Back to skill

Security audit

小红书自动发布工具包 (Xiaohongshu Publish Kit)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real Xiaohongshu publishing toolkit, but it combines live account posting with unsafe shell execution, persistent login automation, and risky browser-session copying.

Review carefully before installing. Use only a dedicated/test Xiaohongshu account, avoid passing untrusted titles/content/filenames, do not enable the cron or daemon keepalive unless you accept recurring access to your logged-in browser, and clear the OpenClaw browser profile/session backup if you stop using the skill.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T06 · System Persistence

Error
Location
scripts/setup_keepalive.sh:27
Finding

Persistent scheduled execution through user crontab modification

Content
View full analysis
> /tmp/xiaohongshu_keepalive.log 2>&1" if crontab -l 2>/dev/null | grep -q "login_keeper.py"; then read -p "> " replace if [ "$replace" = "y" ]; then (crontab -l 2>/dev/null | grep -v "login_keeper.py"; echo "$CRON_CMD") | crontab - fi else (crontab -l 2>/dev/null; echo "$CRON_CMD") | crontab - fi crontab -l | grep login_keeper.py ``` ### Technical Analysis The setup script modifies the current user's crontab to execute `login_keeper.py` every 30 minutes. The job survives the original Skill run and continues accessing an authenticated browser profile across future sessions. Session retention is related to the advertised functionality, and installation requires an interactive selection. Nevertheless, scheduled persistence is not required for on-demand publishing and exceeds the minimum privileges needed by the core feature. Both `SKILL.md` and the setup interface strongly recommend this persistent mode rather than presenting it as an exceptional option. The cron command also interpolates `SCRIPT_DIR` without cron-safe shell quoting. Installation from a path containing spaces or shell metacharacters could cause the job to fail or change its interpretation. Existing jobs are detected and removed using the broad substring `login_keeper.py`, which can match unrelated cron entries. ### Attack Path 1. The user follows the recommended login-retention instructions. 2. The user runs `scripts/setup_keepalive.sh` and selects option 1. 3. The script reads the user's existing crontab and appends a recurring entry. 4. Every 30 minutes, cron launches `login_keeper.py`. 5. The recurring process starts or c ...[truncated 804 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/publish.py:13
Finding

Arbitrary command execution through unsafe publication command construction

Content
View full analysis
{{ const el = document.querySelector('input[placeholder*=\"标题\"]'); if (!el) return 'title input not found'; const setter = Object.getOwnPropertyDescriptor( window.HTMLInputElement.prototype, 'value' ).set; setter.call(el, '{title_escaped}'); el.dispatchEvent(new Event('input', {{bubbles:true}})); el.dispatchEvent(new Event('change', {{bubbles:true}})); return 'title set, length=' + el.value.length; }}"''' ``` ```python paragraphs = content.split('\n') html_content = '' for p in paragraphs: if p.strip(): p_escaped = p.replace("'", "\\'").replace('"', '\\"') html_content += f'

{p_escaped}

' else: html_content += '


' cmd = f'''browser --browser-profile openclaw evaluate --fn ...[truncated 2529 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cover_generator.py:61
Finding

Command injection and unintended network exposure in cover generation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/login_keeper.py:125
Finding

Authenticated browser profile copied to predictable temporary storage and destructively restored

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
examples/daily_news.py:69
Finding

Unsafe shell construction in the daily news publication example

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (41)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Persistent scheduled task installation and daemon/process management materially change the risk profile from simple content publishing to ongoing system-level persistence. In the context of a browser-automation skill tied to a logged-in social-media account, undisclosed persistence can lead to unexpected long-term control over posting capability and session monitoring.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Persistent scheduled task installation and daemon/process management materially change the risk profile from simple content publishing to ongoing system-level persistence. In the context of a browser-automation skill tied to a logged-in social-media account, undisclosed persistence can lead to unexpected long-term control over posting capability and session monitoring.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Persistent scheduled task installation and daemon/process management materially change the risk profile from simple content publishing to ongoing system-level persistence. In the context of a browser-automation skill tied to a logged-in social-media account, undisclosed persistence can lead to unexpected long-term control over posting capability and session monitoring.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This is a true tool-parameter abuse issue because untrusted or semi-trusted values are embedded directly into a shell command that invokes another tool. The skill context makes this more dangerous: it is designed for automated content generation and publication, so data may eventually come from external feeds, model outputs, or user-supplied text, broadening the injection surface.

