What this snapshot is
"Xiaohongshu Skill" is an overloaded phrase. Depending on who is talking, it can mean a Skill published through the official RedSkill channel, a third-party automation script in the OpenClaw ecosystem, an MCP server that exposes Xiaohongshu actions to an agent, or a browser automation project on GitHub. They share a platform, not a supply chain.
The dataset behind this page is our own aggregation: 136 public rows from a ClawHub snapshot of Xiaohongshu-related Skills, tagged with a category, a download count, an install count, a risk label and a persona. It was last updated on 2026-06-02 and it is published in full as JSON and CSV.
The shape of the data
Those totals flatter the data. The median row in this snapshot has zero installs, and 109 of the 136 rows have two installs or fewer. Meanwhile the largest single row — xiaohongshu-mcp with 18,265 downloads — accounts for about a quarter of all downloads by itself.
That is a classic long tail, and it has a practical consequence: any sentence that starts with "the average Xiaohongshu Skill" is describing a row that does not exist. Look at the distribution, the installation ratio, and the risk label instead of the totals.
The eight clusters
We group rows by the request they answer, not by the technology they use. These clusters are ours; the platform has never published a category taxonomy we could find.
| Cluster | Rows | Downloads | Low | Medium | High |
|---|---|---|---|---|---|
| Content creation | 27 | 7,887 | 25 | 2 | 0 |
| Publishing automation | 26 | 7,174 | 0 | 0 | 26 |
| Comprehensive operations | 23 | 35,824 | 0 | 0 | 23 |
| Login, MCP, Mac and CLI | 19 | 6,128 | 0 | 0 | 19 |
| Data and analytics | 18 | 10,089 | 0 | 10 | 8 |
| Image and card generation | 14 | 1,090 | 14 | 0 | 0 |
| Interaction and comments | 5 | 268 | 0 | 0 | 5 |
| Video download and analysis | 4 | 849 | 0 | 4 | 0 |
Four of the eight clusters contain no Low-risk rows at all: publishing automation, comprehensive operations, login and CLI tooling, and interaction. Together those four clusters hold 73 rows and 71% of every download in the snapshot. In other words, roughly seven out of ten downloads in this dataset went to a skill that needs a logged-in session, publishes on your behalf, or acts in bulk.
The two clusters that never touch your account — content creation with 25 Low out of 27, and image and card generation with 14 out of 14 — hold about 13% of downloads between them. Attention and safety are not aligned in this ecosystem, which is exactly why the risk column matters more than the popularity column.
Risk is the useful column
Our labels are deliberately mechanical, so you can disagree with them precisely rather than generally:
- LowThe skill reads public content or produces a local file. Nothing it does is visible to the platform as an action on your account.
- MediumThe skill performs a public, reversible action, or reads at a volume that a platform may treat as scraping.
- HighThe skill needs a logged-in session, publishes on your behalf, or acts in bulk. A mistake here is visible to other users and expensive to undo.
Eighty-one of the 136 rows are High — about 60% of the snapshot. That is not a judgement about the authors. It is a description of what the ecosystem is for: most Xiaohongshu Skills exist to act on the platform, and acting on the platform requires a session.
Three rows that explain the distribution
xiaohongshu-mcp— 18,265 downloads, 169 installs, High. The single biggest row, and a Python MCP client for full automation. Its install-to-download ratio is 0.93%, barely above the dataset average, which suggests a lot of people considered it and relatively few kept it.baoyu-xhs-images— 386 downloads, 26 installs, Low. Small, but a 6.7% install ratio: the most efficient row in the snapshot. It generates images and it touches nothing on the platform, which is a plausible explanation for both numbers.- The 109 rows with two installs or fewer. This is the honest centre of the dataset. Most Xiaohongshu Skills are experiments, and the useful question about any of them is whether you can read enough of it to decide, not how many people downloaded it.
Reading an install command you found in the wild
Install commands circulate in screenshots, notes and chat messages, which means they are exactly the kind of thing you should not paste blind. Before running one:
- Find out which installer it callsThe official RedSkill path downloads a shell script from a Xiaohongshu CDN and pipes it to
bash. Whatever the source, open the URL first and read the script rather than piping it straight into a shell. - Check whether it wants a sessionIf the Skill needs a logged-in browser or a stored token, you are handing over account access. That decision deserves its own moment, not a line in a setup step.
- Look for a hash checkReported behaviour for the official CLI is a zip plus a sha256 verification. An integration that skips verification is a different risk class from one that refuses to install.
- Watch the scope of the first runRun it against a test account or an isolated session, and check what it actually wrote before you point it at anything you care about.
Our guide to automation risk levels goes deeper on those signals, and the RedSkill explainer covers the documented install path in detail.
What the implementation cases add
Alongside the 136 rows, our dataset tracks 12 GitHub implementation cases and 9 reported RedSkill examples with their own source documents. Those carry real, distinct provenance, which makes them the most checkable part of the dataset. They include deck-generation skill collections, an image-generation pipeline built on a commercial image model, and Xiaohongshu automation skill packs that state plainly that they drive a real logged-in browser.
That last detail is the one to internalise. A repository that tells you it uses your logged-in session is being honest, and honesty about session use is the single most useful thing a Skill README can contain. When a project is vague about it, assume it does.