Back to skill

Security audit

xiaohongshu-research-kit

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-built for Xiaohongshu research, but it repeatedly asks agents to use a local Chrome browser session without clearly warning users about cookie sensitivity or profile isolation.

Review before installing. Use a dedicated browser profile containing only the Xiaohongshu account needed for research, avoid sharing cookie-derived outputs, and prefer pinned or isolated installs of yt-dlp and gallery-dl. The artifacts do not show malicious code, but the cookie workflow gives local third-party tools access to authenticated browser session data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:19
Finding

Unpinned Third-Party Dependencies Installed from Mutable Sources

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

lp and gallery-dl locally — no API key required.

Version: 1.0.0 Prerequisites: yt-dlp >= 2024.01.01, gallery-dl >= 1.26.0

Prerequisites

bash
# macOS
brew install yt-dlp gallery-dl

# pip
pip install yt-dlp gallery-dl

# Verify
yt-dlp --version && gallery-dl --version

Authentication

Xiaohongshu requires cookies for most content. Export browser cookies:

bash
yt-dlp --cookies-from-browser chrome "URL"
gallery-dl --cookies-from-browser chrome "URL"

Operations

1. Note Metadata (Video Notes)

Extract title, description, engagement stats from a video note.

bash
yt-dlp --dump-json --skip-download --cookies-from-browser chrome \
  "https://www.xiaohongshu.com/explore/NOTE_ID"

Key JSON fields:

FieldJSON path
Title.title
Description.description
Author.uploader
Upload date.upload_date (YYYYMMDD → YYYY-MM-DD)
Views.view_count
Likes.like_count
Comments`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill repeatedly instructs use of --cookies-from-browser to access protected Xiaohongshu content but does not warn that browser cookies are authenticated session artifacts. In an agent/tooling context, normalizing extraction of browser cookies can expose account sessions, personal data, or cross-site authenticated access if users run commands without understanding the sensitivity of those credentials.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.