← Back to Scanner

xiaohongshu Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

xiaohongshu is an AI agent skill, created by zhjiang22 and published at zhjiang22/openclaw-xhs. ClawSecure audited xiaohongshu across 24 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 66/100 (Medium Risk). The 9 findings concentrate in Unauthorized Tool Use, Data Exfiltration and Supply Chain Attack, including Undeclared Network Access and Suspicious Pattern: urllib.request.Request(. None were rated high or critical severity.

Is xiaohongshu safe?

ClawSecure audited xiaohongshu and assigned a security score of 66/100 (Medium Risk), identifying 9 findings across Unauthorized Tool Use and Data Exfiltration. Review the findings below before installing.

What did ClawSecure find in xiaohongshu?

ClawSecure identified 9 findings in xiaohongshu, concentrated in Unauthorized Tool Use, Data Exfiltration and Supply Chain Attack. The most severe include Undeclared Network Access and Suspicious Pattern: urllib.request.Request(.

How was xiaohongshu audited?

ClawSecure ran xiaohongshu through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 24 files from zhjiang22/openclaw-xhs.

What does a score of 66 mean?

ClawSecure assigned xiaohongshu a security score of 66/100, placing it in the Medium Risk range. This reflects 9 findings led by Unauthorized Tool Use that warrant review before production use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for xiaohongshu

ClawSecure detected 9 security findings in xiaohongshu, spanning Unauthorized Tool Use, Data Exfiltration, Supply Chain Attack and Command Injection.

Each finding is expandable in the interactive list below.

3-Layer Audit Protocol

Security Recommendations for xiaohongshu

Audit external network connections
xiaohongshu sends data to external endpoints. Confirm each destination is expected and authorized, and remove any callback that exfiltrates data. ClawSecure monitors for known exfiltration and C2 endpoints.
Harden command execution
xiaohongshu constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Add a config.json permissions manifest
A config.json file declares what an agent component can access: file system, network, shell execution and more. Without it, users have no visibility into what the component can do before installing. This is the single most impactful security improvement for any AI agent skill.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI AgentsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

clawhubScore 75/100GitNexusScore 75/100@soimy/dingtalkScore 75/100openclawScore 55/100antigravity-awesome-skillsScore 75/100

Scanned on March 15, 2026. xiaohongshu is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan