Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- bin/bbdown-wrapper.js:15
Security audit
Security checks across malware telemetry and agentic risk
This appears to be a real Bilibili downloader, but it auto-downloads an executable dependency and includes shell-based command execution that users should review before installing.
Install only if you are comfortable with an npm postinstall step downloading BBDown from GitHub. Prefer verifying or manually installing BBDown yourself, avoid passing cookie files unless needed, and remember that download history is stored locally under ~/.bilibit.
65/65 vendors flagged this skill as clean.
Detected: suspicious.dangerous_exec