# XiaohongshuSkills: CDP-based automation for Xiaohongshu content publishing

> XiaohongshuSkills automates publishing, searching, and scraping on the Xiaohongshu (RED/RedNote) platform using Chrome DevTools Protocol from Python. It runs on Windows with Python 3.10 and Chrome, and carries an explicit risk warning about account bans.

**white0dew/XiaohongshuSkills** — 支持小红书自动发布、自动评论、自动检索的 Skill。支持 OpenClaw、Codex、CC 等

- Repository: https://github.com/white0dew/XiaohongshuSkills
- Website: https://blog.aistar.cool
- Stars: 3,469 · Forks: 343
- Language: Python
- License: MIT
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/white0dew-xiaohongshuskills

## What XiaohongshuSkills automates and who it is for

Xiaohongshu (also known as RED or RedNote) is a Chinese social media platform where users publish image and video posts called notes. XiaohongshuSkills provides a Python command-line interface that automates the creator workflow: filling in titles and body text, uploading images or video, tagging topics, and clicking the publish button. It also supports read-side operations such as searching for notes, fetching note details with comment data, scraping the home feed, posting comments, and exporting performance analytics to CSV.

The tool targets developers building content pipelines, analysts monitoring published notes, or operators managing multiple Xiaohongshu accounts. The README includes a prominent risk section stating that automation can trigger rate limiting, shadowbanning, or account suspension by the platform. The recommendation is to validate on a test account first and keep publish frequency low.

## How Chrome DevTools Protocol automation works

XiaohongshuSkills controls a Chrome browser through Chrome DevTools Protocol (CDP), a JSON-over-WebSocket interface that exposes browser internals for remote control. The Python scripts connect to Chrome's debugging port (default 9222) and issue CDP commands to navigate pages, fill DOM elements, upload files, and read page state.

This approach differs from using an official API because Xiaohongshu does not provide a public API for content publishing. CDP automation drives a real browser session that holds a logged-in cookie, making the automation traffic look like a human session at the network level. The README notes that the scripts check for login state by validating a logged-in session on xiaohongshu.com before each operation. Login state is cached locally for 12 hours by default to reduce the number of validation round-trips.

The 2026 version of the tool includes fixes for a DOM change in the Xiaohongshu creator center that occurred in the February-March 2026 timeframe. The README explicitly names the affected areas: the publish button, the scheduled-post toggle, the date input, multi-image upload wait logic, and the body text editor. This indicates the fragility inherent in this approach: each platform redesign requires updates to SELECTORS constants and wait strategies in scripts/cdp_publish.py.

The project also supports remote CDP connections, where Chrome runs on a different machine and the Python scripts connect to it via --host and --port flags. This mode is useful when the browser must run on a Windows machine while the orchestration logic runs elsewhere. The README notes that in remote mode the local Chrome launcher is bypassed, and the remote Chrome instance must already be running and reachable before any command is issued.

## Installing the project and logging in for the first time

Requirements are Python 3.10 or newer, Google Chrome, and Windows. Install the Python dependencies:

```bash
pip install -r requirements.txt
```

The requirements.txt file lists requests 2.28.0 or newer and websockets 12.0 or newer as the only two dependencies. The websockets package handles the CDP WebSocket connection and requests handles HTTP operations.

For the first login, run:

```bash
python scripts/cdp_publish.py login
```

This opens a Chrome window where you scan the QR code with the Xiaohongshu mobile app to log in. The login state is cached locally for 12 hours by default. After that window closes, subsequent commands reuse the cached session without opening a new window unless the cache has expired.

To verify the current login status without triggering a browser window:

```bash
python scripts/cdp_publish.py check-login
```

## Publishing content and managing multiple accounts

To publish a note in headless mode (no visible browser window), use publish_pipeline.py:

```bash
python scripts/publish_pipeline.py --headless \
    --title "文章标题" \
    --content "文章正文" \
    --image-urls "https://example.com/image.jpg"
```

The pipeline accepts a title, body text, image URLs or local image paths, and optionally a video file. By default it automatically clicks the publish button. Adding --preview fills the form but does not click publish, giving a manual review step.

For multiple accounts, each account's cookies are stored in isolation. List existing accounts:

```bash
python scripts/cdp_publish.py list-accounts
```

To publish using a specific account:

```bash
python scripts/cdp_publish.py --account myaccount login
```

The README documents that topic tags are recognized from the last non-empty line of the body text if that line consists entirely of hashtag entries like #spring. Each tag is typed individually with a 3-second wait before confirmation, respecting the platform's UI timing.

