xhs-cli

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is coherent with its stated Xiaohongshu automation purpose, and installation comes from PyPI with verifiable provenance, so it is not outright malicious. However, it delegates browser-cookie login and all account actions to a personal third-party reverse-engineered CLI and enables autonomous public actions, creating meaningful credential-handling and account-abuse risk.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Apr 28, 2026, 08:02 AM
Package URL
pkg:socket/skills-sh/Lionad-Morotar%2Fxhs-cli-skill%2Fxhs-cli%2F@9b69c6607f4e2c933dd243c346265519ba269954