xiaohongshu 小红书自动运营

ReviewAudited by ClawScan on May 10, 2026.

Overview

This skill mostly matches Xiaohongshu operations, but needs review because it can use a logged-in account and includes an under-scoped instruction to send screenshots to Feishu.

Before installing, use a dedicated Xiaohongshu browser profile, confirm the account before any public action, review drafts before publishing or replying, and do not allow Feishu screenshot uploads unless you explicitly choose the recipient and are comfortable sharing that page content.

Findings (5)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The agent may operate whichever Xiaohongshu account is logged into the OpenClaw profile.

Why it was flagged

The skill relies on a persistent browser profile that may already be logged into a Xiaohongshu account.

Skill content
固定使用内置浏览器 profile:`openclaw`...账号先登录创作后台,确认页面在 `openclaw` profile 可操作。
Recommendation

Use a dedicated browser profile, verify the logged-in account before each task, and keep final confirmation for any account-changing action.

What this means

If the user approves the final step, the agent can publish or reply publicly from the logged-in account.

Why it was flagged

The skill automates public posting and commenting workflows, but documents confirmation and rate limits.

Skill content
到达“发布”按钮可见处停手,默认不直接点击发布。... 默认 one-send-per-turn(如无明确要求不连发)。
Recommendation

Keep the documented stop-before-publish and one-reply-per-turn safeguards, and review content before approving sends.

What this means

Past records could expose sensitive campaign/account context locally or influence future outputs if inaccurate.

Why it was flagged

The skill creates persistent local records that may include URLs, screenshots, account names, and action history, then reuses them in later tasks.

Skill content
每次完成分析、发布、回复、复刻后补写结果...结论要带证据指针:来源笔记、帖子 URL、截图、时间点、操作结果。
Recommendation

Avoid storing secrets or private personal data, periodically review/delete the knowledge base, and treat stored platform content as reference rather than authoritative instruction.

What this means

Draft posts, account details, or page screenshots could be shared to an unintended external chat or workspace.

Why it was flagged

The skill directs screenshots to Feishu, but the artifacts do not define the Feishu workspace, recipient, approval step before upload, or redaction rules.

Skill content
若涉及截图确认,优先附件形式发送到飞书,并在用户确认后再发布。
Recommendation

Make local preview the default; require explicit user approval before any Feishu upload; specify the exact recipient/workspace; redact sensitive page details; and declare the Feishu integration in metadata.

What this means

Installing the add-on could expand the agent’s capabilities and data flows beyond this skill.

Why it was flagged

The skill suggests installing a separate skill that is not included in the reviewed artifacts.

Skill content
如未安装生图技能,可先执行 `clawhub install nano-banana-pro`。
Recommendation

Install the suggested add-on only if needed, and review that separate skill before use.