本文へ移動
cccskills
無料GitHub で公開

xiaohongshu

Interact with Xiaohongshu (小红书, RED, Little Red Book) — search notes, read note details, view comments, browse user profiles and posts, get home feed. Use this skill whenever the user mentions Xiaohongshu, 小红书, RED, RedNote, Little Red Book, wants to search for lifestyle/beauty/travel content, read XHS discussions, look up XHS users, or browse trending notes. Also trigger when the user pastes a xiaohongshu.com URL (e.g. xiaohongshu.com/explore/noteid) or mentions an XHS note ID.

インストール方法を見る

含まれるファイル(30)

  • SKILL.md19.2 KB
  • references/provider-config.yaml2.5 KB
  • requirements.txt60 B
  • scripts/sync-vendor.sh4.2 KB
  • scripts/xiaohongshu_client.py7.3 KB
  • scripts/xiaohongshu_get_homefeed.py1.6 KB
  • scripts/xiaohongshu_get_note_comments.py1.3 KB
  • scripts/xiaohongshu_get_note_info.py1.2 KB
  • scripts/xiaohongshu_get_user_info.py1.1 KB
  • scripts/xiaohongshu_get_user_notes.py1.5 KB
  • scripts/xiaohongshu_search_note.py1.6 KB
  • vendor/__init__.py0 B
  • vendor/apis/__init__.py0 B
  • vendor/apis/xhs_pc_apis.py43.0 KB
  • vendor/LICENSE1.1 KB
  • vendor/package.json90 B
  • vendor/static/xhs_a1.js18.6 KB
  • vendor/static/xhs_main_260411.js1.1 MB
  • vendor/static/xhs_rap.js434.8 KB
  • vendor/static/xhs_websectiga_env.js4.6 KB
  • vendor/static/xhs_xray_pack1.js3.7 MB
  • vendor/static/xhs_xray_pack2.js1.9 MB
  • vendor/static/xhs_xray.js18.1 KB
  • vendor/UPSTREAM.md749 B
  • vendor/xhs_utils/__init__.py0 B
  • vendor/xhs_utils/common_util.py3.8 KB
  • vendor/xhs_utils/cookie_util.py267 B
  • vendor/xhs_utils/data_util.py11.9 KB
  • vendor/xhs_utils/http_util.py21 B
  • vendor/xhs_utils/xhs_util.py5.0 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Xiaohongshu

Search notes, read note details, view comments, browse user profiles, and get the home feed from Xiaohongshu (小红书).

Skill Directory

<SKILL_DIR> is the directory containing this SKILL.md file. Determine it ONCE at the start and reuse it.

Setup (run FIRST — every time, before any operation)

You MUST complete this setup before running any script. Do NOT skip.

sig status xiaohongshu 2>&1

Check the JSON output fields configured and valid:

  • configured: false → run Provider Setup below.
  • valid: false (but configured: true) → run sig login xiaohongshu --mode visible, complete the captcha, then re-check.
  • valid: true → run Vendor Setup (one-time per machine), then execute the user's request.

Provider Setup

  1. Read <SKILL_DIR>/references/provider-config.yaml
  2. Append the provider block to ~/.sig/config.yaml under providers:
  3. Run sig login xiaohongshu --mode visible — a browser opens; scan the QR code with the Xiaohongshu app and complete the slider/image captcha if prompted
  4. Verify: sig status xiaohongshu should show valid: true

Why the validateRule is so picky — three response shapes

/api/sns/web/unread_count is a permissive endpoint that hides a "partially expired cookie" state behind what looks like a successful response. The provider's validateRule is built specifically to reject it:

State/api/sns/web/unread_count returnsDetected as
Healthy cookie{code:0, success:true, data:{unread_count:N, likes:N, ...}}✅ valid
Cookie partially expired{code:0, success:true, data:{}}❌ rejected by Object.keys(data).length > 0
Cookie fully expired / logged out{code:-101, success:false, msg:"无登录信息"}❌ rejected by code === 0

If sig login exits without prompting you, but later API calls fail with empty data — the partially-expired-cookie state was bypassed by a stale rule. Re-pull references/provider-config.yaml and refresh the rule in ~/.sig/config.yaml, then re-login.

