Risk guide

RedSkill Automation Risk Levels for Xiaohongshu Skills

How to grade RedSkill and Xiaohongshu Skills automation risk: the 81 high-risk rows in our snapshot, account-safety signals and a manual-first rollout plan.

Why risk comes before popularity

Download counts tell you what other people tried. They do not tell you what it cost them. In a young ecosystem those two things come apart quickly, because a Skill that automates something risky gets attention precisely because it automates something risky.

Worse, a download count is a record of a decision made under different information. The person who downloaded a publishing bot six months ago was choosing between two unfamiliar options. You are choosing with a category map in front of you, and you can order your own rollout instead of following theirs.

What the three labels mean here

The labels in our snapshot are not an official grading and they are not ours. We use them as an action question, which is the only reading that changes what you do next:

  1. Low — the Skill never touches your account.It reads public pages or writes a file to your own disk. The worst outcome is a bad output file.
  2. Medium — the Skill acts, but reversibly, or reads at volume.A single public action, or a collection job large enough that the platform may treat it as scraping. Recoverable, but visible.
  3. High — the Skill needs your session, publishes for you, or acts in bulk.A mistake here is visible to other people and expensive to undo, because it happens as you.

The label is a starting point, not a verdict. Two Skills with the same label can differ enormously once you read the file: one asks for confirmation before publishing, the other does not. Reading the SKILL.md is what turns the label into a decision.

What the distribution says

81High-risk rows
16Medium-risk rows
39Low-risk rows
4 of 8clusters with zero Low rows
ClusterRowsLowMediumHighDownloads
Content creation2725207,887
Publishing automation2600267,174
Comprehensive operations23002335,824
Login, MCP, Mac and CLI1900196,128
Data and analytics18010810,089
Image and card generation1414001,090
Interaction and comments5005268
Video download and analysis4040849

The headline is not that risky Skills exist. It is that the risky clusters are where the audience is: four clusters contain 73 High-risk rows and take 71% of every download in the snapshot, while the two clusters that never touch your account take about 13%. If you order your own rollout by what the crowd did, you start with the hardest thing first.

Signals that should stop you

Any one of these is a reason to pause rather than a reason to refuse. Together they are a description of a Skill you should not install until you have read every line of it.

  • It asks for your session and does not say so up front.Honest projects lead with this. A README that never mentions how it authenticates is telling you something.
  • It has no confirmation step before a public action.Drafting and publishing are different products. If the file does not stop before publishing, you are the confirmation step, and only if you are watching.
  • Its install path pipes a remote script into a shell.The documented RedSkill installer does exactly this, so it is normal in this ecosystem — which is precisely why you should open the URL and read it instead of treating normality as safety.
  • It skips integrity verification.Reported behaviour for the official CLI is a zip plus a sha256 check, and the same reporting saw installs fail when that check was missing. Prefer the version that refuses.
  • It acts in bulk without a rate limit you can see.Volume is what platform terms constrain, regardless of your intent or the quality of the output.
  • Its only documentation is a screenshot.If the install command arrived as an image in a chat message, you have no way to check what changed since it was written.

A rollout order that protects your account

  1. Start with a Low row, even if you do not need it.Pick something in image and card generation or content creation. The point of the first run is to learn how installs behave on your machine, with nothing at stake.
  2. Write down one success condition before you install."It should produce three drafts from this product page" is testable. "It should improve my content" is not, and it will make you keep a broken Skill installed.
  3. Move to a Medium row second.A single public action or a bounded read. Watch what it writes, where it writes it, and whether it stopped when it should have.
  4. Only then consider a High row, and never on your main account first.Use a test account or an isolated session, keep the first run small, and keep the manual step manual for at least a full cycle.
  5. Record what you actually ran.The identifier, the version you installed, and the date. When something behaves differently in three months, that note is the only thing that will tell you what changed.

What we would never run unattended

Three categories, and we are specific about them because vagueness here is how people lose accounts.

  • Bulk replies and comment interactions.Individually trivial, collectively the clearest automation signal a platform can read. Draft replies with a Skill; send them yourself.
  • Unattended publishing on a schedule.Not because scheduling is wrong, but because a scheduled publisher turns one bad prompt into a week of bad posts before anyone notices.
  • Anything that collects at volume on credentials you cannot rotate.If the Skill breaks and you cannot revoke what it holds, you have handed over more than you meant to.
The one-sentence version Let software draft, let a human publish, and keep the first attempt of anything new away from the account you care about.

Where to go next