Content

Scanner excerpt · examples/daily_news.py (reported line 75)May include surrounding context.

python
cmd = f"python3 {cover_script} --title '{title}' --date '{date_str}' --output '{output_path}'"
    
    result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
    
    if result.returncode == 0:
        print(f"✅ 封面生成成功: {output_path}")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The publishing step passes title and content into a shell command, enabling abuse of tool parameters for command injection or argument-smuggling. Since this step targets a live publishing workflow, compromise here could lead both to arbitrary code execution and unauthorized or manipulated social-media posts.

Content

Scanner excerpt · examples/daily_news.py (reported line 91)May include surrounding context.

python
cmd = f"python3 {publish_script} --title '{title}' --content '{content}' --image '{cover_path}'"
    
    result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
    
    if result.returncode == 0:
        print("✅ 小红书发布成功!")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/cover_generator.py (reported line 66)May include surrounding context.

python
try:
        # 启动本地HTTP服务器
        subprocess.run("cd /tmp/openclaw && python3 -m http.server 18811 &", shell=True)
        time.sleep(2)
        
        # 用浏览器打开并截图

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/cover_generator.py (reported line 71)May include surrounding context.

python
# 用浏览器打开并截图
        cmd = f"browser --browser-profile openclaw navigate http://localhost:18811/cover.html"
        subprocess.run(cmd, shell=True)
        time.sleep(3)
        
        cmd = f"browser --browser-profile openclaw screenshot --full-page --output {output_path}"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The browser screenshot tool is invoked through the shell with attacker-influenced output_path concatenated into the command string. In a publishing automation skill, command execution via a seemingly harmless output parameter is especially dangerous because it could be triggered through routine content-generation workflows and lead to arbitrary local code execution.

Content

Scanner excerpt · scripts/cover_generator.py (reported line 75)May include surrounding context.

python
time.sleep(3)
        
        cmd = f"browser --browser-profile openclaw screenshot --full-page --output {output_path}"
        result = subprocess.run(cmd, shell=True, capture_output=True)
        
        if result.returncode == 0:
            print(f"封面图片生成: {output_path}")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This is a real command-injection sink: the tool wrapper accepts a raw command string and passes it to a shell. In an agent skill that automates browser actions, this is especially dangerous because future integrations may pass user-controlled or model-generated values into the wrapper, turning ordinary automation into arbitrary OS command execution.

Content

Scanner excerpt · scripts/login_keeper.py (reported line 20)May include surrounding context.

python
# 替换 browser 为 openclaw browser
        if cmd.startswith("browser "):
            cmd = cmd.replace("browser ", "openclaw browser ", 1)
        result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
        return result.returncode == 0, result.stdout.strip()
    except Exception as e:
        return False, str(e)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

This is a true tool-parameter abuse issue because shell=True allows command strings to be interpreted by the shell instead of invoking the browser tool directly. Given the skill context, the script accepts user-provided publishing inputs and constructs commands for browser automation, making the command runner a dangerous primitive if any parameter such as an image path contains shell metacharacters or if future changes pass through more untrusted content.

Content

Scanner excerpt · scripts/publish.py (reported line 20)May include surrounding context.

python
# 替换 browser 为 openclaw browser
        if cmd.startswith("browser "):
            cmd = cmd.replace("browser ", "openclaw browser ", 1)
        result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
        return result.returncode == 0, result.stdout.strip()
    except Exception as e:
        print(f"命令执行失败: {e}")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README instructs users to log in and notes that the browser session will persist, but it does not explain the security implications of storing and reusing an authenticated session. Because this skill is built around browser automation against a creator account, a persisted session can be abused by local users, other tools, or follow-on automation to post content or access account data without re-authentication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README promotes automated publishing and even scheduled posting to a real Xiaohongshu account, but it does not clearly warn that running the examples will perform live actions on a logged-in account. In an automation skill whose purpose is end-to-end posting, this omission increases the risk of accidental publication, spammy behavior, or policy-violating posts triggered by users who assume the examples are dry-run or local-only.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents shell execution and filesystem writes but does not declare any explicit tool scope or permissions, making its effective capabilities broader and less auditable than users would expect. In an automation skill that can install persistence helpers and invoke scripts, missing scope declarations increase the chance of unsafe execution in environments that rely on metadata-based trust decisions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Advertising one-click or fully automated publishing without a prominent warning can lead users to post public content unintentionally, with limited ability to retract it before others view or archive it. In a social-media publishing context, that creates tangible reputational and account-safety risks even absent malicious intent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The workflow combines a logged-in browser profile with keepalive behavior and temporary local storage, which increases the chance that authenticated state persists beyond the user's expectation. That is especially sensitive for social-media accounts because any recovered session could be abused to publish, view, or manage account content without reauthentication.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

