Back to skill

Security audit

bilibili-reader-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and not malicious, but it handles live Bilibili session cookies, persistent local indexes, and optional outbound PDF delivery in ways users should review carefully.

Install only if you are comfortable giving this skill reusable Bilibili session cookies. Keep the .env file private, set restrictive permissions such as chmod 600 where applicable, avoid sharing logs that may contain cookie prefixes, leave delivery set to none unless you intentionally want PDFs sent to a chat platform, and review or upgrade the pinned dependencies before regular use. Remember that summaries, history, topic data, and vector search data persist locally under the skill data directory, and cron setup can make the skill run in the background.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/auth.py:88
Finding

Bilibili Session Credentials Are Stored with Unenforced Permissions and Partially Logged

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (120)

Known Vulnerable Dependency: chromadb==0.5.23 — 6 advisory(ies): CVE-2026-45830 (ChromaDB allows any authenticated users to arbitrarily read, write, update, or d); CVE-2026-45833 (ChromaDB has a code injection vulnerability); CVE-2026-45831 (ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database,) +3 more

Critical
Category
Supply Chain
Confidence
95% confidence
Finding

chromadb==0.5.23 is flagged with multiple severe advisories including authorization bypass and code injection. If the skill exposes ChromaDB locally or uses it to store/query untrusted embeddings or metadata, these issues can lead to unauthorized data access, tampering, or potentially arbitrary code execution.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

This finding is valid because the documentation directs users to place live Bilibili session cookies into a plaintext .env file. While credential collection is necessary for the skill's functionality, storing reusable session material in a local flat file increases the chance of theft through accidental disclosure, backups, misconfigured permissions, or repository commits.

Content

Scanner excerpt · INSTALL.md (reported line 65)May include surrounding context.

首次使用 Skill 时,Hermes 会自动提示输入 Cookie 值。

方式 B:手动创建 .env 文件

bash
cd ~/.hermes/skills/bilibili-reader

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The explicit step to create and populate a .env file with authentication cookies creates a concrete credential exposure path. In this skill's context, the tokens are not harmless examples; they are real account-linked session artifacts that could be abused for authenticated requests if leaked.

Content

Scanner excerpt · INSTALL.md (reported line 69)May include surrounding context.

bash
cd ~/.hermes/skills/bilibili-reader
cp .env.example .env

编辑 .env 文件:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 259)May include surrounding context.

md
echo '{"processed":[],"stats":{"total_processed":0,"last_processed_at":null}}' > ~/.hermes/skills/bilibili-reader/data/processed.json

# 清除 Topic 图谱
rm ~/.hermes/skills/bilibili-reader/data/topic_graph.json

# 清除向量库
rm -rf ~/.hermes/skills/bilibili-reader/data/chroma_db/

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 262)May include surrounding context.

rm ~/.hermes/skills/bilibili-reader/data/topic_graph.json

清除向量库

rm -rf ~/.hermes/skills/bilibili-reader/data/chroma_db/

text

**Q: PDF 中的中文显示为方块?**

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 262)May include surrounding context.

rm ~/.hermes/skills/bilibili-reader/data/topic_graph.json

清除向量库

rm -rf ~/.hermes/skills/bilibili-reader/data/chroma_db/

text

**Q: PDF 中的中文显示为方块?**

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The skill relies on writing sensitive configuration and authentication material to a .env file, which is plain-text local storage and commonly mishandled, committed, or exposed through logs and tooling. Session cookies and delivery settings stored this way can be reused to access the user's Bilibili account or route outputs externally.

Content

Scanner excerpt · SKILL.md (reported line 367)May include surrounding context.

方式一:配置向导(推荐)

python -m src --config

方式二:手动编辑 .env

DELIVERY_PLATFORM=wechat

text

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The workflow explicitly creates a .env containing extracted cookies after browser-based login. Because these are bearer credentials, compromise of the file can enable unauthorized account access without needing the user's password or MFA challenge.

Content

Scanner excerpt · SKILL.md (reported line 534)May include surrounding context.

md
- **验证**:`cd ${HERMES_SKILL_DIR} && .venv/bin/python -c "from src.bilibili_api import BilibiliAPI; ..."` 如果走 curl 路径会正常返回

### WSL 环境下 Playwright 登录
- **症状**:`python -m src --login` 运行后无输出,无浏览器弹出,.env 未创建
- **原因**:WSL 默认无 GUI,Playwright `headless=False` 无法显示浏览器窗口
- **解决**:检查 WSLg 是否可用(`echo $DISPLAY`,`ls /mnt/wslg/`)
  - WSLg 可用时,Playwright GUI 正常工作。但直接 `python -m src --login` 可能因 stdout 缓冲看不到输出

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

Troubleshooting guidance instructs users to manually copy browser cookies into .env, encouraging direct handling of highly sensitive session secrets. Manual extraction increases the chance of accidental disclosure, phishing-style misuse, clipboard leakage, or insecure storage in shell history and files.

Content

Scanner excerpt · SKILL.md (reported line 544)May include surrounding context.

md
cookies = login_via_browser(save_to_env=True)
    print('Result:', cookies)
    ```
  - WSLg 不可用时,需手动从浏览器获取 Cookie 写入 .env

### 交互式配置脚本 EOFError
- **症状**:`python -m src --config` 或 `run_setup()` 报 `EOFError: EOF when reading a line`

Known Vulnerable Dependency: protobuf==4.25.5 — 4 advisory(ies): CVE-2026-0994 (protobuf affected by a JSON recursion depth bypass); CVE-2025-4565 (protobuf-python has a potential Denial of Service issue); CVE-2026-0994 (protobuf affected by a JSON recursion depth bypass) +1 more

High
Category
Supply Chain
Confidence
87% confidence
Finding

protobuf==4.25.5 is reported with denial-of-service and recursion-related advisories. If the skill processes attacker-controlled protobuf or JSON-encoded protobuf-like data from external services, this can lead to resource exhaustion or parser instability.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: weasyprint==62.3 — 6 advisory(ies): CVE-2025-68616 (WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP R); CVE-2026-55073 (weasyprint Has Server-Side Request Forgery (SSRF)); CVE-2026-49452 (WeasyPrint has CSS Injection via Presentational Hints) +3 more

High
Category
Supply Chain
Confidence
94% confidence
Finding

weasyprint==62.3 is associated with multiple SSRF-related advisories and content-handling issues. This skill generates PDFs from externally sourced subtitles, comments, or other web content, which makes an unsafe HTML/CSS-to-PDF engine materially more dangerous because rendering may trigger network fetches or unsafe resource resolution.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The function is explicitly designed to capture authentication cookies from a logged-in browser session and return them to the caller. Returning session cookies as plain strings increases the chance they are logged, reused by unrelated code, or exfiltrated, enabling unauthorized account access.

Content

Scanner excerpt · src/auth.py (reported line 11)May include surrounding context.

python
"""通过 Playwright 打开浏览器,用户扫码后自动提取 Cookie

    Args:
        save_to_env: 是否自动保存到 .env 文件

    Returns:
        成功返回 {"SESSDATA": "...", "bili_jct": "...", "buvid3": "..."}, 失败返回 None

Static analysis

No suspicious patterns detected.