xiaohongshu
Audited by Socket on Mar 10, 2026
1 alert found:
Obfuscated FileThe Xiaohongshu skill presents a coherent capability set for authenticated data collection and interaction with XiaoHongShu, including search, notes, comments, user actions, and home feed access. The use of cookies and encryption parameters is consistent with the stated purpose of handling login states and anti-scraping defenses, but it introduces elevated credential sensitivity and potential privacy concerns. The install path uses standard PyPI packages, which is acceptable, though the tool’s reliance on proxies and encryption configs to circumvent protections introduces risk. Overall, the footprint is moderately coherent with its purpose but carries notable security/privacy considerations due to credential handling, proxy usage, and anti-scraping circumvention. Treat as SUSPICIOUS with a leaning toward BENIGN, given the legitimate data-collection intent but with high credential/data-flow risk if misused or deployed in untrusted contexts.