Back to skill

Security audit

Download Anything

Security checks for vulnerabilities and agentic risk

Overview

This is a transparent but very broad download toolkit that points users toward piracy-associated sources and uses high-risk install, cookie, and network-service patterns.

Install only if you are comfortable reviewing each command before it runs. Use it only for content you are authorized to access, avoid the piracy-oriented source lists and rotating mirrors, do not expose aria2 RPC, avoid browser-cookie options unless you explicitly choose a dedicated low-risk profile, and prefer pinned or OS-packaged dependencies over the bulk installer.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/software.md:65
Finding

Remote Installer Scripts Are Downloaded and Executed Without Verification

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/install-toolkit.sh:32
Finding

Toolkit Installs Unpinned Third-Party Packages Into Shared Environments

Content
View full analysis
/dev/null; then echo "✓ $pkg (already installed)" else echo "→ Installing $pkg..." pip3 install "$pkg" fi done } install_npm() { for pkg in "$@"; do if npm list -g "$pkg" &>/dev/null 2>&1; then echo "✓ $pkg (already installed)" else echo "→ Installing $pkg..." npm install -g "$pkg" fi done } if [[ "$PKG" == "brew" ]]; then install_brew yt-dlp aria2 wget ffmpeg jq install_pip gallery-dl spotdl else echo "→ Linux detected, using pip for most tools" install_pip yt-dlp gallery-dl spotdl if [[ "$PKG" == "apt" ]]; then sudo apt-get install -y aria2 wget ffmpeg jq 2>/dev/null || true elif [[ "$PKG" == "dnf" ]]; then sudo dnf install -y aria2 wget ffmpeg jq 2>/dev/null || true fi fi # Optional: webtorrent-cli (requires Node.js) if command -v npm &>/dev/null; then install_npm webtorrent-cli fi ``` ### Technical Analysis The installer resolves pip and npm package names to the latest available registry versions at execution time. It does not use exact version constraints, dependency lockfiles, package hashes, provenance verification, or an isolated Python environment. The script also globally installs `webtorrent-cli` whenever npm is available, even though the package is described as optional. A global npm installation increases the modification scope and may run package lifecycle scripts. Installing Python packages into the active interpreter can modify a shared or system-associated environment. The packages named in the script are consistent with the declared downloading functionality, and there is no evidence that the names ...[truncated 1313 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/tools-reference.md:277
Finding

Aria2 RPC Example Exposes Unauthenticated Download Control to the Network

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/dl-video.sh:29
Finding

Video Downloader Automatically Probes and Reads Browser Authentication Cookies

Content
View full analysis
/dev/null; then EXTRA_ARGS+=(--cookies-from-browser "$browser") break fi done if [[ ${#EXTRA_ARGS[@]} -eq 0 ]]; then echo "⚠ Bilibili requires login cookies. Log in via Chrome/Firefox first." >&2 echo " Or export cookies: yt-dlp --cookies cookies.txt ..." >&2 fi fi ``` ### Technical Analysis For URLs matching Bilibili or its short-link domain, the script automatically invokes yt-dlp with `--cookies-from-browser` against Chrome, Firefox, and Edge until one succeeds. This reads authenticated browser cookie storage without a separate consent step and may cause requests to execute under the user's logged-in account. Cookie-assisted downloading is relevant for authenticated or members-only resources. However, automatically probing several browser profiles exceeds the minimum privilege needed for public downloads. The safer default is anonymous access, followed by explicit consent for one selected browser profile only when authentication is necessary. The cookie behavior is disclosed in the Skill documentation, and no code was found that intentionally sends cookies to an unrelated collection endpoint. The primary concern is unnecessary access to sensitive session state and the trust placed in the installed yt-dlp package and destination resolution behavior. ### Attack Path 1. A user supplies a URL matching `bilibili.com` or `b23.tv`. 2. The script automatically probes Chrome, Firefox, and Edge cookie stores. 3. yt-dlp ...[truncated 937 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (37)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a comprehensive tool for finding and downloading virtually any kind of digital resource across many ecosystems and tools. The supplied code chunk does not implement that broad purpose. Instead, it performs a specific subtitle-related task: for URLs, it invokes yt-dlp only to fetch subtitles/auto-subs and skips media download; for non-URL input, it merely prints subtitle search URLs for manual use. This is a materially different and much narrower primary purpose than the declared skill, so the description does not accurately represent the code chunk's actual behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger language is so broad that the skill may be invoked for almost any request involving digital content, including ambiguous or risky scenarios. In context, this increases the chance an agent routes users into workflows involving copyrighted material, torrents, scraping, or downloads from untrusted sources without adequate guardrails.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The download tips instruct users to try Sci-Hub first for DOI-to-PDF and to check Anna’s Archive, LibGen, and Z-Library first for textbooks, which is direct procedural guidance for accessing likely infringing sources. Because these are framed as default first-line steps, the skill increases the likelihood of policy violations, copyright infringement, and exposure to malicious or spoofed download sites.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/education.md (reported line 68)May include surrounding context.

