xiaohongshu-note-creator

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core behavior is mostly aligned with its purpose: it reads WPS notes, rewrites them into Xiaohongshu format, writes results back, and can generate images. The main security concerns are moderate rather than overtly malicious: note content and images may be sent to external image providers, provider credentials are retrieved from notes and forwarded to an unreviewed local script, and the workflow performs automatic note writes. No clear credential-harvesting or unrelated capability is present, but the local script and external data flows make this higher risk than a pure documentation/content-formatting skill.

Confidence: 79%Severity: 56%
Audit Metadata
Analyzed At
Apr 7, 2026, 04:01 AM
Package URL
pkg:socket/skills-sh/wpsnote%2Fwpsnote-skills%2Fxiaohongshu-note-creator%2F@1f9500a922098ee226a60023a61bd056b9a6d996