What this rule does NOT catch. unread_count is more permissive than search/feed APIs. A cookie that passes the rule (state #1) may still fail on search if the risk-control / session-token portion has aged out. If sig status shows valid:true but search keeps returning empty data, you're in this gray zone — the only fix is sig logout xiaohongshu && sig login xiaohongshu --mode visible. See Diagnosis below for how to confirm.

Vendor Setup (one-time per machine)

Unlike most skills, xiaohongshu signs every request via JS files at <SKILL_DIR>/vendor/static/, evaluated through PyExecJS. The skill ships those source files but not their npm/pip deps — install them once:

node --version                          # must be >= 18; install from https://nodejs.org if missing
cd <SKILL_DIR>/vendor && npm install    # installs crypto-js, jsdom
pip install --user -r <SKILL_DIR>/requirements.txt   # PyExecJS, requests, loguru, retry

If pip complains about externally-managed Python (PEP 668 on macOS/Debian), use a venv or pipx.

Smoke-test signing (no network, no cookie needed):

cd <SKILL_DIR>/vendor && python3 -c "
import sys; sys.path.insert(0, '.')
from xhs_utils.xhs_util import generate_x_rap_param, generate_xs_xs_common
xs, xt, xsc = generate_xs_xs_common('a1=test', '/api/sns/web/v1/feed', '', 'POST')
rap = generate_x_rap_param('/api/sns/web/v1/user_posted', '')
print('OK' if xs and rap else 'FAIL')
"

Expect OK. If it fails, see Error Handling.

Running Scripts

All scripts output JSON to stdout. Read operations need a cookie (the public site does not allow anonymous access to most endpoints).

Recommended — sig run injects the cookie as SIG_XIAOHONGSHU_COOKIE:

sig run xiaohongshu -- bash -c 'python3 <SKILL_DIR>/scripts/xiaohongshu_search_note.py --keyword "AI" --page 1'

Alternative — pass --cookie explicitly:

COOKIE=$(sig get xiaohongshu --no-redaction --format value)
python3 <SKILL_DIR>/scripts/xiaohongshu_search_note.py --keyword "AI" --cookie "$COOKIE"

Scripts Reference

All scripts are in this skill's scripts/ directory. Output is JSON to stdout.

ScriptPurposeAuth
xiaohongshu_search_note.pySearch notes by keywordCookie
xiaohongshu_get_note_info.pyGet full note detail by URLCookie
xiaohongshu_get_note_comments.pyGet top-level comments on a noteCookie
xiaohongshu_get_user_info.pyGet a user's profileCookie
xiaohongshu_get_user_notes.pyGet notes published by a user (page)Cookie
xiaohongshu_get_homefeed.pyGet home feed recommendations (page)Cookie

Script Arguments

xiaohongshu_search_note.py

  • --keyword (required) — search keyword
  • --page — page number, default 1
  • --sort — 0 general (default), 1 newest, 2 most-liked, 3 most-commented, 4 most-collected
  • --note-type — 0 any (default), 1 video, 2 image
  • --cookie — override env var

xiaohongshu_get_note_info.py

  • --url (required) — full note URL like https://www.xiaohongshu.com/explore/<id>?xsec_token=...&xsec_source=pc_search
  • --cookie

xiaohongshu_get_note_comments.py

  • --note-id (required)
  • --xsec-token (required) — comes from a search/feed result
  • --cursor — pagination, default empty
  • --cookie

xiaohongshu_get_user_info.py

  • --user-id (required)
  • --cookie

xiaohongshu_get_user_notes.py

  • --user-id (required)
  • --cursor — pagination, default empty
  • --xsec-token, --xsec-source — pass through if available
  • --cookie

xiaohongshu_get_homefeed.py

  • --category — channel id, default homefeed_recommend
  • --cursor-score — pagination
  • --refresh-type, --note-index — feed iteration state
  • --cookie