/ CS: Python教程, 前端开发, 机器学习

  • Math: 高等数学, 线性代数, 概率论
  • Language: 英语学习, 日语入门
  • Science: 物理, 化学, 生物
  • Design: PS教程, UI设计, 视频剪辑

Download Bilibili courses:

bash
# yt-dlp supports Bilibili
yt-dlp "https://www.bilibili.com/video/BV..."

# For members-only content, use cookies
yt-dlp --cookies-from-browser chrome "URL"

# Download entire multi-part video (合集)
yt-dlp --yes-playlist "URL"

# List all parts first
yt-dlp --flat-playlist "URL"

Downloadable Course Materials

Many platforms allow downloading materials for offline use:

PlatformDownloadable ContentHow
MIT OCWLecture notes, problem sets, exams (PDF). Some video.Direct download from course page.
Khan AcademyVideos (via yt-dlp)yt-dlp "khanacademy.org/..."
CourseraVideos, slides (enrolled courses)Use coursera-dl (`

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The source-specific guidance explicitly points users toward piracy-associated services and communities such as Anna's Archive, Z-Library, Sci-Hub, r/Piracy, and r/opendirectories, without clear restrictions to lawful or authorized content. Given the skill's stated purpose of helping users download almost any digital resource, these references strongly increase the likelihood of facilitating copyright infringement and access to unauthorized copies at scale.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/tools-reference.md (reported line 79)May include surrounding context.

`

Playlist & Batch

bash
# Full playlist
yt-dlp --yes-playlist "PLAYLIST_URL"

# Playlist range
yt-dlp --playlist-items 1,3,5-7 "PLAYLIST_URL"

# Entire channel
yt-dlp "https://www.youtube.com/@CHANNEL"

# Batch from file
yt-dlp -a urls.txt

# Skip already downloaded
yt-dlp --download-archive archive.txt "URL"

Auth & Network

bash
# Cookies from browser (easiest auth)
yt-dlp --cookies-from-browser chrome "URL"
yt-dlp --cookies-from-browser firefox "URL"

# Cookies file
yt-dlp --cookies cookies.txt "URL"

# Proxy
yt-dlp --proxy socks5://127.0.0.1:1080 "URL"

# Geo-bypass
yt-dlp --geo-bypass-country US "URL"

# Rate limit
yt-dlp --limit-rate 5M "URL"

# Resume
yt-dlp --no-overwrites -c "URL"

Agent Automation Flags

bash
# Get metadata as JSON (no download) -- CRITICAL for agent use
yt-dlp -j --no-download "URL"

