小红书商业洞察与竞品分析助手

AdvisoryAudited by VirusTotal on Apr 17, 2026.

Overview

Type: OpenClaw Skill Name: xiaohongshu-tool Version: 1.0.2 The skill bundle is a legitimate data mining tool for Xiaohongshu (Red) analytics, acting as a wrapper for the Guaikei API. It implements robust input validation for keywords (src/validate/keyword.js) and URLs (src/validate/url.js) to prevent injection, uses standard Node.js HTTPS modules without external dependencies to minimize supply chain risks, and includes clear documentation for the OpenClaw agent. No evidence of data exfiltration, malicious execution, or prompt injection was found; the use of a hardcoded default API token (src/utils/key.js) is transparently handled as a fallback for trial purposes.