Baidunetdisk Skill
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill is classified as suspicious due to its requirement for highly sensitive Baidu Netdisk credentials (BDUSS and STOKEN) which grant full access to the user's cloud storage, including irreversible deletion capabilities. While the `SKILL.md` documentation transparently warns the user about these risks and the `scripts/main.py` code appears to implement only the stated functionalities without evidence of malicious intent (e.g., no unauthorized data exfiltration, no shell injection vulnerabilities, no persistence mechanisms), the inherent high-risk nature of these permissions and operations warrants a 'suspicious' classification rather than 'benign'. There are no prompt injection attempts against the agent.
