xhs-publisher

Fail

Audited by Socket on Mar 2, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment describes a comprehensive Xiaohongshu automation tool, with reasonable features for login persistence, multi-account handling, AI content/image generation, and scheduling/analytics. No explicit malicious activity is evident. However, the combination of local credential stores, a keystore with encryption, and potential local proxies expands the risk surface if access controls and secure handling are not properly implemented. Prioritize robust access controls, encryption-at-rest, minimized logging of sensitive data, secure proxy configuration, and explicit TLS usage for external communications. Overall securityRisk is moderate with actionable hardening recommendations.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 2, 2026, 10:56 AM
Package URL
pkg:socket/skills-sh/PengJiyuan%2Fxhs-skill%2Fxhs-publisher%2F@fd0132be8406bd394a6c5df68d623d9ee63e27db