bilibili 热门视频推荐排行榜

Security checks across malware telemetry and agentic risk

Overview

This skill fetches public Bilibili trending-video data, but users should notice that it does so through an undeclared third-party proxy domain.

Install only if you are comfortable with the skill contacting an undeclared third-party proxy to obtain Bilibili results. It does not appear to access credentials or local private data, but the publisher should ideally disclose the proxy endpoint and formalize the requests dependency.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger example uses a broad natural-language request ('帮我看看现在B站最火的视频有哪些') that can easily appear in ordinary conversation, increasing the chance the skill activates unintentionally when a user is merely discussing trending videos. Accidental invocation can cause context hijacking or unexpected external data retrieval, especially in systems where trigger matching is loose or automatic.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal