write-xiaohongshu

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is consistent with its stated purpose and contains expected high-privilege operations (reading posts/comments and publishing). Primary risks are operational: (1) autonomy risk from publish capability — require explicit per-post user confirmation and audit logs; (2) credential/token handling — enforce least privilege, secure storage, and short token lifetimes; (3) data privacy — avoid storing verbatim comments, redact identifiers; (4) external image sourcing — prefer known stock providers, rehost or scan images. I found no evidence of obfuscated code, embedded backdoors, or explicit exfiltration endpoints in the provided specification. Treat as low-to-moderate security risk that can be mitigated by the recommendations above.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 3, 2026, 06:02 AM
Package URL
pkg:socket/skills-sh/adjfks%2Fcorner-skills%2Fwrite-xiaohongshu%2F@616932cd2690be335f011f6a7d84ccf042c6472b