xiaohongshu

Fail

Audited by Snyk on Mar 6, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The skill requires extracting and reusing parameters like "xsec_token" (a secret-like token) from search/browse results and passing them into subsequent tool calls, which forces the agent to handle and emit secret values verbatim.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skills call MCP tools like search_feeds and get_feed_detail to fetch and analyze public user-generated Xiaohongshu notes and comments (see skills/xhs-content-plan/SKILL.md and skills/xhs-explore/SKILL.md), so the agent ingests untrusted third‑party content that can influence its analysis and actions.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
HIGH
Analyzed
Mar 6, 2026, 02:51 AM