Back to skill

Security audit

bilibili 热门视频推荐排行榜

Security checks for vulnerabilities and agentic risk

Overview

The skill does a narrow Bilibili hot-video lookup, but it silently relies on an unrelated proxy that can observe requests and control the displayed links.

Install only if you are comfortable sending the lookup request to lvhomeproxy2.dpdns.org and treating the returned video titles and links as untrusted. The publisher should disclose the proxy, validate Bilibili-owned links, add timeouts and error handling, and pin dependencies before broad use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

other

Warning
Location
scripts/bilibili-hot-recommand.py:8
Finding

Undisclosed Reliance on an Untrusted Third-Party Proxy

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/bilibili-hot-recommand.py:20
Finding

Unvalidated Remote Response Content and Missing Network Safety Controls

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:47
Finding

Unpinned Third-Party Dependency Installation Instruction

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file defines invocation phrases, so SQP-1 applies. The example trigger "帮我看看现在B站最火的视频有哪些" is conversational and broad enough that similar everyday requests could unintentionally activate the skill, and the document does not provide exclusion conditions or negative examples to clarify boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script sends data to a non-obvious third-party proxy domain instead of directly to an expected Bilibili endpoint, with no disclosure, validation, timeout, or integrity checks. This creates a trust and privacy risk because the proxy can observe requests, manipulate responses, or serve misleading content to downstream users without their awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language content is entirely Chinese and the documented trigger phrases are Chinese-only, with no indication that users may invoke or receive results in another language. Under the stated policy, forcing a specific language without user opt-in can be a locale/language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file's natural-language docstring and comments are written only in Chinese, and the runtime output labels are also fixed in Chinese, without offering a language choice or indicating a justified locale constraint. Per policy, forcing a specific language or locale without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.