@borye

Xiaohongshu (小红书) Automation

Automate Xiaohongshu (RedNote) content operations using a Python client for the xiaohongshu-mcp server. Use for: (1) Publishing image, text, and video content, (2) Searching for notes and trends, (3) Analyzing post details and comments, (4) Managing user profiles and content feeds. Triggers: xiaohongshu automation, rednote content, publish to xiaohongshu, xiaohongshu search, social media management.

当前版本
v1.0.0
177 3.7万总安装 331

scripts/xhs_client.py

text/plain · 10169 字节

SKILL.md

text/markdown · 3843 字节

skill-card.md

text/markdown · 2046 字节

Security Scan

状态

suspicious

打开 VirusTotal

OpenClaw

gpt-5.5

suspicious

OpenClaw 分析

This skill is coherent for Xiaohongshu automation, but it asks users to run third-party local binaries tied to a logged-in account and includes a publish command without built-in confirmation.

置信度: high

VirusTotal

Type: OpenClaw Skill Name: xiaohongshu-mcp Version: 1.0.0 The skill is classified as suspicious due to its reliance on external, third-party binaries for core functionality. The `SKILL.md` explicitly instructs the user to download and execute `xiaohongshu-mcp` and `xiaohongshu-login` binaries from a GitHub repository, which then run a local server. While the bundled Python client (`scripts/xhs_client.py`) only communicates with this local server (`http://localhost:18060`) and does not exhibit direct malicious behavior (e.g., data exfiltration, remote execution), the requirement to run untrusted external executables introduces a significant supply chain risk and places a high trust burden on the user for a component outside the skill bundle's direct control.

元数据

  • 作者: @borye
  • 创建时间: 2026/02/01
  • 更新时间: 2026/05/17
  • 版本数: 1
  • 评论数: 0
  • 扫描时间: 2026/05/28

运行要求

官方公开数据里暂未列出运行要求。

Xiaohongshu (小红书) Automation | ClawHub 中文站