Back to skill

Security audit

bilibili-cli

Security checks for vulnerabilities and agentic risk

Overview

This Bilibili CLI is coherent, but needs review because it can automatically read browser session cookies, persist login credentials, and perform account-changing actions.

Install only if you are comfortable letting the tool read Bilibili browser cookies, store reusable session credentials locally, and let an agent run authenticated Bilibili actions. Prefer QR login, review account-changing commands before use, clear credentials with bili logout when done, and approve audio extraction only when you expect local media files to be created.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (47)

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.md (reported line 29)May include surrounding context.

User — profile, video list, following list

  • 🔍 Search — search users or videos by keyword
  • 🔥 Trending — hot videos and site-wide ranking
  • 📰 Feed — dynamic timeline from your follows
  • 📂 Favorites — browse favorite folders, watch-later, and watch history
  • 👍 Interactions — like, coin, triple (一键三连)
  • 🔐 Smart auth — auto-extracts cookies from Chrome/Firefox, or QR code login
  • 📊 Structured output — major query commands support --yaml and --json
  • 🤖 Agent-friendly defaults — non-TTY stdout defaults to YAML; override with OUTPUT=yaml|json|rich|auto
  • 📦 Stable envelope — see SCHEMA.md for ok/schema_version/data/error
  • 🧱 Normalized payloads — command-layer output is normalized instead of leaking raw upstream SDK responses

Installation

bash
# Recommended: uv tool (fast, isolated)
uv tool install bilibili-cli

# Or: pipx
pipx install bilibili-cli

# If you n

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The README documents loading saved credentials from ~/.bilibili-cli/credential.json and auto-extracting browser cookies. In an agent-integrated CLI, this represents real credential access behavior: if the tool is invoked by an agent or script, it may read reusable authentication secrets from disk or browsers, enabling account access and write actions without sufficiently explicit user interaction.

Content

Scanner excerpt · README.md (reported line 140)May include surrounding context.

md
bilibili-cli uses a 3-tier authentication strategy:

1. **Saved credential** — loads from `~/.bilibili-cli/credential.json`
2. **Browser cookies** — auto-extracts from Chrome, Firefox, Edge, or Brave
3. **QR code login** — `bili login` displays a QR code in the terminal

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

This is the Chinese-language duplicate documenting the same credential-loading and browser-cookie extraction behavior. The risk remains that the skill can access and reuse local session credentials, which is especially sensitive in automated-agent environments.

Content

Scanner excerpt · README.md (reported line 352)May include surrounding context.

md
bilibili-cli 采用三级认证策略:

1. **已保存凭证** — 从 `~/.bilibili-cli/credential.json` 加载
2. **浏览器 Cookie** — 自动从 Chrome、Firefox、Edge、Brave 提取
3. **扫码登录** — `bili login` 在终端显示二维码

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill's declared purpose emphasizes browsing and YAML retrieval, but it also offers audio extraction, local saving, and optional segmentation with PyAV. That discrepancy matters because media extraction and filesystem operations introduce persistence, content-handling, and potentially copyright/privacy-sensitive behaviors that are materially different from metadata browsing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill's declared purpose emphasizes browsing and YAML retrieval, but it also offers audio extraction, local saving, and optional segmentation with PyAV. That discrepancy matters because media extraction and filesystem operations introduce persistence, content-handling, and potentially copyright/privacy-sensitive behaviors that are materially different from metadata browsing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill's declared purpose emphasizes browsing and YAML retrieval, but it also offers audio extraction, local saving, and optional segmentation with PyAV. That discrepancy matters because media extraction and filesystem operations introduce persistence, content-handling, and potentially copyright/privacy-sensitive behaviors that are materially different from metadata browsing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill's declared purpose emphasizes browsing and YAML retrieval, but it also offers audio extraction, local saving, and optional segmentation with PyAV. That discrepancy matters because media extraction and filesystem operations introduce persistence, content-handling, and potentially copyright/privacy-sensitive behaviors that are materially different from metadata browsing.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

Automatic detection of cookies from Chrome, Firefox, Edge, and Brave is effectively credential-source access, even if intended for convenience. Because the skill also supports authenticated interactions, those cookies can be leveraged for actions on behalf of the user, raising privacy and account-abuse risk.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

bili login # QR code login (if not authenticated)

text

Authentication auto-detects local browser cookies (Chrome/Firefox/Edge/Brave). If cookies are found and valid, no manual login needed. Credentials are saved to `~/.bilibili-cli/credential.json`.

## Command Reference

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

Automatic detection of cookies from Chrome, Firefox, Edge, and Brave is effectively credential-source access, even if intended for convenience. Because the skill also supports authenticated interactions, those cookies can be leveraged for actions on behalf of the user, raising privacy and account-abuse risk.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

bili login # QR code login (if not authenticated)

text

Authentication auto-detects local browser cookies (Chrome/Firefox/Edge/Brave). If cookies are found and valid, no manual login needed. Credentials are saved to `~/.bilibili-cli/credential.json`.

