Back to skill

Security audit

XHS Publisher

Security checks for vulnerabilities and agentic risk

Overview

This skill is a mostly coherent Xiaohongshu publishing helper, but it can publish to a real account without an explicit final confirmation and includes loosely scoped account/profile actions.

Review before installing. Use this skill only when you intentionally want an agent to operate an already logged-in Xiaohongshu creator session, and require a manual confirmation before any publish click. Avoid using the broad account-management or profile-fetching parts unless you have a clear, authorized reason.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger description includes broad language such as managing a Xiaohongshu account, which can cause the skill to activate for requests beyond publishing. In an automation context, over-broad invocation increases the chance of the agent taking sensitive account actions the user did not specifically intend.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow proceeds to clicking the live publish button without requiring an explicit confirmation step immediately before posting. Because publishing is an external side-effect on a real user account, omission of a final consent gate can lead to accidental or premature public posting, reputational harm, or policy-violating content being published.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is scoped as a publisher for posting notes, but it also documents fetching profile information from Xiaohongshu user pages. That expands the capability into profile data collection unrelated to the core task, which can enable unnecessary scraping of account metadata and creates privacy and misuse risk beyond expected publishing behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The profile-access instructions tell the agent to open a user profile page and extract follower counts and note counts, but they do not include any privacy warning, scope limitation, or consent guidance. Even if the data is publicly viewable, automating its retrieval can normalize collection of account information outside the skill's main publishing purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.