Back to skill

Security audit

AI Content — Xiaohongshu Content Production

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed content-production workflow that uses external sources and AI providers, with no evidence of hidden or destructive behavior.

Install only if you are comfortable running the referenced external app locally. Review its dependencies before use, use limited-scope AI-provider keys, avoid adding private or internal sources unless intended, and manually review generated content before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger list is unusually broad and includes generic phrases like content creation, article writing, template management, and topic discovery. In an agent environment, this can cause the skill to activate for ordinary user requests unrelated to this workflow, increasing the chance of unintended data access, external collection actions, or prompting users into a more powerful content pipeline than expected.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill advertises RSS/API/web collection and third-party model/provider configuration without warning that content may be fetched from external sources and transmitted to external AI services. In an agent context, this omission can lead users to unknowingly expose private materials, internal URLs, or copyrighted/sensitive content to outside systems.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.