Key Concepts

  • xsec_token / xsec_source: per-note security tokens issued by the search/feed endpoints. To call get_note_info or get_note_comments, you must first call search_note to obtain these tokens (they are embedded in the note URL returned).
  • Why Node.js? XHS signs every request with x-s, x-t, x-s-common, x-rap-param, and x-xray-traceid derived from JSVMP-obfuscated JavaScript. The skill ships those JS files (<SKILL_DIR>/vendor/static/) and runs them via PyExecJS, which shells out to node. Pure-Python signing libraries (e.g. xhshow) currently miss x-rap-param and fail on data APIs with HTTP 406.

Error Handling

ErrorMeaningFix
AUTH_REQUIREDNo cookie availablesig login xiaohongshu --mode visible
VENDOR_MISSING<SKILL_DIR>/vendor/ not populatedRun <SKILL_DIR>/scripts/sync-vendor.sh
NODE_MODULES_MISSINGvendor/node_modules/ missingcd <SKILL_DIR>/vendor && npm install
API_ERROR with msg="'msg'"Vendor parser hit KeyError: 'msg' because the API returned {code:0, success:true, data:{}}. The cookie has expired enough to fail on search even though unread_count may still pass. This is the most common failure mode in normal use — sessions age out faster than unread_count's acceptance criteria.sig logout xiaohongshu && sig login xiaohongshu --mode visible. If sig login exits immediately without prompting (because the old unread_count-passing cookie is still present), check Diagnosis below first to confirm.
API_ERROR with code=-101无登录信息 — session is gonesig login xiaohongshu --mode visible
API_ERROR (other)Account flagged, vendor schema drift, etc.sig logout xiaohongshu && sig login xiaohongshu --mode visible. If it persists after re-login, run <SKILL_DIR>/scripts/sync-vendor.sh to refresh the signing JS.
HTTP_<code>Network / transport failureCheck connectivity

Workflow Examples

Find a topic and read the top result with comments

# 1. Search — output is JSON with a list of notes
sig run xiaohongshu -- bash -c \
  'python3 <SKILL_DIR>/scripts/xiaohongshu_search_note.py --keyword "城市探索" --sort 2' \
  > /tmp/xhs_search.json

# 2. Extract note_id + xsec_token from the first result.
#    Path: items[0].id  and  items[0].xsec_token
NOTE_ID=$(jq -r '.items[0].id' /tmp/xhs_search.json)
XSEC=$(jq -r '.items[0].xsec_token' /tmp/xhs_search.json)
URL="https://www.xiaohongshu.com/explore/${NOTE_ID}?xsec_token=${XSEC}&xsec_source=pc_search"

# 3. Get full detail
sig run xiaohongshu -- bash -c \
  "python3 <SKILL_DIR>/scripts/xiaohongshu_get_note_info.py --url '$URL'"

# 4. Get comments
sig run xiaohongshu -- bash -c \
  "python3 <SKILL_DIR>/scripts/xiaohongshu_get_note_comments.py --note-id '$NOTE_ID' --xsec-token '$XSEC'"

Diagnosis: when search fails, do NOT jump to conclusions

sig status xiaohongshu showing valid: true is necessary but not sufficient for search to work. The validateUrl is permissive on purpose (so it can run without XHS request signing), which means a cookie that has aged out enough to fail on search may still pass validation. Before re-logging in or "fixing" anything, triangulate with three probes:

# Probe 1 — what sig itself thinks
sig status xiaohongshu

# Probe 2 — what the validateUrl says (permissive endpoint)
sig run xiaohongshu -- bash -c \
  'curl -sL -H "Cookie: $SIG_XIAOHONGSHU_COOKIE" -H "User-Agent: Mozilla/5.0" \
   https://edith.xiaohongshu.com/api/sns/web/unread_count'

