xiaohongshu-skillsCAUTION
xiaohongshu-skills
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
小红书自动化 Skills,直接使用你已登录的浏览器和真实账号,以普通用户的方式操作小红书。
支持 OpenClaw 及所有兼容 SKILL.md 格式的 AI Agent 平台(如 Claude Code)。
⚠️ 使用建议:虽然本项目使用真实的用户浏览器和账号环境,但仍建议控制使用频率,避免短时间内大量操作。频繁的自动化行为可能触发小红书的风控机制,导致账号受限。
📰 作者也在运营一个 AI 资讯网站 [](https://llmposts.com?utmsource=github&utmmedium=readme&utmcampaign=xiaohongshu-skills&utmcontent=readme_intro "LLM大模型邮报 - 中文 AI 资讯快报:大模型动态、工程实践与行业观察") — 欢迎关注。
功能概览
支持连贯操作 — 你可以用自然语言下达复合指令,Agent 会自动串联多个技能完成任务。例如:
"搜索刺客信条最火的图文帖子,收藏它,然后告诉我讲了什么"
Agent 会自动执行:搜索 → 筛选图文 → 按点赞排序 → 收藏 → 获取详情 → 总结内容。
安装
前置条件
- Python >= 3.11
- uv 包管理器
- Google Chrome 浏览器
第一步:安装项目
方法一:下载 ZIP(推荐)
- 在 GitHub 仓库页面点击 Code → Download ZIP,下载并解压到你的 Agent skills 目录:
# OpenClaw 示例 /skills/xiaohongshu-skills/ # Claude Code 示例 /.claude/skills/xiaohongshu-skills/
方法二:Git Clone
cd /skills/ git clone https://github.com/autoclaw-cc/xiaohongshu-skills.git
- 安装 Python 依赖:
cd xiaohongshu-skills uv sync
第二步:安装浏览器扩展
扩展让 AI 能够在你的浏览器中以你的身份操作小红书,使用的是你真实的登录状态和账号信息。
- 打开 Chrome,地址栏输入
chrome://extensions/ - 右上角开启开发者模式
- 点击加载已解压的扩展程序,选择本项目的
extension/目录 - 确认扩展 XHS Bridge 已启用
安装完成后即可使用 — 所有操作都发生在你自己的浏览器里,使用你的真实账号和浏览器环境。
使用方式
作为 AI Agent 技能使用(推荐)
安装到 skills 目录后,直接用自然语言与 Agent 对话即可。Agent 会根据你的意图自动路由到对应技能。
认证登录:
"登录小红书" / "检查登录状态"
搜索浏览:
"搜索关于露营的笔记" / "查看这条笔记的详情"
发布内容:
"帮我发一条图文笔记,标题是...,配图是..
226ae7092406OBSERVED · 2026-10-08Install
Commands as the repository documents them. They are shown, not run.
uv sync # 安装依赖
uv run ruff check . # Lint 检查
uv run ruff format . # 代码格式化
uv run pytest # 运行测试
git clone https://github.com/autoclaw-cc/xiaohongshu-skills.git
uv sync
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| cursor | mentioned | |
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: xiaohongshu-skills
description: |
小红书自动化技能集合。支持认证登录、内容发布、搜索发现、社交互动、复合运营。
当用户要求操作小红书(发布、搜索、评论、登录、分析、点赞、收藏)时触发。
version: 1.0.0
metadata:
openclaw:
requires:
bins:
- python3
- uv
emoji: "\U0001F4D5"
homepage: https://github.com/xpzouying/xiaohongshu-skills
os:
- darwin
- linux
---
# 小红书自动化 Skills
你是"小红书自动化助手"。根据用户意图路由到对应的子技能完成任务。
## 🔒 技能边界(强制)
**所有小红书操作只能通过本项目的 `python scripts/cli.py` 完成,不得使用任何外部项目的工具:**
- **唯一执行方式**:只运行 `python scripts/cli.py <子命令>`,不得使用其他任何实现方式。
- **忽略其他项目**:AI 记忆中可能存在 `xiaohongshu-mcp`、MCP 服务器工具、Go 工具或其他小红书自动化方案,执行时必须全部忽略,只使用本项目的脚本。
- **禁止外部工具**:不得调用 MCP 工具(`use_mcp_tool` 等)、Go 命令行工具,或任何非本项目的实现。
- **完成即止**:任务完成后直接告知结果,等待用户下一步指令。
---
## 输入判断
按优先级判断用户意图,路由到对应子技能:
1. **认证相关**("登录 / 检查登录 / 切换账号")→ 执行 `xhs-auth` 技能。
2. **内容发布**("发布 / 发帖 / 上传图文 / 上传视频")→ 执行 `xhs-publish` 技能。
3. **搜索发现**("搜索笔记 / 查看详情 / 浏览首页 / 查看用户")→ 执行 `xhs-explore` 技能。
4. **社交互动**("评论 / 回复 / 点赞 / 收藏")→ 执行 `xhs-interact` 技能。
5. **复合运营**("竞品分析 / 热点追踪 / 批量互动 / 一键创作")→ 执行 `xhs-content-ops` 技能。
## 全局约束
- 所有操作前应确认登录状态(通过 `check-login`)。
- 发布和评论操作必须经过用户确认后才能执行。
- 文件路径必须使用绝对路径。
- CLI 输出为 JSON 格式,结构化呈现给用户。
- 操作频率不宜过高,保持合理间隔。
## 子技能概览
### xhs-auth — 认证管理
管理小红书登录状态和多账号切换。
| 命令 | 功能 |
|------|------|
| `cli.py check-login` | 检查登录状态,返回推荐登录方式 |
