T03 · Remote Payload Retrieval and Execution
- Location
references/software.md:65- Finding
Remote Installer Scripts Are Downloaded and Executed Without Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a transparent but very broad download toolkit that points users toward piracy-associated sources and uses high-risk install, cookie, and network-service patterns.
Install only if you are comfortable reviewing each command before it runs. Use it only for content you are authorized to access, avoid the piracy-oriented source lists and rotating mirrors, do not expose aria2 RPC, avoid browser-cookie options unless you explicitly choose a dedicated low-risk profile, and prefer pinned or OS-packaged dependencies over the bulk installer.
references/software.md:65Remote Installer Scripts Are Downloaded and Executed Without Verification
scripts/install-toolkit.sh:32Toolkit Installs Unpinned Third-Party Packages Into Shared Environments
references/tools-reference.md:277Aria2 RPC Example Exposes Unauthenticated Download Control to the Network
scripts/dl-video.sh:29Video Downloader Automatically Probes and Reads Browser Authentication Cookies
The declared description presents a comprehensive tool for finding and downloading virtually any kind of digital resource across many ecosystems and tools. The supplied code chunk does not implement that broad purpose. Instead, it performs a specific subtitle-related task: for URLs, it invokes yt-dlp only to fetch subtitles/auto-subs and skips media download; for non-URL input, it merely prints subtitle search URLs for manual use. This is a materially different and much narrower primary purpose than the declared skill, so the description does not accurately represent the code chunk's actual behavior.
The trigger language is so broad that the skill may be invoked for almost any request involving digital content, including ambiguous or risky scenarios. In context, this increases the chance an agent routes users into workflows involving copyrighted material, torrents, scraping, or downloads from untrusted sources without adequate guardrails.
The download tips instruct users to try Sci-Hub first for DOI-to-PDF and to check Anna’s Archive, LibGen, and Z-Library first for textbooks, which is direct procedural guidance for accessing likely infringing sources. Because these are framed as default first-line steps, the skill increases the likelihood of policy violations, copyright infringement, and exposure to malicious or spoofed download sites.
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
/ CS: Python教程, 前端开发, 机器学习
高等数学, 线性代数, 概率论英语学习, 日语入门物理, 化学, 生物PS教程, UI设计, 视频剪辑Download Bilibili courses:
# yt-dlp supports Bilibili
yt-dlp "https://www.bilibili.com/video/BV..."
# For members-only content, use cookies
yt-dlp --cookies-from-browser chrome "URL"
# Download entire multi-part video (合集)
yt-dlp --yes-playlist "URL"
# List all parts first
yt-dlp --flat-playlist "URL"
Many platforms allow downloading materials for offline use:
| Platform | Downloadable Content | How |
|---|---|---|
| MIT OCW | Lecture notes, problem sets, exams (PDF). Some video. | Direct download from course page. |
| Khan Academy | Videos (via yt-dlp) | yt-dlp "khanacademy.org/..." |
| Coursera | Videos, slides (enrolled courses) | Use coursera-dl (` |
The source-specific guidance explicitly points users toward piracy-associated services and communities such as Anna's Archive, Z-Library, Sci-Hub, r/Piracy, and r/opendirectories, without clear restrictions to lawful or authorized content. Given the skill's stated purpose of helping users download almost any digital resource, these references strongly increase the likelihood of facilitating copyright infringement and access to unauthorized copies at scale.