# Get direct download URL only (pipe to aria2/curl)
yt-dlp -g "URL"

# Output template
yt-dlp -o "%(title)s.%(ext)s" "URL"
yt-dlp -o "%(uploader)s

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The aria2 example enables RPC with --rpc-listen-all=true and --rpc-allow-origin-all=true, which can expose unauthenticated download control to other hosts and web origins if the service is reachable. In a skill designed for broad downloading, this could let an attacker enqueue arbitrary downloads, write files to attacker-chosen locations, or abuse the host as a downloader.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
97% confidence
Finding

The --cookies-from-browser chrome pattern matches credential access behavior because it reads authenticated browser cookies from the user's local profile. Even though presented as a convenience feature for downloading members-only media, in an agent skill this can facilitate unauthorized access, session theft, or accidental exfiltration of active account credentials if logs, subprocess arguments, or follow-on tooling capture them.

Content

Scanner excerpt · references/video.md (reported line 98)May include surrounding context.

nload. |

Online Video Downloaders

yt-dlp (primary tool -- supports 1800+ sites)

bash
# Best 1080p video
yt-dlp -f "bv[height<=1080]+ba/b[height<=1080]" "URL"

# List formats first
yt-dlp -F "URL"

# Download with subtitles
yt-dlp --write-subs --sub-lang en,zh --embed-subs "URL"

# Audio only (MP3)
yt-dlp -x --audio-format mp3 "URL"

# Bilibili (need cookies for members-only)
yt-dlp --cookies-from-browser chrome "https://www.bilibili.com/video/BV..."

# Twitter/X video
yt-dlp "https://twitter.com/user/status/ID"

# TikTok (no watermark)
yt-dlp "https://www.tiktok.com/@user/video/ID"

# Download entire playlist
yt-dlp --yes-playlist "PLAYLIST_URL"

# Get metadata only (no download)
yt-dlp -j --no-download "URL"

Cobalt

Webcobalt.tools
APISelf-host via Docker for agent use
SupportsYouTube, TikTok, Instagram, Twitter, Reddit, SoundCloud, 30+ sites
bash
# API call (self-hosted instance)
curl -X POST "https://YOUR-INS

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/dl-video.sh (reported line 31)May include surrounding context.

sh
[height<=720]+ba/b" ;;
    480)    FORMAT="bv[height<=480][vcodec~='^(avc|hev)'][ext=mp4]+ba[acodec~='^(mp4a)'][ext=m4a]/bv[height<=480][ext=mp4]+ba[ext=m4a]/bv[height<=480]+ba/b" ;;
    *)      FORMAT="$QUALITY" ;;  # allow raw format string
esac

EXTRA_ARGS=()

# Auto-detect sites that require browser cookies
if [[ "$URL" =~ bilibili\.com|b23\.tv ]]; then
    # Bilibili returns HTTP 412 without cookies. Try Chrome first, then Firefox.
    for browser in chrome firefox edge; do
        if yt-dlp --cookies-from-browser "$browser" -j "$URL" &>/dev/null; then
            EXTRA_ARGS+=(--cookies-from-browser "$browser")
            break
        fi
    done
    if [[ ${#EXTRA_ARGS[@]} -eq 0 ]]; then
        echo "⚠ Bilibili requires login cookies. Log in via Chrome/Firefox first." >&2
        echo "  Or export cookies: yt-dlp --cookies cookies.txt ..." >&2
    fi
fi

yt-dlp \
    -f "$FORMAT" \
    --merge-output-format mp4 \
    --embed-metadata \
    --embed-thumbnail \
    --write-sub