## Command Reference

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

io]"

Or: pipx install "bilibili-cli[audio]"

text

## Authentication

Most read commands work without login. Subtitles, favorites/following/watch-later/history, feed, and interactions require login.

```bash
bili status                    # Check if logged in (exit 0 = yes, 1 = no)
bili login                     # QR code login (if not authenticated)

Authentication auto-detects local browser cookies (Chrome/Firefox/Edge/Brave). If cookies are found and valid, no manual login needed. Credentials are saved to ~/.bilibili-cli/credential.json.

Command Reference

Video

bash
# Get video details (accepts BV ID or full URL)
bili video BV1ABcsztEcY
bili video https://www.bilibili.com/video/BV1ABcsztEcY

# Options
bili video BV1ABcsztEcY --subtitle            # Show subtitles (plain text)
bili video BV1ABcsztEcY --subtitle-timeline   # Show subtitles with timestamps
bili video BV1ABcsztEcY -st --subtitle-format srt  # Export as SRT format
bili video BV1ABcsztEcY --ai

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The authentication strategy explicitly includes storing and reusing session credentials from a local JSON file and sourcing them from browsers. In an agent skill, persistent credential handling is sensitive because compromise of the file or unintended invocation of the skill can yield authenticated account access without re-prompting the user.

Content

Scanner excerpt · bili_cli/auth.py (reported line 4)May include surrounding context.

python
"""Authentication for Bilibili.

Strategy:
1. Try loading saved credential from ~/.bilibili-cli/credential.json
2. Try extracting cookies from local browsers via browser-cookie3
3. Fallback: QR code login via bilibili-api-python + terminal display
"""

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

This path defines a fixed credential file under the user's home directory, and later code writes active session data there. Even with 0600 permissions, storing bearer-style session material in a predictable plaintext location increases exposure to local compromise, backups, or accidental disclosure by other tooling.

Content

Scanner excerpt · bili_cli/auth.py (reported line 28)May include surrounding context.

python
logger = logging.getLogger(__name__)

CONFIG_DIR = Path.home() / ".bilibili-cli"
CREDENTIAL_FILE = CONFIG_DIR / "credential.json"

# Required cookies for a valid Bilibili session
REQUIRED_COOKIES = {"SESSDATA"}

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill metadata frames this as a browsing/YAML-output CLI, but this code also exposes authenticated state-changing operations such as following/unfollowing users, posting/deleting dynamics, and liking/coin/triple actions. In an agent setting, capability mismatch is dangerous because a caller may grant credentials expecting read-only behavior, while the skill can silently perform account actions with side effects.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata describes browsing and interactions, but this file also implements write-capable operations that post and delete Bilibili dynamics. That mismatch is dangerous because an agent or user relying on the manifest may grant or invoke the skill expecting read-oriented behavior, while the code can perform irreversible account actions once authenticated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The tests demonstrate commands that perform state-changing and destructive actions, such as posting and deleting dynamics, even though the skill metadata describes the tool as browse-focused. This mismatch is dangerous because an agent or user may grant trust or credentials based on a read-only mental model, while the skill can actually modify account state and remove content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README advertises automatic extraction of browser cookies for authentication, but it does not prominently warn users that this accesses sensitive local browser credential material. In an agent-skill context, this is risky because an agent may invoke such behavior without the user fully understanding that browser session data is being read and reused.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
74% confidence
Finding

The README indicates persistent authentication plus normalized write actions such as like, coin, triple, unfollow, and posting/deleting dynamics. Persisted sessions combined with write-capable credentials increase the blast radius of any unintended or agent-driven invocation, because actions can be performed later without fresh re-authentication.

Content

Scanner excerpt · README.md (reported line 132)May include surrounding context.

bili coin BV1ABcsztEcY # Give coin bili triple BV1ABcsztEcY # 一键三连 🎉 bili unfollow 946974 # Unfollow by UID bili like BV1ABcsztEcY --json # Structured write result bili coin BV1ABcsztEcY --yaml # Structured write result

text

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 198)May include surrounding context.

git clone git@github.com:jackwener/bilibili-cli.git .agents/skills/bilibili-cli

Or just copy the SKILL.md

curl -o .agents/skills/bilibili-cli/SKILL.md
https://raw.githubusercontent.com/jackwener/bilibili-cli/main/SKILL.md

text

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 409)May include surrounding context.

git clone git@github.com:jackwener/bilibili-cli.git .agents/skills/bilibili-cli

Or just copy the SKILL.md

curl -o .agents/skills/bilibili-cli/SKILL.md
https://raw.githubusercontent.com/jackwener/bilibili-cli/main/SKILL.md

text

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documents use of shell, network access, local file writes, environment interaction, and credential handling, but it does not declare any explicit tool scope or allowed-tools boundary. In an agent setting, that omission weakens least-privilege controls and can let the skill invoke broader capabilities than a reviewer or orchestrator would expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents account-modifying commands such as like, coin, triple, unfollow, dynamic-post, and dynamic-delete without prominent warnings or confirmation guidance. In agent-driven use, this increases the risk of unintended social/account actions, irreversible deletions, or misuse of authenticated sessions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 246)May include surrounding context.

md
## Safety Notes

- Do not ask users to share raw credential/cookie values in chat logs.
- Prefer local browser cookie extraction over manual secret copy/paste.
- If auth fails, ask the user to re-login via `bili login`.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module is designed to automatically extract authentication cookies from local browsers, which is a sensitive credential-access capability beyond basic video browsing. In an agent skill context, silently harvesting browser session material is especially risky because the agent can gain account access without an explicit, informed consent step from the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

At the point where saved credentials are stale, the code automatically attempts browser extraction without any user-facing disclosure or confirmation. Accessing local browser cookies without an immediate warning is dangerous because it can silently expand the tool's privileges to a user's authenticated Bilibili session.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · bili_cli/auth.py (reported line 210)May include surrounding context.

python
'''

    try:
        result = subprocess.run(
            [sys.executable, "-c", extract_script],
            capture_output=True,
            text=True,

Static analysis

No suspicious patterns detected.