xhs-search-workflow
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is internally coherent for an XHS scraping/export workflow and appears to call Xiaohongshu directly, but it handles raw session cookies, persists local auth, and relies on third-party reverse-engineered signing/auth logic through an undisclosed setup script. Risk is driven more by sensitive credential handling and unverifiable install details than by clear malware or credential exfiltration.
Confidence: 81%Severity: 58%
Audit Metadata