xhs-cli

Warn

Audited by Socket on Mar 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
README.md

The codebase (as described in the README) represents a legitimate automation tool for interacting with Xiaohongshu via browser automation. While not inherently malicious, it enables data scraping and automated actions that could violate terms of service and raise privacy concerns. The main security considerations are handling of session cookies/tokens, secure storage of credentials, and ensuring compliance with platform policies. There is no evidence of malware in the provided fragment, but the tool’s capabilities could be abused if misused or if credentials are leaked.

Confidence: 52%Severity: 62%
AnomalyLOW
SKILL.md

该技能的核心能力与“小红书 CLI”目的基本一致,没有明显第三方凭证中转或明显恶意取证迹象,因此不像确认恶意。但它依赖浏览器自动化绕过官方 API、持久化登录 Cookie,并支持 --auto 自动发帖,这使其具备中等偏高风险,尤其在账号接管、误发帖和会话泄露方面。总体判断为 SUSPICIOUS 而非 MALICIOUS。

Confidence: 82%Severity: 63%
Audit Metadata
Analyzed At
Mar 16, 2026, 04:48 AM
Package URL
pkg:socket/skills-sh/0xranx%2Fagent-kit%2Fxhs-cli%2F@3d19ca9392d86fa3e718cb85582daef3886db10f