xiaohongshu-create
v1.0.0小红书定制化创作技能 - 固定操作流程,提高发布成功率
⭐ 0· 64·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Skill name/description (Xiaohongshu post helper) matches the instructions: opening creator.xiaohongshu.com publish pages, pasting copy, choosing image generation, and posting. No unrelated capabilities or credentials are requested.
Instruction Scope
SKILL.md instructs the agent to use the browser tool to open official creator.xiaohongshu.com URLs, paste content, select styles, and confirm posting. It also says to "record to Feishu '已发布内容库'" — this is a plausible post-publication step but is underspecified (no details about which Feishu integration or creds are required). Otherwise the instructions do not reference unrelated files, system paths, or secret harvesting.
Install Mechanism
No install spec and no code files — instruction-only. Nothing is downloaded or written to disk.
Credentials
The skill declares no required environment variables or credentials. The only minor ambiguity is the Feishu recording step: if the agent/platform uses a Feishu integration, credentials would be managed by the platform, not this skill. No unexplained secret requests are present in the skill itself.
Persistence & Privilege
always is false and the skill is user-invocable. It does not request persistent/global privileges or attempt to modify other skills. It relies on the agent's browser and messaging tools, which is expected for this workflow.
Assessment
This is an instruction-only Xiaohongshu posting helper and appears internally consistent. Before installing: (1) confirm you trust the agent's browser and messaging tools because the skill requires the agent to open pages and interact with the site; (2) if you do not want automated notifications to Feishu, verify whether your agent/platform has a Feishu integration and disable it or deny the skill permission to use it; (3) run a test with dummy content to confirm behavior and that no unexpected endpoints are contacted; (4) if you need stronger assurance, ask the publisher for clarification on how the "记录到飞书" step is performed and what credentials, if any, it uses.Like a lobster shell, security has layers — review code before you run it.
latestvk97bmm0b4t1t2y0p0ckyq215fd84594s
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