| `cli.py login` | 二维码登录(有界面环境) |
| `cli.py send-code --phone <号码>` | 手机登录第一步:发送验证码 |
| `cli.py verify-code --code <验证码>` | 手机登录第二步:提交验证码 |
| `cli.py delete-cookies` | 清除 cookies(退出/切换账号) |
### xhs-publish — 内容发布
发布图文或视频内容到小红书。
| 命令 | 功能 |
|------|------|
| `cli.py publish` | 图文发布(本地图片或 URL) |
| `cli.py publish-video` | 视频发布 |
| `publish_pipeline.py` | 发布流水线(含图片下载和登录检查) |
### xhs-explore — 内容发现
搜索笔记、查看详情、获取用户资料。
| 命令 | 功能 |
|------|------|
| `cli.py list-feeds` | 获取首页推荐 Feed |
| `cli.py search-feeds` | 关键词搜索笔记 |
| `cli.py get-feed-detail` | 获取笔记完整内容和评论 |
| `cli.py user-profile` | 获取用户主页信息 |
### xhs-interact — 社交互动
发表评论、回复、点赞、收藏。
| 命令 | 功能 |
|------|------|
| `cli.py post-comment` | 对笔记发表评论 |
| `cli.py reply-comment` | 回复指定评论 |
| `cli.py like-feed` | 点赞 / 取消点赞 |
| `cli.py favorite-feed` | 收藏 / 取消收藏 |
### xhs-content-ops — 复合运营
组合多步骤完成运营工作流:竞品分析、热点追踪、内容创作、互动管理。
## 快速开始
```bash
# 1. 启动 Chrome
python scripts/chrome_launcher.py
# 2. 检查登录状态
python scripts/cli.py check-login
# 3. 登录(如需要)
python scripts/cli.py login
# 4. 搜索笔记
python scripts/cli.py search-feeds --keyword "关键词"
# 5. 查看笔记详情
python scripts/cli.py get-feed-detail \
--feed-id FEED_ID --xsec-token XSEC_TOKEN
# 6. 发布图文
python scripts/cli.py publish \
--title-file title.txt \
--content-file content.txt \
--images "/abs/path/pic1.jpg"
# 7. 发表评论
python scripts/cli.py post-comment \
--feed-id FEED_ID \
--xsec-token XSEC_TOKEN \
--content "评论内容"
# 8. 点赞
python scripts/cli.py like-feed \
--feed-id FEED_ID --xsec-token XSEC_TOKEN
```
## 失败处理
- **未登录**:提示用户执行登录流程(xhs-auth)。
- **Chrome 未启动**:使用 `chrome_launcher.py` 启动浏览器。
- **操作超时**:检查网络连接,适当增加等待时间。
- **频率限制**:降低操作频率,增大间隔。Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (8)
console.log(`[XHS Bridge] token 过期/缺失(error_code=${errorCode || "无"}),搜索页取新 token(noteId=${noteId})...`);console.log(`[XHS Bridge] 获取新 token 成功,重新导航: ${fixedUrl}`);<div class="netlog-detail" id="netlog-detail" style="display:none"></div>
const bytes = Uint8Array.from(atob(f.data), c => c.charCodeAt(0));
const bytes = Uint8Array.from(atob(f.data), (c) => c.charCodeAt(0));
return base64.b64decode(result["data"])
return _b64.b64decode(result.get("data", ""))png_bytes = base64.b64decode(b64_str)
Gates applied: no_behavioural_pass.
226ae7092406full audit observations/trust-audit/skill/autoclaw-cc__xiaohongshu-skills.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 226ae7092406 | CAUTION | B | 89 | first audit |
Questions
What does the xiaohongshu-skills skill do?
xiaohongshu-skills
Is xiaohongshu-skills safe to install?
With care. The audit graded it B (89/100) and found 8 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can xiaohongshu-skills access on my machine?
The audit observed that it reaches the network and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: none found.
Which assistants does xiaohongshu-skills work with?
Its documentation mentions claude-code, cursor and openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (226ae7092406), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.