Back to skill

Security audit

开源小红书技能

Security checks across malware telemetry and agentic risk

Overview

This skill is for managing a Xiaohongshu account, but it gives broad account-changing and message-access capabilities without clear safeguards.

Install only if you intentionally want an agent to help manage a real Xiaohongshu account. Before providing credentials or enabling real API calls, require per-action confirmation for posting, deleting, replying, blacklisting, profile edits, and account linking; review affected note/comment/user IDs before bulk actions; and treat private messages and linked-account data as sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly advertises destructive actions such as deleting notes and comments, but it does not warn about irreversibility, require confirmation, or describe safeguards. In an agent context, this increases the risk of accidental or overly broad deletion causing permanent content loss or account disruption.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill includes capabilities to view and reply to private messages and to link external accounts, but it does not disclose the privacy sensitivity of accessing user communications or connected account data. In practice, these features can expose sensitive personal information, enable unintended data access, or expand the blast radius if credentials are mishandled.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.