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises and invokes shell-based download workflows but does not declare any tool scope or permissions boundaries. In an agent environment, this can enable unintended shell execution for network retrieval, file writes, and potentially unsafe follow-on handling of untrusted content without explicit authorization controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill encourages downloading and processing arbitrary internet resources, including software, torrents, and files from rotating mirror sites, but provides no warnings about malware, legal risk, unsafe execution, or provenance verification. That omission is dangerous because users or agents may treat the workflow as routine and fetch untrusted content directly into the local environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section gives operational guidance for locating, saving, and downloading files from third-party cloud-drive search engines, including workaround advice for throttling, but does not warn about copyright infringement, malware-laden files, credential exposure, or the risks of exporting browser cookies. In the context of a skill explicitly designed to help users download virtually any digital resource, this omission materially increases the chance of facilitating unsafe or unlawful downloads and account compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section explicitly promotes shadow-library sources such as Anna’s Archive, Z-Library, and LibGen, including mirror-hunting guidance, without any legal, copyright, malware, or credential-safety warning. In the context of a skill whose purpose is to help users download content from across the internet, this materially facilitates copyright infringement and increases exposure to malicious mirrors, phishing, and unsafe downloads.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The academic papers section includes Sci-Hub as a recommended workflow and presents it alongside legitimate sources without warning that it is widely associated with unauthorized access to copyrighted papers and may violate law or organizational policy. This normalization can steer users away from safer legal sources and toward risky domains that often rotate and may be impersonated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The download examples provide operational steps for using yt-dlp, including authenticated access, without warning that cookies can expose active sessions or that downloading members-only material may violate platform policies. In a skill centered on obtaining digital resources broadly, omission of these guardrails increases misuse risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file explicitly instructs users to supply browser-derived cookies to yt-dlp for accessing members-only content. While this may be framed as convenience for legitimate offline viewing, it normalizes use of authenticated session material in a broad 'download anything' skill and can facilitate bypass of platform access controls or unsafe handling of sensitive session data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The section recommends tools like coursera-dl, edx-dl, yt-dlp, and wget --mirror for offline copying of course materials without clarifying authorization, copyright, or acceptable-use boundaries. That omission can encourage bulk copying of educational content beyond intended personal use or permitted platform functionality.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/media-assets.md (reported line 29)May include surrounding context.

Programmatic access:

bash
# Unsplash API (free, 50 req/hr)
curl "https://api.unsplash.com/search/photos?query=mountain&per_page=10" \
  -H "Authorization: Client-ID YOUR_ACCESS_KEY"

# Pexels API (free, 200 req/hr)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/media-assets.md (reported line 33)May include surrounding context.

md
-H "Authorization: Client-ID YOUR_ACCESS_KEY"

# Pexels API (free, 200 req/hr)
curl "https://api.pexels.com/v1/search?query=nature&per_page=10" \
  -H "Authorization: YOUR_API_KEY"

# Pixabay API (free, 100 req/min)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file provides direct commands for spotDL, yt-dlp, and a Cobalt instance to extract or download audio from online services without any warning about copyright, authorization, or platform terms. In this skill's context—'download virtually any digital resource'—that omission materially increases misuse risk by normalizing extraction from services that may not permit it.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/music.md (reported line 76)May include surrounding context.

Cobalt -- Quick Audio Grab

bash
curl -X POST "https://YOUR-INSTANCE/" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/video.md (reported line 123)May include surrounding context.

Cobalt -- Quick Audio Grab

bash
curl -X POST "https://YOUR-INSTANCE/" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation is internally inconsistent: it states Listen 1 is 'streams only, no download' but later recommends Listen 1 or LX Music with custom sources as a practical way to download from Chinese streaming platforms. In a skill explicitly designed to help users obtain digital content, this contradiction can mislead users into unauthorized circumvention workflows and obscures the real legal and policy risks of those tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Chinese music section recommends download sites and multi-source/custom-source clients without warning that some sources may be unauthorized mirrors or facilitate access outside official platform permissions. Because the skill explicitly covers finding and downloading content across Chinese ecosystems, this guidance strongly enables potentially infringing acquisition at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The VGM and podcast sections include extraction and batch-download instructions, including YouTube OST ripping and RSS scraping, without addressing rights, authorization, or the impact of bulk downloading on third-party services. That creates a clear misuse path for large-scale copying of copyrighted audio and abusive scraping behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.