Back to skill

Security audit

一键收藏抖音B站视频到你的飞书多维表格

Security checks across malware telemetry and agentic risk

Overview

This skill does what it advertises, but it grants broader local command authority than its video-to-Feishu workflow needs and writes persistent records without a clear review step.

Review before installing. Use a dedicated or least-privilege Feishu Base, verify dokobot and lark-cli from trusted sources, and remove unused permissions such as node and rm if your agent supports narrowing allowed tools. Avoid using it for private or access-controlled video links unless the Feishu table sharing settings are appropriate.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrase includes a broad, conversational expression ('帮我整理这个视频') that can plausibly appear in normal chat, increasing the chance of unintended skill invocation. Because this skill performs external fetching and writes data into a Feishu base, accidental triggering can cause unwanted network access and persistence of user-supplied or conversation-derived content.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill is designed to retrieve data from external video platforms and then write records into a user data store (Feishu Base), but it does not clearly warn about outbound data transfer, storage of scraped content, or the trust boundary around provided URLs and generated summaries. In context, this is more dangerous because the skill combines two risky actions—external content collection and persistent third-party storage—without requiring explicit disclosure or confirmation from the user.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.