xiaohongshu-workflow
Fail
Audited by Socket on Mar 5, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The skill description is coherent with its stated automation purpose and provides a reasonably complete workflow for Xiaohongshu MCP-based operations. However, it involves sensitive credential handling (cookies), third-party binary downloads, and multi-script memory export flows that expand the trust surface. These patterns warrant cautious review and verifiable integrity controls (signatures/checksums, restricted cookie handling, and minimized data exposure). Overall risk is present but not definitively malicious; treat as SUSPICIOUS with recommended mitigations rather than BENIGN.
Confidence: 65%Severity: 60%
Audit Metadata