Fox Xiaohongshu Publish
Security checks across static analysis, malware telemetry, and agentic risk
Overview
Instructions match the stated purpose: the skill automates posting long-form notes to Xiaohongshu via the built-in browser, requests no extra credentials or installs, and is coherent with its description.
This skill appears coherent and does what it says: it will use the agent's built-in browser to open the Xiaohongshu creator page and interact with the UI to publish a long note. Before using it: 1) ensure you're logged into the correct Xiaohongshu account in the built-in browser (the skill will act with that session's authority); 2) review and confirm content before publishing (there's no credential prompt because it uses existing cookies); 3) be cautious about enabling autonomous invocation if you don't want the agent to publish without explicit confirmation; and 4) note the metadata mismatch in _meta.json (probably benign but worth checking the skill source if you need provenance). If you need publishing that requires explicit authentication steps (e.g., OAuth), request or add those steps to the skill to make behavior clearer.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
