Back to skill

Security audit

xiaohongshu-research-kit

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Xiaohongshu research helper, but it tells agents to use browser login cookies without enough safeguards or scoping.

Review before installing. Use it only for Xiaohongshu URLs you choose, approve any command that reads browser cookies, prefer a dedicated browser profile or site-limited cookie file, and install yt-dlp/gallery-dl only from sources you trust.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs use of `--cookies-from-browser` without warning that this accesses live authenticated browser session data, which may include sensitive cookies beyond the immediate task depending on tooling and user understanding. In an agent setting, this can normalize extracting privileged session material and create risk of over-collection, accidental exposure in logs, or misuse by downstream steps.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.