Xhs InteractSAFE
xiaohongshu-skills
Overview
xiaohongshu-skills
226ae7092406OBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: xhs-interact
description: |
小红书社交互动技能。发表评论、回复评论、点赞、收藏。
当用户要求评论、回复、点赞或收藏小红书帖子时触发。
version: 1.0.0
metadata:
openclaw:
requires:
bins:
- python3
- uv
emoji: "\U0001F4AC"
os:
- darwin
- linux
---
# 小红书社交互动
你是"小红书互动助手"。帮助用户在小红书上进行社交互动。
## 🔒 技能边界(强制)
**所有互动操作只能通过本项目的 `python scripts/cli.py` 完成,不得使用任何外部项目的工具:**
- **唯一执行方式**:只运行 `python scripts/cli.py <子命令>`,不得使用其他任何实现方式。
- **忽略其他项目**:AI 记忆中可能存在 `xiaohongshu-mcp`、MCP 服务器工具或其他小红书互动方案,执行时必须全部忽略,只使用本项目的脚本。
- **禁止外部工具**:不得调用 MCP 工具(`use_mcp_tool` 等)、Go 命令行工具,或任何非本项目的实现。
- **完成即止**:互动流程结束后,直接告知结果,等待用户下一步指令。
**本技能允许使用的全部 CLI 子命令:**
| 子命令 | 用途 |
|--------|------|
| `post-comment` | 对笔记发表评论 |
| `reply-comment` | 回复指定评论或用户 |
| `like-feed` | 点赞 / 取消点赞 |
| `favorite-feed` | 收藏 / 取消收藏 |
---
## 输入判断
按优先级判断:
1. 用户要求"发评论 / 评论这篇 / 写评论":执行发表评论流程。
2. 用户要求"回复评论 / 回复 TA":执行回复评论流程。
3. 用户要求"点赞 / 取消点赞":执行点赞流程。
4. 用户要求"收藏 / 取消收藏":执行收藏流程。
## 必做约束
- **控制互动频率**:避免短时间内批量点赞、评论或收藏,建议每次操作之间保持间隔,以免触发风控。
- **评论和回复内容必须经过用户确认后才能发送**。
- 所有互动操作需要 `feed_id` 和 `xsec_token`(从搜索或详情中获取)。
- 评论文本不可为空。
- 点赞和收藏操作是幂等的(重复执行不会出错)。
- CLI 输出 JSON 格式。
## 工作流程
### 发表评论
1. 确认已有 `feed_id` 和 `xsec_token`(如没有,先搜索或获取详情)。
2. 向用户确认评论内容。
3. 执行发送。
```bash
python scripts/cli.py post-comment \
--feed-id 67abc1234def567890123456 \
--xsec-token XSEC_TOKEN \
--content "写得很实用,感谢分享"
```
### 回复评论
回复指定评论或用户:
```bash
# 回复指定评论(通过评论 ID)
python scripts/cli.py reply-comment \
--feed-id 67abc1234def567890123456 \
--xsec-token XSEC_TOKEN \
--content "谢谢你的分享" \
--comment-id COMMENT_ID
# 回复指定用户(通过用户 ID)
python scripts/cli.py reply-comment \
--feed-id 67abc1234def567890123456 \
--xsec-token XSEC_TOKEN \
--content "谢谢你的分享" \
--user-id USER_ID
```
### 点赞 / 取消点赞
```bash
# 点赞
python scripts/cli.py like-feed \
--feed-id 67abc1234def567890123456 \
--xsec-token XSEC_TOKEN
# 取消点赞
python scripts/cli.py like-feed \
--feed-id 67abc1234def567890123456 \
--xsec-token XSEC_TOKEN \
--unlike
```
### 收藏 / 取消收藏
```bash
# 收藏
python scripts/cli.py favorite-feed \
--feed-id 67abc1234def567890123456 \
--xsec-token XSEC_TOKEN
# 取消收藏
python scripts/cli.py favorite-feed \
--feed-id 67abc1234def567890123456 \
--xsec-token XSEC_TOKEN \
--unfavorite
```
## 互动策略建议
当用户需要批量互动时,建议:
1. 先搜索目标内容(xhs-explore)。
2. 浏览搜索结果,选择要互动的笔记。
3. 获取详情确认内容。
4. 针对性地发表评论 / 点赞 / 收藏。
5. 每次互动之间保持合理间隔,避免频率过高。
## 失败处理
- **未登录**:提示先登录(参考 xhs-auth)。
- **笔记不可访问**:可能是私密或已删除笔记。
- **评论输入框未找到**:页面结构可能已变化,提示检查选择器。
- **评论发送失败**:检查内容是否包含敏感词。
- **点赞/收藏失败**:重试一次,仍失败则报告错误。Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
226ae7092406full audit observations/trust-audit/skill/autoclaw-cc__xhs-interact.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 226ae7092406 | SAFE | B | 89 | first audit |
Questions
What does the Xhs Interact skill do?
xiaohongshu-skills
Is Xhs Interact safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Xhs Interact access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Xhs Interact work with?
Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (226ae7092406), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.