← 返回 Skills 市场
yikailucas

xhs Agent

作者 Lucas · GitHub ↗ · v0.1.3
cross-platform ⚠ suspicious
1237
总下载
5
收藏
12
当前安装
4
版本数
在 OpenClaw 中安装
/install xhs-browser-ops
功能描述
xhs 全流程助手,覆盖小红书内容策划、文案与标题生成、封面制作、笔记发布及日常运营管理。适用于写笔记、生成标题/封面、发布或保存草稿、站内搜索、评论互动(点赞/收藏/回复)等小红书相关任务。支持从内容创作到发布执行的一站式流程;封面 AI 生图可选配置 GEMINI_API_KEY、IMG_API_KEY 或...
安全使用建议
This instruction-only skill appears to do what it claims (automate publishing on Xiaohongshu) but has a documentation inconsistency: the description mentions optional AI image API keys that are not declared or used in the runtime instructions. Before installing or enabling it, ask the skill author to clarify whether cover-generation calls will be made and, if so, which environment variables are required and how keys are stored/used. Be aware the skill operates through your browser login: it can create drafts, post, reply, and read dashboard info in that session. To reduce risk, test with draft-only mode first, avoid supplying API keys until you understand why they're needed, and ensure you will be prompted for final confirmation before any publish action. If you don't trust the author or can't get clarification, avoid installing or restrict usage to manual/draft workflows.
功能分析
Type: OpenClaw Skill Name: xhs-browser-ops Version: 0.1.3 The skill bundle is designed for Xiaohongshu (Redbook) content management via browser automation. The `SKILL.md` instructions are clear, well-defined, and include several safety measures, such as requiring explicit user confirmation for publishing, prohibiting bypassing CAPTCHA/SMS, and defaulting to 'draft-only' for vague user input. There is no evidence of data exfiltration, malicious execution, persistence mechanisms, or prompt injection attempts against the agent. The mention of API keys for AI image generation is a feature, not an instruction to steal credentials. All content aligns with the stated purpose.
能力评估
Purpose & Capability
The name/description and SKILL.md both describe a browser-automation Xiaohongshu (小红书) publishing assistant (drafts, publish, replies, metrics). That purpose is coherent with the step-by-step publish flow and confirmation policy. However, the description mentions optional cover-generation API keys (GEMINI_API_KEY, IMG_API_KEY, HUNYUAN_API_KEY) while the skill metadata declares no required environment variables and SKILL.md contains no instructions about calling those image-generation services. This mismatch is unexplained and could be a missing integration or incomplete docs.
Instruction Scope
SKILL.md stays largely within scope: it requires using the official creator site, explicit SMS/CAPTCHA handling by the user, a strict publish confirmation policy, and stepwise publish/draft flows. It does allow actions beyond publishing (reply to comments/messages, check metrics) but only the publish action is gated by an explicit confirmation requirement. The doc does not instruct reading unrelated system files or environment variables. Consider whether replies or other write actions should also require explicit confirmation.
Install Mechanism
This is an instruction-only skill with no install spec and no code files, so nothing is written to disk or installed. That is the lowest-risk install mechanism and matches its described browser-automation role.
Credentials
Metadata shows no required environment variables, but the description mentions optional GEMINI_API_KEY / IMG_API_KEY / HUNYUAN_API_KEY for AI-generated covers. These keys are not declared in requires.env nor referenced in SKILL.md; it's unclear if the skill will ever ask for or use such keys. This is an unexplained discrepancy: if cover-generation features exist, they would legitimately need API keys — the skill should declare them and document when/how they'll be used. Also note the skill acts on the user's logged-in web session (browser cookies/SMS), which effectively grants it ability to post on the user's account; that is expected for this purpose but is a sensitive capability.
Persistence & Privilege
always:false and no installation hooks are set. The skill will act via the current browser session and can be invoked autonomously by the agent (the platform default). Autonomous invocation combined with publish capability increases blast radius, but SKILL.md requires explicit confirmation for publishes which mitigates that particular risk. The skill does not request persistent system-wide privileges or modify other skills.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install xhs-browser-ops
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /xhs-browser-ops 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v0.1.3
Refine description wording for xhs all-in-one workflow
v0.1.2
Update description: all-in-one Xiaohongshu assistant with copy, cover, publish and engagement workflows
v0.1.1
Rename package display name to xhs Agent
v0.1.0
Rename skill to XHS and keep browser publishing workflow
元数据
Slug xhs-browser-ops
版本 0.1.3
许可证
累计安装 12
当前安装数 12
历史版本数 4
常见问题

xhs Agent 是什么?

xhs 全流程助手,覆盖小红书内容策划、文案与标题生成、封面制作、笔记发布及日常运营管理。适用于写笔记、生成标题/封面、发布或保存草稿、站内搜索、评论互动(点赞/收藏/回复)等小红书相关任务。支持从内容创作到发布执行的一站式流程;封面 AI 生图可选配置 GEMINI_API_KEY、IMG_API_KEY 或... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 1237 次。

如何安装 xhs Agent?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install xhs-browser-ops」即可一键安装,无需额外配置。

xhs Agent 是免费的吗?

是的,xhs Agent 完全免费(开源免费),可自由下载、安装和使用。

xhs Agent 支持哪些平台?

xhs Agent 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 xhs Agent?

由 Lucas(@yikailucas)开发并维护,当前版本 v0.1.3。

💬 留言讨论