xhs-profile

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS:技能目的本身合理,但对 xsec_token 的使用、未披露的实际 API 端点,以及对第三方 xhs-login 技能的依赖,使其数据流和供应链边界不透明。未见直接恶意或明显窃密行为,但整体信任链不足,风险中等。

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Mar 24, 2026, 07:59 AM
Package URL
pkg:socket/skills-sh/autoclaw-cc%2Fxiaohongshu-mcp-skills%2Fxhs-profile%2F@21c0fc8c1b73d348d166daf3b544181849f27f16