## Search, feed scraping, and the content data dashboard

Beyond publishing, XiaohongshuSkills exposes read and interaction operations through cdp_publish.py. To search notes by keyword:

```bash
python scripts/cdp_publish.py search-feeds --keyword "春招"
```

The search operation also captures autocomplete suggestions that appear in the search box before submitting, returning them in a recommended_keywords field alongside the main results. The README notes that search-feeds returns the results currently visible on the page without a limit parameter; callers who need only the top N results must truncate the returned list themselves.

Note detail fetching requires a feed_id and xsec_token, both of which are returned by search results. The get-feed-detail command accepts optional flags to scroll through all comments (--load-all-comments) and expand nested replies (--click-more-replies).

Interaction commands support liking, un-liking, bookmarking, and removing bookmarks on a specific note. User profile snapshots and the list of notes from a profile are also accessible. The notification mentions endpoint reads the you/mentions interface from the /notification page.

The content data dashboard command fetches performance metrics (impression count, view count, like count) from the creator center and can export them to CSV:

```bash
python scripts/cdp_publish.py content-data --csv-file "/abs/path/content_data.csv"
```

All of these operations validate login state against the main xiaohongshu.com homepage session, not the creator center session, before executing.

## Limitations and where CDP-based automation breaks

The most significant limitation is platform fragility. CDP automation depends on specific HTML selectors, wait timings, and page structure. Any redesign of the Xiaohongshu creator center can break the publish flow. The README explicitly names the selectors that needed updates in early 2026 and instructs users to check SELECTORS, multi-image upload wait logic, and the publish button click logic in scripts/cdp_publish.py whenever the tool stops working after a platform change. This is a maintenance overhead that the user inherits.

The project has only been tested on Windows. The README does not describe Linux or macOS support. The Chrome launcher script and Windows/UNC path handling in the publish pipeline reflect Windows-specific assumptions. Developers on other operating systems would need to adapt both.

The remote CDP mode, which connects to Chrome running on a different machine using --host and --port, skips the local Chrome launcher logic. The README states that in remote mode the caller must ensure the remote Chrome instance is already running and reachable on the specified address and port. There is no automatic startup, health check, or reconnect logic for remote targets.

Image download from URLs uses an automatic Referer header to bypass hotlinking protection on external image hosts. The README notes this behavior directly. Depending on the source of the images, this may or may not be appropriate for a given workflow.

Playwright, by comparison, is a browser automation library maintained by Microsoft that supports Chrome, Firefox, and Safari across Windows, macOS, and Linux, with a stable API that abstracts over browser versions. Its scope is general browser automation rather than Xiaohongshu-specific workflows, so using it would require writing the full creator center interaction logic from scratch, but the resulting code would be portable and would not depend on a project-specific selector inventory.

## Conclusion

XiaohongshuSkills is appropriate for developers who need to automate Xiaohongshu publishing pipelines, content monitoring, or feed scraping on Windows and who accept the account risk the README explicitly states. The README recommends testing on a separate account first and limiting publish frequency. It is not appropriate for production use on a primary account without that testing step, and it is not appropriate on Linux or macOS since the README notes the project has only been tested on Windows. Developers who want platform-neutral browser automation should look at Playwright instead.

## FAQ

### What operating systems does XiaohongshuSkills support?

The README states the project has only been tested on Windows. Linux and macOS are not mentioned as supported platforms. The Chrome DevTools Protocol approach itself is cross-platform, but the Chrome launcher scripts and file path handling in the repository target Windows.

### How does XiaohongshuSkills handle multiple Xiaohongshu accounts?

Each account's cookies are stored in isolation. The cdp_publish.py script accepts an --account flag to specify which account to use. Commands such as list-accounts, add-account, set-default-account, and switch-account manage account records. The login cache defaults to 12 hours per account.

### What is the risk of using XiaohongshuSkills with a Xiaohongshu account?

The README includes a dedicated risk section stating that automation can trigger platform rate limiting, content restriction, or account suspension. It recommends testing only on a separate test account, keeping publish frequency and traffic volume low, and manually reviewing final content before automated submission.

## Sources

- [Issues](https://github.com/white0dew/XiaohongshuSkills/issues)
- [License: MIT](https://github.com/white0dew/XiaohongshuSkills/blob/main/LICENSE)
- [Project website](https://blog.aistar.cool)
- [README](https://github.com/white0dew/XiaohongshuSkills/blob/main/README.md)
- [white0dew/XiaohongshuSkills on GitHub](https://github.com/white0dew/XiaohongshuSkills)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/white0dew-xiaohongshuskills
