Back to skill

Security audit

biliup-skills

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently helps upload videos to Bilibili, with disclosed setup, login, credential, and upload steps but some dependency and URL-handling risks to review.

Install only if you are comfortable letting the agent install Python packages, store a Bilibili access credential in cookies.json, and post videos to your Bilibili account. Use trusted video paths or URLs, protect cookies.json, and confirm the title, tags, category, and target account before upload.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
scripts/setup_biliup.sh:33
Finding

Unpinned Installation of the biliup Package

Content
View full analysis
/dev/null; then echo "🛠️ 使用 pipx 安装..." pipx install biliup echo "✅ biliup 安装成功(pipx)" exit 0 fi # 回退到 pip install --user if command -v pip3 &>/dev/null; then echo "🛠️ 使用 pip3 install --user 安装..." pip3 install --user biliup elif command -v pip &>/dev/null; then echo "🛠️ 使用 pip install --user 安装..." pip install --user biliup else ``` ### Technical Analysis The setup script installs `biliup` by package name without pinning a reviewed version or verifying package hashes. Each invocation can therefore resolve to a different package release and transitive dependency set. Installation of a Python package can execute package-controlled build and installation logic. Although `biliup` is a plausible package from the expected package index and no direct evidence of a currently malicious release was found, the installation process trusts mutable upstream artifacts without integrity constraints. The resulting CLI is subsequently used with Bilibili authentication credentials and user video files. Using `pipx` provides environment isolation but does not address package authenticity, release mutability, or integrity verification. ### Attack Path 1. An attacker compromises the upstream `biliup` package, one of its dependencies, or the package distribution account. 2. A malicious or compromised release becomes the version resolved by `pipx` or `pip`. 3. A user runs `scripts/setup_biliup.sh`. 4. The package manager downloads and installs the mutable release without checking a pinned version or expected hash. 5. Malicious installation logic or imported runtime code executes with the privileges of the user running the script. 6. The malicious package can access files available to that u ...[truncated 445 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/qr_login.py:42
Finding

Automatic Installation of Unpinned QR-Code Dependencies During Login

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/qr_login.py:151
Finding

Predictable Shared Temporary Path for the Login QR Image

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个完整的 B 站投稿技能,覆盖安装 biliup、扫码登录、收集投稿元数据、执行上传与返回结果等端到端流程。但提供的代码块是 qr_login.py,其行为聚焦于登录阶段:检测 biliup 可执行文件是否存在、安装二维码生成依赖、运行 biliup login、从输出中提取授权链接、生成 PNG 二维码,并可等待登录完成。该代码没有任何与视频文件、标题/简介/分区等投稿参数、上传命令调用或投稿结果解析相关的逻辑。因此描述显著超出了代码实际能力,且代码的主要用途与声明的主要用途不一致,应判定为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill explicitly instructs shell execution (bash, pip, curl, python3) but does not declare any tool scope or allowed-tools restrictions. That makes the operational boundary unclear and increases the chance an agent executes powerful commands without policy gating, especially because the workflow includes package installation, network access, and file handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger description uses broad, open-ended activation phrasing, which can cause the skill to run in unintended contexts. Because the skill performs sensitive actions like login, package installation, shell commands, and uploads, overly broad triggering materially raises the risk of accidental or unauthorized execution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill expands into downloading arbitrary user-provided URLs via curl -L, which introduces SSRF-like behavior, untrusted content retrieval, and potential delivery of malicious files. Even with a later file check, the agent may still fetch internal resources, large payloads, or deceptive content outside the stated upload-only purpose.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
88% confidence
Finding

The script automatically installs a Python package at runtime via pip without version pinning, hash verification, or an isolated environment. This creates a supply-chain risk: if package resolution is tampered with or a malicious dependency is served, arbitrary code could execute during installation with the privileges of the running process.

Content

Scanner excerpt · scripts/qr_login.py (reported line 47)May include surrounding context.

python
from PIL import Image  # noqa: F401
    except ImportError:
        print("📦 安装 qrcode[pil] 依赖...", file=sys.stderr)
        subprocess.run(
            [sys.executable, "-m", "pip", "install", "-q", "qrcode[pil]"],
            check=True,
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/qr_login.py (reported line 84)May include surrounding context.

python
cmd = [biliup_path, "-u", cookie_path, "login"]
    print(f"▶ 启动: {' '.join(cmd)}", file=sys.stderr)

    proc = subprocess.Popen(
        cmd,
        stdout=subprocess.PIPE,
        stderr=subprocess.STDOUT,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This shell script's comments and all visible status/output messages are written in Chinese, which imposes a specific language on users. The policy requires flagging language or locale constraints when they are forced without user opt-in or a clearly documented justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The credential section says the saved login credential is 'not uploaded to any third-party server,' suggesting a narrowly local handling model. Elsewhere, the login flow explicitly relies on browser/App-based authorization URLs against Bilibili services, so the documentation's privacy/handling claim is broader and more absolute than the actual end-to-end behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.