xiaohongshu-workflow

Fail

Audited by Socket on Mar 13, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s purpose matches social-media operations, but its footprint is high-risk. It asks the agent to install third-party binaries and a cloned downloader, handle raw session cookies, transfer those cookies to servers, export account data into long-lived memory, and perform public posting/commenting actions. These behaviors are broadly consistent with the stated purpose, so this is not confirmed malware, but the credential handling, supply-chain exposure, and autonomous public-action scope make it a high-risk skill.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Mar 13, 2026, 07:03 AM
Package URL
pkg:socket/skills-sh/aAAaqwq%2FAGI-Super-Team%2Fxiaohongshu-workflow%2F@dd23b44444282548146eded88b7c418997aa962f