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
`
# Full playlist
yt-dlp --yes-playlist "PLAYLIST_URL"
# Playlist range
yt-dlp --playlist-items 1,3,5-7 "PLAYLIST_URL"
# Entire channel
yt-dlp "https://www.youtube.com/@CHANNEL"
# Batch from file
yt-dlp -a urls.txt
# Skip already downloaded
yt-dlp --download-archive archive.txt "URL"
# Cookies from browser (easiest auth)
yt-dlp --cookies-from-browser chrome "URL"
yt-dlp --cookies-from-browser firefox "URL"
# Cookies file
yt-dlp --cookies cookies.txt "URL"
# Proxy
yt-dlp --proxy socks5://127.0.0.1:1080 "URL"
# Geo-bypass
yt-dlp --geo-bypass-country US "URL"
# Rate limit
yt-dlp --limit-rate 5M "URL"
# Resume
yt-dlp --no-overwrites -c "URL"
# Get metadata as JSON (no download) -- CRITICAL for agent use
yt-dlp -j --no-download "URL"
# Get direct download URL only (pipe to aria2/curl)
yt-dlp -g "URL"
# Output template
yt-dlp -o "%(title)s.%(ext)s" "URL"
yt-dlp -o "%(uploader)s
The aria2 example enables RPC with --rpc-listen-all=true and --rpc-allow-origin-all=true, which can expose unauthenticated download control to other hosts and web origins if the service is reachable. In a skill designed for broad downloading, this could let an attacker enqueue arbitrary downloads, write files to attacker-chosen locations, or abuse the host as a downloader.
The --cookies-from-browser chrome pattern matches credential access behavior because it reads authenticated browser cookies from the user's local profile. Even though presented as a convenience feature for downloading members-only media, in an agent skill this can facilitate unauthorized access, session theft, or accidental exfiltration of active account credentials if logs, subprocess arguments, or follow-on tooling capture them.
nload. |
# Best 1080p video
yt-dlp -f "bv[height<=1080]+ba/b[height<=1080]" "URL"
# List formats first
yt-dlp -F "URL"
# Download with subtitles
yt-dlp --write-subs --sub-lang en,zh --embed-subs "URL"
# Audio only (MP3)
yt-dlp -x --audio-format mp3 "URL"
# Bilibili (need cookies for members-only)
yt-dlp --cookies-from-browser chrome "https://www.bilibili.com/video/BV..."
# Twitter/X video
yt-dlp "https://twitter.com/user/status/ID"
# TikTok (no watermark)
yt-dlp "https://www.tiktok.com/@user/video/ID"
# Download entire playlist
yt-dlp --yes-playlist "PLAYLIST_URL"
# Get metadata only (no download)
yt-dlp -j --no-download "URL"
| Web | cobalt.tools |
| API | Self-host via Docker for agent use |
| Supports | YouTube, TikTok, Instagram, Twitter, Reddit, SoundCloud, 30+ sites |
# API call (self-hosted instance)
curl -X POST "https://YOUR-INS
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
[height<=720]+ba/b" ;;
480) FORMAT="bv[height<=480][vcodec~='^(avc|hev)'][ext=mp4]+ba[acodec~='^(mp4a)'][ext=m4a]/bv[height<=480][ext=mp4]+ba[ext=m4a]/bv[height<=480]+ba/b" ;;
*) FORMAT="$QUALITY" ;; # allow raw format string
esac
EXTRA_ARGS=()
# Auto-detect sites that require browser cookies
if [[ "$URL" =~ bilibili\.com|b23\.tv ]]; then
# Bilibili returns HTTP 412 without cookies. Try Chrome first, then Firefox.
for browser in chrome firefox edge; do
if yt-dlp --cookies-from-browser "$browser" -j "$URL" &>/dev/null; then
EXTRA_ARGS+=(--cookies-from-browser "$browser")
break
fi
done
if [[ ${#EXTRA_ARGS[@]} -eq 0 ]]; then
echo "⚠ Bilibili requires login cookies. Log in via Chrome/Firefox first." >&2
echo " Or export cookies: yt-dlp --cookies cookies.txt ..." >&2
fi
fi
yt-dlp \
-f "$FORMAT" \
--merge-output-format mp4 \
--embed-metadata \
--embed-thumbnail \
--write-sub
The skill advertises and invokes shell-based download workflows but does not declare any tool scope or permissions boundaries. In an agent environment, this can enable unintended shell execution for network retrieval, file writes, and potentially unsafe follow-on handling of untrusted content without explicit authorization controls.
