Borrowing it
Nothing to install: this file belongs to lux888093-hash/xhs_mcp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/lux888093-hash/xhs_mcp/main/CLAUDE.mdgit clone --depth 1 https://github.com/lux888093-hash/xhs_mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/lux888093-hash/xhs_mcp/claude-md)<a href="https://agentmods.dev/instructions/lux888093-hash/xhs_mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/lux888093-hash/xhs_mcp/claude-md/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/instructions/lux888093-hash/xhs_mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/lux888093-hash/xhs_mcp/claude-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00834 | $0.00834 |
| Opus 5 | $0.00417 | $0.00417 |
| Sonnet 5 | $0.00167 | $0.00167 |
| Haiku 4.5 | $0.00083 | $0.00083 |
Grade A, and why
xhs_mcp CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
xhs-toolkit 项目说明
项目概述
小红书 MCP 工具包,通过 MCP 协议与小红书交互。
重要路径信息
项目根目录
必须使用绝对路径: D:\AI\xhs-toolkit
所有配置文件和数据文件都在此目录下:
.env- 环境配置文件(已使用绝对路径)xhs_cookies.json- 小红书登录 cookiesxhs_toolkit.log- 日志文件temp_images/- 临时图片目录
MCP 配置
配置文件位置: C:\Users\Administrator\AppData\Roaming\Claude\claude_desktop_config.json
关键配置:
{
"mcpServers": {
"xhs-toolkit": {
"command": "python",
"args": ["-m", "src.server.mcp_server", "--stdio"],
"cwd": "D:\\AI\\xhs-toolkit",
"env": {
"PYTHONPATH": "D:\\AI\\xhs-toolkit",
"XHS_TOOLKIT_HOME": "D:\\AI\\xhs-toolkit",
"COOKIES_FILE": "D:\\AI\\xhs-toolkit\\xhs_cookies.json",
"LOG_FILE": "D:\\AI\\xhs-toolkit\\xhs_toolkit.log"
}
}
}
}
重要环境变量:
XHS_TOOLKIT_HOME- 项目根目录(用于定位 .env 和其他资源文件)COOKIES_FILE- cookies 文件绝对路径LOG_FILE- 日志文件绝对路径
工作目录要求
⚠️ 重要:此项目必须在 D:\AI\xhs-toolkit 目录下运行!
原因:
.env配置文件使用绝对路径xhs_cookies.json需要被正确加载temp_images/临时目录相对路径
常用 MCP 工具
账号相关
login_xiaohongshu- 智能登录小红书get_creator_data_analysis- 获取创作者中心数据test_connection- 测试 MCP 连接
内容分析
analyze_note_detail- 分析笔记详细数据search_and_analyze_accounts- 搜索并分析账号
互动功能
like_note- 点赞笔记comment_note- 评论笔记analyze_and_comment_note- 分析并自动评论
发布功能
smart_publish_note- 智能发布笔记(支持自动生成配图)
AI 媒体生成
generate_ai_media_by_content- 根据正文生成图片/视频generate_hot_topics_image- 抓取热点并生成配图
配置检查清单
使用前确保:
-
xhs_cookies.json存在且有效(已登录小红书) -
.env文件使用绝对路径 - MCP 配置正确(包含绝对路径的环境变量)
- Chrome 浏览器已安装
故障排查
问题:找不到 cookies
解决:运行 login_xiaohongshu 工具重新登录
问题:MCP 连接失败
解决:
- 检查 MCP 配置文件中的路径是否正确
- 确保
cwd指向D:\AI\xhs-toolkit - 重启 Claude Desktop
问题:相对路径文件找不到
解决:已修复 - .env 和 MCP 配置都使用绝对路径
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 97 lines · 834 tokens per session scan A fdc698b338f0
xhs_mcp CLAUDE.md is an instructions file published in the GitHub repository lux888093-hash/xhs_mcp (0 stars, last pushed 6mo ago), licensed MIT. It adds 834 tokens to every session, about $0.0042 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.