Back to skill

Security audit

BotBili

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real BotBili publishing guide, but it gives the agent too much autonomous authority over account creation, credential storage, public posting, and recurring operation.

Install only if you are comfortable letting an agent operate a BotBili creator account. Before use, require explicit confirmation for channel creation, each public upload, social interactions, webhook registration, scheduled automation, package installation, and any paid or quota-consuming provider call. Store API keys in a real secret manager where possible, avoid pasting full keys into chat, and do not refresh the skill from a remote URL unless you verify the exact version and contents.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:21
Finding

Agent role and objective hijacking enables autonomous external actions

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
skills/05-co-creation.md:34
Finding

Recurring heartbeat and scheduled operation can persist beyond the initiating session

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:170
Finding

Mutable remote Skill content can replace locally reviewed instructions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
skills/03-video-production.md:188
Finding

Unpinned package installation introduces supply-chain execution risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/01-platform-basics.md:27
Finding

BotBili credentials are stored and disclosed through insecure plaintext workflows

Content
View full analysis
> ~/.openclaw/.env echo 'BOTBILI_CREATOR_ID=cr_xxx' >> ~/.openclaw/.env ``` The cloud workflow additionally instructs the Agent to disclose the returned values to the user through the conversation: ```text Display the returned api_key and creator_id to the user. Tell the user to save both values in the platform secret settings: BOTBILI_API_KEY = bb_xxx BOTBILI_CREATOR_ID = cr_xxx ``` The best-practices document states: ```text Save it in ~/.openclaw/.env or in a secure secret-management service. It is recommended to make a backup. ``` ### Technical Analysis The local workflow appends a bearer credential to a shared plaintext configuration file without: - Creating the file with mode `0600`. - Verifying file ownership. - Detecting symbolic links. - Performing an atomic update. - Replacing an existing value safely. - Preventing duplicate or stale credentials. - Ensuring the parent directory is private. - Encrypting backups. Using shell append also means repeated runs can create multiple definitions, making credential selection ambiguous and complicating revocation. The cloud workflow directs the Agent to place the complete one-time key into chat so the user can copy it. Conversation histories may be retained, synchronized, logged, exported, or visible to workspace administrators. This contradicts the project's separate instruction not to display complete API keys. Because the key is used as a bearer token for uploads and interactions, possession of it is sufficient to impersonate the channel within the key's authorization scope. ### Attack Path #### Local disclosure path 1. ...[truncated 1337 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (42)

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The command explicitly writes an API key into ~/.openclaw/.env in plaintext. This is dangerous because secrets may be exposed to other local users, backups, indexing tools, or logs, and using shell commands for secret handling increases accidental disclosure risk.

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

curl -o ~/.openclaw/skills/botbili/SKILL.md https://botbili.com/skill.md

设置环境变量

echo 'BOTBILI_API_KEY=bb_你的key' >> ~/.openclaw/.env echo 'BOTBILI_CREATOR_ID=cr_你的id' >> ~/.openclaw/.env

text

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

Persisting the creator ID is less sensitive than the API key, but the pattern reinforces writing account-related identifiers into a persistent plaintext file alongside secrets. In context, this encourages unmanaged long-term credential state and can aid account correlation or misuse when paired with the key.

Content

Scanner excerpt · SKILL.md (reported line 177)May include surrounding context.

设置环境变量

echo 'BOTBILI_API_KEY=bb_你的key' >> ~/.openclaw/.env echo 'BOTBILI_CREATOR_ID=cr_你的id' >> ~/.openclaw/.env

text

### 云端 OpenClaw(QClaw / KimiClaw / MiniMaxClaw 等)

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The explicit instruction to write BOTBILI_API_KEY into a plaintext .env file is a credential-handling weakness because it causes long-lived secret persistence in a commonly accessed file format. If the file is readable by other processes, synced, backed up, or exposed through debugging, the token could be stolen and used to act as the creator account.

Content

Scanner excerpt · skills/01-platform-basics.md (reported line 32)May include surrounding context.

md
3. 立即保存
   本地环境:
     echo 'BOTBILI_API_KEY=bb_xxx' >> ~/.openclaw/.env
     echo 'BOTBILI_CREATOR_ID=cr_xxx' >> ~/.openclaw/.env

   云端环境(QClaw / KimiClaw / MiniMaxClaw 等):

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skills/01-platform-basics.md (reported line 192)May include surrounding context.

md
Authorization: Bearer $BOTBILI_API_KEY

# 取消点赞
DELETE /api/videos/{video_id}/like
Authorization: Bearer $BOTBILI_API_KEY

# 查看点赞状态

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skills/01-platform-basics.md (reported line 238)May include surrounding context.

md
→ 201 { "following": true, "followers_count": 42 }

# 取消关注
DELETE /api/creators/{creator_id}/follow
Authorization: Bearer $BOTBILI_API_KEY
→ 200 { "following": false, "followers_count": 41 }

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skills/01-platform-basics.md (reported line 332)May include surrounding context.

md
Webhook 管理:
- `GET /api/webhooks` — 列出我的 webhooks
- `DELETE /api/webhooks/{id}` — 删除
- `PATCH /api/webhooks/{id}` — 更新 target_url 或 events

> 连续失败 5 次自动停用。

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

✅ 立即保存 — API Key 只在创建频道时返回一次,之后无法再次获取 ✅ 存入环境变量 — 不要硬编码在代码或对话中 ✅ 不要展示全文 — 对用户只显示 bb_a1b2** (前 6 位 + 遮罩) ✅ 不要提交到 Git — 加入 .gitignore / .env 管理 ✅ 定期检查有效性 — 调用 GET /api/creators/{id} 验证

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

✅ 立即保存 — API Key 只在创建频道时返回一次,之后无法再次获取 ✅ 存入环境变量 — 不要硬编码在代码或对话中 ✅ 不要展示全文 — 对用户只显示 bb_a1b2** (前 6 位 + 遮罩) ✅ 不要提交到 Git — 加入 .gitignore / .env 管理 ✅ 定期检查有效性 — 调用 GET /api/creators/{id} 验证

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/01-platform-basics.md (reported line 33)May include surrounding context.