The skill encourages downloading and processing arbitrary internet resources, including software, torrents, and files from rotating mirror sites, but provides no warnings about malware, legal risk, unsafe execution, or provenance verification. That omission is dangerous because users or agents may treat the workflow as routine and fetch untrusted content directly into the local environment.
This section gives operational guidance for locating, saving, and downloading files from third-party cloud-drive search engines, including workaround advice for throttling, but does not warn about copyright infringement, malware-laden files, credential exposure, or the risks of exporting browser cookies. In the context of a skill explicitly designed to help users download virtually any digital resource, this omission materially increases the chance of facilitating unsafe or unlawful downloads and account compromise.
This section explicitly promotes shadow-library sources such as Anna’s Archive, Z-Library, and LibGen, including mirror-hunting guidance, without any legal, copyright, malware, or credential-safety warning. In the context of a skill whose purpose is to help users download content from across the internet, this materially facilitates copyright infringement and increases exposure to malicious mirrors, phishing, and unsafe downloads.
The academic papers section includes Sci-Hub as a recommended workflow and presents it alongside legitimate sources without warning that it is widely associated with unauthorized access to copyrighted papers and may violate law or organizational policy. This normalization can steer users away from safer legal sources and toward risky domains that often rotate and may be impersonated.
The download examples provide operational steps for using yt-dlp, including authenticated access, without warning that cookies can expose active sessions or that downloading members-only material may violate platform policies. In a skill centered on obtaining digital resources broadly, omission of these guardrails increases misuse risk.
The file explicitly instructs users to supply browser-derived cookies to yt-dlp for accessing members-only content. While this may be framed as convenience for legitimate offline viewing, it normalizes use of authenticated session material in a broad 'download anything' skill and can facilitate bypass of platform access controls or unsafe handling of sensitive session data.
The section recommends tools like coursera-dl, edx-dl, yt-dlp, and wget --mirror for offline copying of course materials without clarifying authorization, copyright, or acceptable-use boundaries. That omission can encourage bulk copying of educational content beyond intended personal use or permitted platform functionality.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Programmatic access:
# Unsplash API (free, 50 req/hr)
curl "https://api.unsplash.com/search/photos?query=mountain&per_page=10" \
-H "Authorization: Client-ID YOUR_ACCESS_KEY"
# Pexels API (free, 200 req/hr)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
-H "Authorization: Client-ID YOUR_ACCESS_KEY"
# Pexels API (free, 200 req/hr)
curl "https://api.pexels.com/v1/search?query=nature&per_page=10" \
-H "Authorization: YOUR_API_KEY"
# Pixabay API (free, 100 req/min)
The file provides direct commands for spotDL, yt-dlp, and a Cobalt instance to extract or download audio from online services without any warning about copyright, authorization, or platform terms. In this skill's context—'download virtually any digital resource'—that omission materially increases misuse risk by normalizing extraction from services that may not permit it.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST "https://YOUR-INSTANCE/" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-d '{
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST "https://YOUR-INSTANCE/" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-d '{
The documentation is internally inconsistent: it states Listen 1 is 'streams only, no download' but later recommends Listen 1 or LX Music with custom sources as a practical way to download from Chinese streaming platforms. In a skill explicitly designed to help users obtain digital content, this contradiction can mislead users into unauthorized circumvention workflows and obscures the real legal and policy risks of those tools.
The Chinese music section recommends download sites and multi-source/custom-source clients without warning that some sources may be unauthorized mirrors or facilitate access outside official platform permissions. Because the skill explicitly covers finding and downloading content across Chinese ecosystems, this guidance strongly enables potentially infringing acquisition at scale.
The VGM and podcast sections include extraction and batch-download instructions, including YouTube OST ripping and RSS scraping, without addressing rights, authorization, or the impact of bulk downloading on third-party services. That creates a clear misuse path for large-scale copying of copyrighted audio and abusive scraping behavior.
No suspicious patterns detected.