Back to skill

Security audit

多平台视频发布

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real multi-platform video publisher, but it can post to public accounts and persists reusable login sessions with weak scoping and protection.

Install only if you are comfortable giving the skill control over the named creator accounts. Review every video, title, tag, target platform, and account before running publish commands, avoid the all-platform trigger unless intentional, keep the cookies directory private and out of backups or commits, and do not run setup with elevated privileges or with untrusted Chrome-path input.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup.py:40
Finding

Python Source Injection Through Unsafely Generated Chrome Configuration

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/setup.py:32
Finding

Unpinned Dependencies Are Installed and Executed in the Active Python Environment

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/publish.py:22
Finding

Authentication Cookies and Access Tokens Are Persisted as Unprotected Plaintext Files

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (44)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the code chunk truly contains only metadata/constants while the skill advertises browser automation, login, and publishing, the issue is primarily misrepresentation rather than direct exploitability. It still matters because inaccurate descriptions can bypass scrutiny and lead operators to trust a package whose real capabilities are unclear.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the code chunk truly contains only metadata/constants while the skill advertises browser automation, login, and publishing, the issue is primarily misrepresentation rather than direct exploitability. It still matters because inaccurate descriptions can bypass scrutiny and lead operators to trust a package whose real capabilities are unclear.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the code chunk truly contains only metadata/constants while the skill advertises browser automation, login, and publishing, the issue is primarily misrepresentation rather than direct exploitability. It still matters because inaccurate descriptions can bypass scrutiny and lead operators to trust a package whose real capabilities are unclear.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the code chunk truly contains only metadata/constants while the skill advertises browser automation, login, and publishing, the issue is primarily misrepresentation rather than direct exploitability. It still matters because inaccurate descriptions can bypass scrutiny and lead operators to trust a package whose real capabilities are unclear.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes automatic login and multi-platform publishing, but does not prominently warn that the skill performs irreversible account-impacting actions using saved authentication state. In this context, lack of an explicit warning and confirmation expectation is dangerous because the skill can post content, reuse cookies, and affect multiple third-party accounts with a single invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises very broad natural-language triggers such as '发布视频' and '把视频发到所有平台', without any scoping, confirmation, or exclusion conditions. In an agent environment, this can cause unintended invocation of a capability that performs real external actions across multiple user accounts, increasing the chance of accidental posting or prompt-triggered misuse.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares no tool scope even though it clearly instructs the agent to use shell, filesystem, environment-variable manipulation, network access, and persistent cookie storage. In an agent setting, missing explicit permission boundaries can let a broadly-triggered skill execute powerful actions without adequate review, increasing the chance of unauthorized publishing, local file access, or unintended command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation phrases are broad enough that common requests like '发布视频' or '登录抖音' may auto-trigger a high-impact automation workflow. Because this skill can publish content, open browser sessions, and reuse stored cookies, ambiguous invocation materially raises the risk of accidental or unauthorized actions on external platforms.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description does not clearly warn users that the skill will automate browser actions, store persistent login cookies, and post content to third-party platforms. In context, this omission is dangerous because these are privacy- and account-sensitive operations; users may invoke the skill without understanding that credentials/session state will be retained and content may be published publicly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document explicitly instructs users to store platform session cookies, including sensitive B站 fields such as SESSDATA, in local JSON files without any warning about their credential-equivalent nature or how to protect them. In the context of an automation skill that logs into multiple creator platforms, these cookies can be reused to hijack accounts or publish content if exposed through repo commits, local compromise, backups, or logs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file’s natural-language content is entirely in Chinese, including operational comments such as browser and service configuration notes. This can indicate a language/locale constraint without any user opt-in or documented region-specific justification, which matches the policy-violation category for language choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code persists browser authentication state to disk via storage_state/path and account.json cookie files, enabling long-lived reuse of logged-in sessions. If the local filesystem, workspace, or skill package is accessible to other users or processes, those tokens can be stolen and used to impersonate the account across publishing platforms.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/publish.py (reported line 106)May include surrounding context.

python
cookie_file = COOKIES["bilibili"]
    cookie_file.parent.mkdir(parents=True, exist_ok=True)
    print(f"[B站] 运行 biliup 登录,cookie 保存到: {cookie_file}")
    subprocess.run([str(biliup), "-u", str(cookie_file), "login"], check=True)
    print("[B站] 登录完成")
    return True

