T08 · Insecure Dependencies
- Location
SKILL.md:19- Finding
Unpinned Third-Party Dependencies Installed from Mutable Sources
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears purpose-built for Xiaohongshu research, but it repeatedly asks agents to use a local Chrome browser session without clearly warning users about cookie sensitivity or profile isolation.
Review before installing. Use a dedicated browser profile containing only the Xiaohongshu account needed for research, avoid sharing cookie-derived outputs, and prefer pinned or isolated installs of yt-dlp and gallery-dl. The artifacts do not show malicious code, but the cookie workflow gives local third-party tools access to authenticated browser session data.
SKILL.md:19Unpinned Third-Party Dependencies Installed from Mutable Sources
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
lp and gallery-dl locally — no API key required.
Version: 1.0.0 Prerequisites: yt-dlp >= 2024.01.01, gallery-dl >= 1.26.0
# macOS
brew install yt-dlp gallery-dl
# pip
pip install yt-dlp gallery-dl
# Verify
yt-dlp --version && gallery-dl --version
Xiaohongshu requires cookies for most content. Export browser cookies:
yt-dlp --cookies-from-browser chrome "URL"
gallery-dl --cookies-from-browser chrome "URL"
Extract title, description, engagement stats from a video note.
yt-dlp --dump-json --skip-download --cookies-from-browser chrome \
"https://www.xiaohongshu.com/explore/NOTE_ID"
Key JSON fields:
| Field | JSON path |
|---|---|
| Title | .title |
| Description | .description |
| Author | .uploader |
| Upload date | .upload_date (YYYYMMDD → YYYY-MM-DD) |
| Views | .view_count |
| Likes | .like_count |
| Comments | ` |
The skill repeatedly instructs use of --cookies-from-browser to access protected Xiaohongshu content but does not warn that browser cookies are authenticated session artifacts. In an agent/tooling context, normalizing extraction of browser cookies can expose account sessions, personal data, or cross-site authenticated access if users run commands without understanding the sensitivity of those credentials.
No suspicious patterns detected.