T09 · Insecure Skill Coding Practices
- Location
scripts/bilibili_pipeline.mjs:40- Finding
Unrestricted URL Fetching Enables Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it says, but its script accepts and follows arbitrary URLs instead of limiting requests to Bilibili, which creates an avoidable network-access risk.
Install only if you are comfortable with the script making network requests and sending audio to SiliconFlow for transcription. Prefer using SILICONFLOW_API_KEY from the environment, do not pass keys on the command line, and avoid running it on untrusted URLs until the script restricts input and redirects to approved Bilibili domains.
scripts/bilibili_pipeline.mjs:40Unrestricted URL Fetching Enables Server-Side Request Forgery
scripts/bilibili_pipeline.mjs:481SiliconFlow API Key Can Be Exposed Through Command-Line Arguments
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
---
name: bilibili-transcribe-summary
description: 当用户提供 B 站视频链接、BV 号或 b23.tv 短链,并希望转录、提取字幕、总结或分析视频内容时使用。先检查 Node.js 环境和 SILICONFLOW_API_KEY,优先尝试官方字幕;如果没有字幕,则获取匿名音频地址,下载为 .m4s 后直接改名为 .mp3,无需转码;有 API key 时调用硅基流动 ASR,再按用户要求总结;如果用户没有特别要求,默认输出重点总结。
metadata: {"openclaw":{"homepage":"https://cloud.siliconflow.cn/me/account/ak","primaryEnv":"SILICONFLOW_API_KEY","requires":{"bins":["node"],"env":[]}}}
Referenced artifact was not completely inspected
3. 运行 `scripts/bilibili_pipeline.mjs`。
Referenced artifact was not completely inspected
3. 运行 `scripts/bilibili_pipeline.mjs`。
Referenced artifact was not completely inspected
3. 运行 `scripts/bilibili_pipeline.mjs`。
Referenced artifact was not completely inspected
3. 运行 `scripts/bilibili_pipeline.mjs`。
The skill uses a persistent .skill-ready.json marker to suppress future environment and API-key checks, which creates a trust-on-first-use condition. If the environment changes, the marker is stale, or a different output directory is reused, the agent may execute without revalidating prerequisites or re-prompting for sensitive configuration, increasing the chance of unsafe or unintended execution.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
if (result.bvid && result.cid) {
const subtitleApi = `https://api.bilibili.com/x/player/v2?bvid=${encodeURIComponent(
result.bvid
)}&cid=${encodeURIComponent(result.cid)}`;
const subtitleResponse = await fetchJson(subtitleApi);
This finding points to the same SiliconFlow upload path: the skill sends downloaded audio to a third-party domain for processing. The danger is contextual rather than inherently malicious—the skill's purpose includes transcription—but absent consent controls and privacy disclosure, the transfer can expose sensitive content to an external processor.
form.append("file", new Blob([buffer], { type: "audio/mpeg" }), "audio.mp3");
form.append("model", model);
const response = await fetch("https://api.siliconflow.cn/v1/audio/transcriptions", {
method: "POST",
headers: {
Authorization: `Bearer ${apiKey}`,
This finding points to the same SiliconFlow upload path: the skill sends downloaded audio to a third-party domain for processing. The danger is contextual rather than inherently malicious—the skill's purpose includes transcription—but absent consent controls and privacy disclosure, the transfer can expose sensitive content to an external processor.
form.append("file", new Blob([buffer], { type: "audio/mpeg" }), "audio.mp3");
form.append("model", model);
const response = await fetch("https://api.siliconflow.cn/v1/audio/transcriptions", {
method: "POST",
headers: {
Authorization: `Bearer ${apiKey}`,
The note explicitly states the pipeline renamed the downloaded Bilibili audio stream from .m4s to .mp3 without transcoding. However, earlier code sets the output path to audio.mp3 and later sends that file to the transcription API as type audio/mpeg, which can misrepresent the actual file format and contradict the implied meaning of the .mp3 output artifact. This is an intent/documentation mismatch with operational significance because downstream consumers may treat the file as genuine MP3 audio.
When subtitles are unavailable, the skill uploads downloaded audio to SiliconFlow for transcription, but the code provides no explicit consent prompt, disclosure, or policy gate before sending potentially sensitive audio off-host. This creates a privacy and data-handling risk because users may not realize third-party transmission occurs or that spoken content may contain personal or confidential information.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sudo apt-get update
sudo apt-get install -y nodejs npm
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sudo apt-get update
sudo apt-get install -y nodejs npm
The code hard-codes "accept-language" to prefer zh-CN and zh for outbound requests. This imposes a specific locale preference in network interactions without offering the user a choice or explaining why a Chinese locale is required.
No suspicious patterns detected.