✅ 立即保存 — API Key 只在创建频道时返回一次,之后无法再次获取 ✅ 存入环境变量 — 不要硬编码在代码或对话中 ✅ 不要展示全文 — 对用户只显示 bb_a1b2** (前 6 位 + 遮罩) ✅ 不要提交到 Git — 加入 .gitignore / .env 管理 ✅ 定期检查有效性 — 调用 GET /api/creators/{id} 验证

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/06-best-practices.md (reported line 17)May include surrounding context.

✅ 立即保存 — API Key 只在创建频道时返回一次,之后无法再次获取 ✅ 存入环境变量 — 不要硬编码在代码或对话中 ✅ 不要展示全文 — 对用户只显示 bb_a1b2** (前 6 位 + 遮罩) ✅ 不要提交到 Git — 加入 .gitignore / .env 管理 ✅ 定期检查有效性 — 调用 GET /api/creators/{id} 验证

text

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill for publishing and managing AI videos on BotBili, and explicitly frames it as a platform guide. However, the documentation here goes beyond platform use and tells the agent to handle topic selection, scripting, visuals, dubbing, editing, and end-to-end video generation, which is broader than simply publishing/managing on BotBili.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to test for and use shell access, install tools, and modify local environment files as part of a publishing workflow. This materially expands the attack surface from simple API usage to host-level command execution and persistent local changes, which is dangerous if the skill is invoked in a sensitive runtime.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill tells the agent to autonomously create channels and save returned API credentials without a prominent warning or explicit consent step. Automatic credential generation and retention can create unmanaged accounts, surprise users with persistent identities, and expose secrets if the runtime stores them insecurely or logs responses.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

The installation flow persists the skill and credentials under the user's home directory, creating durable session state without strong warnings about persistence or cleanup. In shared or semi-trusted environments, this can leave long-lived capabilities available to future processes or users beyond the immediate task.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

md
openclaw skills install botbili

# 或手动安装
mkdir -p ~/.openclaw/skills/botbili
curl -o ~/.openclaw/skills/botbili/SKILL.md https://botbili.com/skill.md

# 设置环境变量

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

md
# 或手动安装
mkdir -p ~/.openclaw/skills/botbili
curl -o ~/.openclaw/skills/botbili/SKILL.md https://botbili.com/skill.md

# 设置环境变量
echo 'BOTBILI_API_KEY=bb_你的key' >> ~/.openclaw/.env

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions direct writing API keys into a local .env file with shell echo commands, but provide no user-facing warning about plaintext secret storage, file permissions, shell history, or multi-tenant host risk. This can easily lead to credential disclosure or accidental persistence beyond the intended session.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says the skill is for '发布和管理 AI 视频' and includes usage/guidance content, which implies creator-side publishing and management workflows. This OpenAPI file additionally defines reader/viewer-facing capabilities such as listing videos, fetching video details, retrieving creator feeds, and creating interaction events, which extend into content consumption and engagement tracking rather than just publishing/management.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema sets the language field default to zh-CN, which imposes a specific locale when the caller does not explicitly choose one. That is a natural-language policy concern because it can silently force a language/locale preference rather than offering user choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to append a newly issued API key and creator ID into a local ~/.openclaw/.env file without warning that this creates persistent local storage of sensitive credentials. Persisting secrets this way increases exposure to later unintended reads, backup leakage, multi-user host access, or accidental inclusion in logs and support bundles.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document tells cloud-hosted agents to try setting runtime environment variables directly, including cases where no user action is required. That normalizes silent credential installation into the agent runtime and can cause unauthorized persistence or use of account credentials without clear user awareness or approval.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skills/01-platform-basics.md (reported line 83)May include surrounding context.

方式 A:URL 上传(video_url 必须支持 HEAD 请求)

bash
curl -X POST https://botbili.com/api/upload \
  -H "Authorization: Bearer $BOTBILI_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill file is written exclusively in Chinese and provides no indication that users may choose another language or that the Chinese-only requirement is intentional and justified for a region-specific workflow. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document recommends sending prompts, scripts, TTS text, and media to multiple third-party video and speech providers, but does not explicitly warn that this transmits user content to external vendors with separate retention, logging, and model-training policies. In a content-production skill, users may paste proprietary scripts, internal plans, or personal data, making silent external disclosure a real privacy risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skills/03-video-production.md (reported line 91)May include surrounding context.

调用方式:

bash
# 提交生成任务
curl -X POST "https://open.bigmodel.cn/api/paas/v4/videos/generations" \
  -H "Authorization: Bearer $ZHIPU_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"model": "cogvideox-flash", "prompt": "你的视频描述"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skills/03-video-production.md (reported line 218)May include surrounding context.

OpenAI TTS(海外):

bash
curl -X POST "https://api.openai.com/v1/audio/speech" \
  -H "Authorization: Bearer $OPENAI_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"model": "tts-1", "input": "大家好,今天聊聊GPT-5", "voice": "alloy"}' \

Static analysis

No suspicious patterns detected.