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The setup script immediately performs pip installs and downloads Chromium without an upfront warning or consent flow, causing unexpected network activity and modification of the local environment. In a skill intended to be copied into arbitrary OpenClaw instances, this increases supply-chain and trust risk because users may run it before understanding that external code and binaries will be fetched.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/setup.py (reported line 35)May include surrounding context.

python
def install_deps():
    print("安装依赖...")
    subprocess.check_call([sys.executable, "-m", "pip", "install",
                           "playwright", "biliup", "loguru", "requests"], stdout=subprocess.DEVNULL)
    subprocess.check_call([sys.executable, "-m", "playwright", "install", "chromium"])
    print("依赖安装完成")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/setup.py (reported line 37)May include surrounding context.

python
print("安装依赖...")
    subprocess.check_call([sys.executable, "-m", "pip", "install",
                           "playwright", "biliup", "loguru", "requests"], stdout=subprocess.DEVNULL)
    subprocess.check_call([sys.executable, "-m", "playwright", "install", "chromium"])
    print("依赖安装完成")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code explicitly extracts highly sensitive Bilibili session and authentication material from a JSON structure, including SESSDATA, bili_jct, DedeUserID fields, and access_token, and prepares them for direct login use. In the context of an auto-publishing skill that controls browser sessions and platform accounts, handling these credentials without any consent, minimization, masking, lifecycle controls, or user-facing disclosure increases the risk of account takeover or unauthorized posting if the data is exposed or misused.

Content

No source excerpt is available for this finding.

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
55% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · scripts/uploader/bilibili_uploader/main.py (reported line 69)May include surrounding context.

python
with BiliBili(self.data) as bili:
            bili.login_by_cookies(self.cookie_data)
            bili.access_token = self.cookie_data.get('access_token')
            video_part = bili.upload_file(str(self.file), lines=self.lines,
                                          tasks=self.upload_thread_num)  # 上传视频,默认线路AUTO自动选择,线程数量3。
            video_part['title'] = self.title
            self.data.append(video_part)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code persists authenticated browser storage state to disk via context.storage_state(path=account_file) after interactive login, creating a reusable session token file with no visible notice, consent flow, or protection shown in this file. In the context of a multi-platform auto-publishing skill, stolen or reused cookie state could let anyone with filesystem access impersonate the user on Douyin and perform account actions without re-authentication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The publish flow automatically clicks the final "发布" button in a retry loop as soon as it is present, with no explicit confirmation gate at the point of irreversible action. In a skill whose purpose is bulk cross-platform posting, this increases the risk of accidental or unauthorized publication of content, including to the wrong account or with unintended metadata, making the operational context more dangerous rather than less.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code persists Playwright storage state to disk after an interactive login, which typically includes authentication cookies and session data. In a skill that automates posting to social media accounts, silently writing this data creates credential persistence risk: other local users, malware, or later processes could reuse the session to act as the account owner without re-authentication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

After publishing, the skill overwrites and re-saves the account's storage state to disk, extending the lifetime of authenticated session material and potentially replacing prior state without notice. In this context, that makes unauthorized reuse of the managed social media account easier if the local environment or stored file is exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code persists authenticated Playwright browser state to disk via storage_state(path=account_file), which typically includes session cookies and other login artifacts for Weixin. In a local automation skill this may be functional, but storing reusable authenticated state without explicit consent, secure storage controls, or lifecycle protections increases the risk of account takeover if the file is exposed, copied, or reused by another process.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code transmits the local file specified by self.file_path to https://channels.weixin.qq.com/platform/post/create via the browser automation flow. Although uploading is part of the skill's apparent purpose, there is no direct confirmation prompt or explicit user disclosure at the moment the file is attached and sent to the remote service in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

After publishing, the code re-saves the authenticated browser state back to disk, refreshing persisted login material without explicit user notice. This extends the lifetime of a reusable authenticated session and can make credential theft or unauthorized reuse easier if the state file is accessible to other users, processes, or backups.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.exposed_secret_literal

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/utils/stealth.min.js:7

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/uploader/bilibili_uploader/main.py:68