How we read this cluster
These are the suites: login plus publish plus analytics plus reply handling bundled into one install. They dominate the download counts in the snapshot, and the same property that makes them popular — one command covers everything — is what makes them the largest blast radius if a selector or an endpoint changes underneath you.
Read the dependency list before the feature list. A suite that silently requires a real logged-in browser session is doing something very different from one that only reads public pages, even when the marketing copy is identical.
How demand is distributed
The single highest-scoring row accounts for 51% of this cluster's downloads.
Risk mix
These labels ship with the snapshot. They are not an official grading and they are not ours. Our reading is to treat the label as a question: does this row only read public content, or does it need your session, or does it publish for you? Low roughly means "never touches your account"; High roughly means "touches it in a way other people can see".
Top rows by opportunity score
| Skill | Downloads | Installs | Risk |
|---|---|---|---|
xiaohongshu-mcp |
18,265 | 169 | High |
xhs |
8,461 | 43 | High |
xiaohongshu-ops |
1,827 | 26 | High |
xhs-skill |
2,158 | 16 | High |
xiaohongshu |
2,163 | 10 | High |
Where these numbers come from
How to verify a row before you install it
- Check the skill's own repository or documentation. The shared source page behind this snapshot is a starting point; it is not evidence that the row is still maintained.
- Read the risk label as an action question: does it only read public content, or does it need a logged-in session, or does it publish on your behalf?
- Run it once in an isolated session or a test account. Do not make the first attempt on your main account.
- Write down the single smallest thing you want it to do, then check only that after the first run.