# Probe 3 — what a stricter authenticated endpoint says
sig run xiaohongshu -- bash -c \
  'curl -sL -H "Cookie: $SIG_XIAOHONGSHU_COOKIE" -H "User-Agent: Mozilla/5.0" \
   https://edith.xiaohongshu.com/api/sns/web/v2/user/me'

Read the three answers together:

sig statusunread_countv2/user/meMost likely causeFix
valid:truecode:0 + non-empty datacode:0 + your real user_idCookie is healthy. Search itself is failing for another reason — vendor schema drift, transient network, account-level flag. Do NOT re-login first.Re-run sync-vendor.sh, retry once, only re-login if that doesn't help
valid:truecode:0 + non-empty datacode:0 + guest:falseCookie passes the rule but search still failsCookie has aged into the gray zone. sig logout && sig login --mode visible
valid:truecode:0 + data:{}code:-1 / 401Local config has the old loose validateRule — sigcli accepted a half-cooked cookieRefresh ~/.sig/config.yaml from references/provider-config.yaml, then sig logout && sig login
valid:false——Cookie fully expired or never writtensig login xiaohongshu --mode visible

The mistake the previous version of this skill encouraged: see KeyError: 'msg' → assume captcha → tell the user to re-login + solve captcha. Most of the time captcha never appears, the real cause is cookie aging, and re-login does fix it — but for the wrong reason. Document the right reason so the next debugger doesn't get misled.

Two-tier verification. Run tier 1 unconditionally; tier 2 only after tier 1 passes.

Tier 1: prerequisite checks (read-only, safe)

# 1. Provider authenticated and validated against the strict rule
sig status xiaohongshu
# Expect: configured: true, valid: true
# 2. Probe the validateUrl directly — must return non-empty data object
sig run xiaohongshu -- bash -c 'curl -sL --max-time 10 \
  -H "Cookie: $SIG_XIAOHONGSHU_COOKIE" \
  -H "User-Agent: Mozilla/5.0" \
  https://edith.xiaohongshu.com/api/sns/web/unread_count'
# Expect: {"code":0,"success":true,"msg":"成功","data":{"unread_count":N,...}}
# If `data` is `{}` → captcha not solved. Re-login with --mode visible and complete the captcha.
# If code is -101 → session gone. Re-login.
# 3. Vendor signing JS deps installed
test -d <SKILL_DIR>/vendor/node_modules && echo "OK: node_modules present" || echo "FAIL: cd vendor && npm install"
# 4. Smoke-test signature generation (no network, no cookie)
cd <SKILL_DIR>/vendor && python3 -c "
import sys; sys.path.insert(0, '.')
from xhs_utils.xhs_util import generate_x_rap_param, generate_xs_xs_common
xs, xt, xsc = generate_xs_xs_common('a1=test', '/api/sns/web/v1/feed', '', 'POST')
rap = generate_x_rap_param('/api/sns/web/v1/user_posted', '')
print('OK' if xs and rap else 'FAIL')
"
# Expect: OK

Tier 2: live execution test

Run a tiny search and assert that items is a non-empty list. This is the canary for "everything actually works":

sig run xiaohongshu -- bash -c \
  'python3 <SKILL_DIR>/scripts/xiaohongshu_search_note.py --keyword "AI"' \
  | python3 -c "
import json, sys
d = json.load(sys.stdin)
items = d.get('items', [])
assert isinstance(items, list) and len(items) > 0, f'expected items list, got: {d}'
print(f'OK: {len(items)} items')
"
# Expect: OK: N items
# If you see {'error': 'API_ERROR', 'message': \"code=0, msg=\\\"'msg'\\\"\"} → captcha-not-solved
# soft-reject. The cookie is half-cooked even though sig status shows valid:true.
# Refresh references/provider-config.yaml into ~/.sig/config.yaml, then re-login with captcha.

