Integrate Spider XHS
Keep this adapter audit-only. The pinned repository has no LICENSE file, claims non-commercial-only use, and includes reverse-engineered signing and risk-control behavior.
Workflow
- Read references/integration.md before inspecting or proposing any connection.
- Resolve the local repository and verify remote, pinned commit, missing LICENSE, README restrictions, and worktree.
- Inspect manifests and interfaces statically. Do not install dependencies or execute repository code.
- Inventory the requested capability and classify it as read-only public data, account/private data, login, signing, anti-detection, creator publishing, KOL data, distributor data, or local utility.
- Stop unsupported categories and propose an official API, user-controlled browser, exported first-party data, or licensed vendor alternative.
- If the user obtains written permission and platform authorization, require a fresh security/legal review before changing this audit-only boundary.
- Report facts from the pinned source without reproducing signing algorithms, secrets, or bypass instructions.
Hard Stops
- Never execute
pip install,npm install, Docker,python main.py, orpython -m spider.spiderfor this repository under this Skill. - Never assist with signature reverse engineering, fingerprint mutation, proxy rotation, automatic retry intended to evade controls, CAPTCHA/SMS bypass, scraping private data, or unauthorized publishing.
- Never treat a README badge as a license grant.
Agent Output
Return repository identity, license state, static interface map, blocked capabilities, compliant alternatives, and requirements for any future re-review.