redbook-creator-publish

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill fragment presents a cohesive, multi-stage automation pipeline for generating Xiaohongshu posts and uploading them via a browser-driven workflow. The automation is consistent with the stated purpose (content generation, image handling, local previews, and automatic publishing). While the auto-upload feature reduces friction and could be convenient, it also increases risk of unintended posts if used inappropriately or on compromised machines. There are no hardcoded secrets or suspicious data exfiltration patterns; credentials are user-provided via browser login. Overall, the footprint is coherent with the stated aim but should be treated as suspicious from a strict supply-chain perspective due to automatic external actions and browser automation; classify as SUSPICIOUS to BENIGN leaning toward SUSPICIOUS depending on deployment controls.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 03:09 AM
Package URL
pkg:socket/skills-sh/happycapy-ai%2FHappycapy-skills%2Fredbook-creator-publish%2F@6f0e70c688cdec4931744fbe87fb41c1a7677ee9