This skill bundles a minimal slice of cv-cat/Spider_XHS (MIT) at <SKILL_DIR>/vendor/. To bump the vendored version:

<SKILL_DIR>/scripts/sync-vendor.sh           # latest master
<SKILL_DIR>/scripts/sync-vendor.sh <ref>     # specific commit/tag

License and upstream metadata are in <SKILL_DIR>/vendor/LICENSE and <SKILL_DIR>/vendor/UPSTREAM.md.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

bilibili

無料

Interact with Bilibili (B站) — browse trending videos, view video details, read comments, search videos and users, view user profiles, like, coin, and favorite videos. Use this skill whenever the user mentions Bilibili, B站, wants to browse Bilibili content, search Bilibili videos, read Bilibili comments, look up Bilibili users, or interact with Bilibili content. Also trigger when the user pastes a Bilibili URL (e.g. bilibili.com/video/BV...) or mentions a BV ID.

日本語の概要は準備中です。原文の説明を表示しています。

sigcli/sigcli2932026年9月28日 更新

douyin

無料

Provide authenticated cookies for Douyin (抖音/TikTok China) — two providers: douyin (www.douyin.com for scraping) and douyin-live (live.douyin.com for livestream). Use this skill whenever the user needs Douyin cookies for scraping tools like DouYin_Spider, or needs to authenticate with Douyin services. Trigger when the user mentions 抖音, Douyin, TikTok China, douyin cookies, or wants to use tools that require Douyin login cookies.

日本語の概要は準備中です。原文の説明を表示しています。

sigcli/sigcli2932026年9月28日 更新

Interact with Hacker News (news.ycombinator.com) — browse top, new, and best stories, read item details and comment threads, look up user profiles, and search posts via Algolia. Use this skill whenever the user mentions Hacker News, HN, YCombinator news, ycombinator.com, news.ycombinator.com, wants to browse tech news, read HN discussions, search HN posts, or look up HN users. Also trigger when the user pastes an HN URL (e.g. news.ycombinator.com/item?id=12345). Keywords: Hacker News, HN, YC, ycombinator, tech news, Show HN, Ask HN, HN front page.

日本語の概要は準備中です。原文の説明を表示しています。

sigcli/sigcli2932026年9月28日 更新

linkedin

無料

Interact with LinkedIn — view your profile, browse other profiles, read the feed, search jobs/posts/people, get job details, create posts, like/unlike posts, comment, send connection requests, and follow/unfollow users. Use this skill whenever the user mentions LinkedIn, wants to search for jobs or people, read their LinkedIn feed, view a profile, get job details, create a post, like or comment on content, send a connection request, or follow someone. Also trigger when the user pastes a LinkedIn URL (e.g. linkedin.com/in/..., linkedin.com/jobs/view/...) or mentions LinkedIn networking.

日本語の概要は準備中です。原文の説明を表示しています。

sigcli/sigcli2932026年9月28日 更新

msteams

無料

Interact with Microsoft Teams — send and read messages, search conversations, look up people, check calendar, get meeting transcripts, and manage chats. Use this skill whenever the user mentions Teams, MS Teams, Microsoft Teams, wants to send a message, read chat history, search conversations, look up a colleague, check their calendar, find meeting recordings or transcripts, see direct reports or manager, or do anything involving Teams communication. Also trigger when the user asks about scheduling, org chart, people search, or wants to message someone.

日本語の概要は準備中です。原文の説明を表示しています。

sigcli/sigcli2932026年9月28日 更新

outlook

無料

Interact with Outlook email — read inbox, send emails, search messages, reply/forward, manage folders, download attachments. Use this skill whenever the user mentions email, Outlook, inbox, mail, send email, check email, unread messages, email search, attachments, reply to email, forward email, 邮件, 收件箱, or wants to read, send, search, reply to, forward, or manage emails.

日本語の概要は準備中です。原文の説明を表示しています。

sigcli/sigcli2932026年9月28日 更新

sigcli のスキルをすべて見る

このスキルの問題を報告する