browser --browser-profile openclaw start

创建图片上传目录

mkdir -p /tmp/openclaw/uploads

text

### 2. 登录小红书创作平台

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The workflow combines a logged-in browser profile with keepalive behavior and temporary local storage, which increases the chance that authenticated state persists beyond the user's expectation. That is especially sensitive for social-media accounts because any recovered session could be abused to publish, view, or manage account content without reauthentication.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

browser --browser-profile openclaw start

创建图片上传目录

mkdir -p /tmp/openclaw/uploads

text

### 2. 登录小红书创作平台

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Bulk publishing automation against a public platform can cause accidental mass posting, spam, account penalties, or rapid dissemination of unintended content if misused or misconfigured. The risk is amplified because the feature is presented as straightforward to invoke without an accompanying warning about rate limits, review steps, or public impact.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
96% confidence
Finding

This command is built via string interpolation and executed with shell=True, which makes it vulnerable to shell injection if title, date_str, script path, or output path ever contain shell metacharacters or attacker-controlled content. In this skill, the function is part of an automated publishing pipeline, so future integration with external news/content sources would make this especially risky.

Content

Scanner excerpt · examples/daily_news.py (reported line 75)May include surrounding context.

python
cmd = f"python3 {cover_script} --title '{title}' --date '{date_str}' --output '{output_path}'"
    
    result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
    
    if result.returncode == 0:
        print(f"✅ 封面生成成功: {output_path}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
99% confidence
Finding

The publish command is assembled as a shell string using title, content, and cover_path, then executed with shell=True. Because content ultimately originates from news items and could later be sourced from APIs or user input, an attacker could inject shell syntax and achieve arbitrary command execution in the environment running the publisher.

Content

Scanner excerpt · examples/daily_news.py (reported line 91)May include surrounding context.

python
cmd = f"python3 {publish_script} --title '{title}' --content '{content}' --image '{cover_path}'"
    
    result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
    
    if result.returncode == 0:
        print("✅ 小红书发布成功!")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script performs a real external posting action automatically once prior steps succeed, without any explicit confirmation, dry-run mode, or warning at the point of publication. In an agent skill for social-media automation, this increases the chance of unintended or manipulated content being posted to a live account, creating operational and reputational harm.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Nearly all natural-language output in the script is presented only in Chinese, with no mechanism for the user to choose a language or locale. This can violate language/locale policy when a skill forces a specific language without explicit opt-in or documented regional limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script will automatically invoke the publishing workflow whenever command-line arguments are supplied, causing an external side effect without a confirmation step or strong warning. In a publishing automation skill, this increases the risk of accidental or unintended posting if the script is called by another tool, wrapper, or user who does not realize arguments trigger a live publish.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill’s title, descriptions, CLI messages, and generated content are all fixed in Chinese, including user-facing strings such as the subtitle and status output. There is no opt-in, language selection, or documented justification limiting the skill to Chinese-only behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest does mention image generation and browser automation as part of the overall toolkit, but this specific script's stated purpose and docstrings are only about generating a Xiaohongshu cover image. Instead of only rendering locally, it launches a background HTTP server and executes external browser commands, which are broader system-level capabilities than the file's declared image-conversion intent suggests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The function starts a local HTTP server and invokes browser-related shell commands via subprocess.run. While there are failure and success messages, there is no explicit warning before these operations that the script will launch background processes and open a browser session to render and capture the cover image.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.