Xhs Downloader
JoeanAmier/XHS-DownloaderGPL-3.0โญ 10,344๐ง 0 tools
Xhs Downloader has risks โ usable with isolation (6.16/10, 3 critical, 0 high).
Recommended Actions
- highRun In Container3 critical vulnerabilities require isolation
- highLimit PermissionsRestrict tool access to minimum required scope
Do Not
- โrunning in production without container isolation
- โexposing this tool to untrusted input
Risk Flags (2)
- criticalcommand_injectionCommand injection risk รขโฌโ subprocess called with shell=True and non-literal command
- criticalsql_injectionร2SQL injection รขโฌโ .execute() called with f-string (user input may reach query)
How This Was Decided
- positivew=0.5Overall quality score = 6.16/10 (grade F)
- negativew=0.83 critical security issue(s) detected
- positivew=0.3Tool description clarity score = 5.0/10
Description Quality
3-Layer Breakdown
Description Dimensions
Category Ranking: Databases
#28 of 160 ยท Top 18%Why #28 in Databases?
Top 18% of 160 toolsHow to reach #27? Need +0.0 overall to pass Sql Injection Testing (6.2). Biggest opportunity: Security is 2.6 below category average.
Top action: Fix 3 critical security issue(s) โ use parameterized queries, avoid eval/exec (+0.2)
Security Analysis
Findings Redacted
Detailed security findings are hidden during the 90-day responsible disclosure window. Maintainers have been notified.
Metadata Health
Badge
Add this badge to your README:
[](https://spiderrating.com/servers/JoeanAmier/XHS-Downloader)Protect Your Agents
Get a free API key. Every MCP tool call checked against 15,923 rated servers in real-time.
Get Free API Key โMonitor All Your Servers
Dashboard for your entire MCP portfolio. Score tracking, alerts, and compliance reports.
Start Free Trial โScan Locally (Open Source)
Run SpiderShield on your own machine. 46+ security rules, zero data leaves your system.
Star on GitHub โ