Back to skill

Security audit

B站视频转文字&总结神器-Bilibili video transcribe&summary

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but its script accepts and follows arbitrary URLs instead of limiting requests to Bilibili, which creates an avoidable network-access risk.

Install only if you are comfortable with the script making network requests and sending audio to SiliconFlow for transcription. Prefer using SILICONFLOW_API_KEY from the environment, do not pass keys on the command line, and avoid running it on untrusted URLs until the script restricts input and redirects to approved Bilibili domains.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/bilibili_pipeline.mjs:40
Finding

Unrestricted URL Fetching Enables Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/bilibili_pipeline.mjs:481
Finding

SiliconFlow API Key Can Be Exposed Through Command-Line Arguments

Content
View full analysis
[--output-dir ./output]\n node scripts/bilibili_pipeline.mjs run [--output-dir ./output] [--api-key ] [--model TeleAI/TeleSpeechASR]" ); } ``` The key is then used as a bearer credential: ```js const response = await fetch("https://api.siliconflow.cn/v1/audio/transcriptions", { method: "POST", headers: { Authorization: `Bearer ${apiKey}`, }, body: form, }); ``` ### Technical Analysis The script supports receiving the SiliconFlow API key through `--api-key`. Command-line arguments are an inappropriate transport for long-lived secrets because they may be exposed through: - Process inspection utilities. - Operating-system process telemetry. - Shell command history. - CI/CD logs and job metadata. - Agent execution traces. - Wrapper scripts, debugging tools, or monitoring systems. Environment-variable input is already implemented and is the method documented in `SKILL.md` and `setup.md`. The command-line option is therefore unnecessary for the declared functionality and increases credential exposure without providing a required capability. The code sends the key only to the fixed HTTPS SiliconFlow transcription endpoint. No evidence was found that it transmits the key to Bilibili or another undocumented service ...[truncated 1152 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
---
name: bilibili-transcribe-summary
description: 当用户提供 B 站视频链接、BV 号或 b23.tv 短链,并希望转录、提取字幕、总结或分析视频内容时使用。先检查 Node.js 环境和 SILICONFLOW_API_KEY,优先尝试官方字幕;如果没有字幕,则获取匿名音频地址,下载为 .m4s 后直接改名为 .mp3,无需转码;有 API key 时调用硅基流动 ASR,再按用户要求总结;如果用户没有特别要求,默认输出重点总结。
metadata: {"openclaw":{"homepage":"https://cloud.siliconflow.cn/me/account/ak","primaryEnv":"SILICONFLOW_API_KEY","requires":{"bins":["node"],"env":[]}}}

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
3. 运行 `scripts/bilibili_pipeline.mjs`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
3. 运行 `scripts/bilibili_pipeline.mjs`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
3. 运行 `scripts/bilibili_pipeline.mjs`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
3. 运行 `scripts/bilibili_pipeline.mjs`。

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill uses a persistent .skill-ready.json marker to suppress future environment and API-key checks, which creates a trust-on-first-use condition. If the environment changes, the marker is stale, or a different output directory is reused, the agent may execute without revalidating prerequisites or re-prompting for sensitive configuration, increasing the chance of unsafe or unintended execution.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/bilibili_pipeline.mjs (reported line 287)May include surrounding context.

js
}

  if (result.bvid && result.cid) {
    const subtitleApi = `https://api.bilibili.com/x/player/v2?bvid=${encodeURIComponent(
      result.bvid
    )}&cid=${encodeURIComponent(result.cid)}`;
    const subtitleResponse = await fetchJson(subtitleApi);

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This finding points to the same SiliconFlow upload path: the skill sends downloaded audio to a third-party domain for processing. The danger is contextual rather than inherently malicious—the skill's purpose includes transcription—but absent consent controls and privacy disclosure, the transfer can expose sensitive content to an external processor.

Content

Scanner excerpt · scripts/bilibili_pipeline.mjs (reported line 361)May include surrounding context.

js
form.append("file", new Blob([buffer], { type: "audio/mpeg" }), "audio.mp3");
  form.append("model", model);

  const response = await fetch("https://api.siliconflow.cn/v1/audio/transcriptions", {
    method: "POST",
    headers: {
      Authorization: `Bearer ${apiKey}`,

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This finding points to the same SiliconFlow upload path: the skill sends downloaded audio to a third-party domain for processing. The danger is contextual rather than inherently malicious—the skill's purpose includes transcription—but absent consent controls and privacy disclosure, the transfer can expose sensitive content to an external processor.

Content

Scanner excerpt · scripts/bilibili_pipeline.mjs (reported line 361)May include surrounding context.

js
form.append("file", new Blob([buffer], { type: "audio/mpeg" }), "audio.mp3");
  form.append("model", model);

  const response = await fetch("https://api.siliconflow.cn/v1/audio/transcriptions", {
    method: "POST",
    headers: {
      Authorization: `Bearer ${apiKey}`,

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The note explicitly states the pipeline renamed the downloaded Bilibili audio stream from .m4s to .mp3 without transcoding. However, earlier code sets the output path to audio.mp3 and later sends that file to the transcription API as type audio/mpeg, which can misrepresent the actual file format and contradict the implied meaning of the .mp3 output artifact. This is an intent/documentation mismatch with operational significance because downstream consumers may treat the file as genuine MP3 audio.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

When subtitles are unavailable, the skill uploads downloaded audio to SiliconFlow for transcription, but the code provides no explicit consent prompt, disclosure, or policy gate before sending potentially sensitive audio off-host. This creates a privacy and data-handling risk because users may not realize third-party transmission occurs or that spoken content may contain personal or confidential information.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.md (reported line 44)May include surrounding context.

Ubuntu or Debian

bash
sudo apt-get update
sudo apt-get install -y nodejs npm

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.md (reported line 45)May include surrounding context.

Ubuntu or Debian

bash
sudo apt-get update
sudo apt-get install -y nodejs npm

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code hard-codes "accept-language" to prefer zh-CN and zh for outbound requests. This imposes a specific locale preference in network interactions without offering the user a choice or explaining why a Chinese locale is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.