpinned commands:

bash
npm install playwright
npx playwright install chromium

Technical Analysis

The audited project contains only SKILL.md; it does not include the referenced scripts/xhs_publish.cjs implementation, a package manifest, or a dependency lockfile. Consequently, the security-sensitive implementation responsible for browser automation, authentication-state handling, publishing, and data retrieval cannot be verified as part of this package.

The documented fallback location is outside the audited Skill directory. Trusting an executable from a separately deployed workspace creates a mutable trust boundary: that file may be replaced or modified independently after this Skill is reviewed.

Playwright is also installed without an exact version or committed lockfile. Dependency resolution can therefore change over time. The npm installation process may execute package lifecycle scripts, while the browser installation command retrieves additional components. This exposes the workflow to package-registry compromise, dependency substitution, or an unexpected future dependency version.

Attack Path

  1. An attacker gains the ability to modify the separately deployed xhs_publish.cjs file, influence the path rep ...[truncated 1521 chars]
Remediation
View remediation

Remediation Suggestions

  1. Include scripts/xhs_publish.cjs in the Skill package so its browser actions, network destinations, input handling, and authentication-state management can be audited.
  2. Do not silently fall back to an executable outside the Skill directory. Resolve the script from a canonical package-relative path and reject path traversal, symbolic-link redirection, and unexpected external locations.
  3. If an external deployment is unavoidable, pin the approved script by a cryptographic digest or signed release and verify it immediately before every execution.
  4. Add a package manifest and committed lockfile containing exact dependency versions and integrity metadata.
  5. Replace ad hoc installation with a reproducible command such as npm ci against the reviewed lockfile.
  6. Review all dependency lifecycle scripts. Where compatible with the deployment model, install with lifecycle scripts disabled and perform any required browser setup through a separately verified procedure.
  7. Pin and verify the expected Playwright and Chromium artifacts rather than accepting whichever versions are current at installation time.
  8. Run the publishing automation under a dedicated, least-privileged operating-system account or sandbox. Restrict filesystem access and outbound network access to the minimum required destinations.
  9. Preserve the existing explicit publication confirmations, and display the final title, body, tags, image paths, target account, and destination immediately before submission.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill instructs users to run npx playwright install chromium without pinning a specific package version, which can fetch and execute whatever version of Playwright is current at invocation time. This creates a supply-chain risk: a malicious or compromised upstream release, dependency confusion event, or breaking change could lead to unreviewed code execution in the user's environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.