xiaohongshu-hub

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该技能与“小红书自动化客户端”目的基本一致,但其实际能力偏高风险:依赖浏览器会话 Cookie、包含反风控/逆向签名,并可代用户执行公开账号操作。未见明显第三方凭证转发或确认恶意窃取,因此更适合判定为高风险可疑自动化技能,而非确认恶意软件。

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Mar 28, 2026, 11:50 AM
Package URL
pkg:socket/skills-sh/OpenMinis%2FMinisSkills%2Fxiaohongshu-hub%2F@1d1fa8ae4a6027a0ef31fe5dd3480b5ce16bc986