Back to skill

Security audit

B站视频分析

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches public Bilibili video metadata from Bilibili's API and asks the agent to summarize it, with no evidence of credential access, persistence, destructive behavior, or hidden unrelated actions.

Install only if you are comfortable with the BV video ID from your request being sent to Bilibili's public API. Expect metadata-based summaries rather than full transcript or video-content summaries, and note that the script filename typo may need correction for the skill to run reliably.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared behavior says the skill summarizes Bilibili videos, but the implementation reportedly only fetches structured/raw metadata and depends on external network access not disclosed in the description. This mismatch is dangerous because users and reviewers may approve the skill under false assumptions, while the hidden external-access behavior expands data flow and trust risks.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes an internal script that performs network access, but the manifest does not declare any tool scope, permissions, or allowed-tools boundaries. This weakens reviewability and enforcement, making it easier for a skill to access external resources without transparent user or platform oversight.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The returned error messages and comments are in Chinese only, such as "未找到 BV 号" and "API 返回异常", with no indication that the user can choose another language. This can violate language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 5)May include surrounding context.

md
// 2. 调 B站官方 API
  const res = await fetch(
    `https://api.bilibili.com/x/web-interface/view?bvid=${bvid}`,
    {
      headers: {
        "User-Agent": "Mozilla/5.0"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fecth.js (reported line 12)May include surrounding context.

js
// 2. 调 B站官方 API
  const res = await fetch(
    `https://api.bilibili.com/x/web-interface/view?bvid=${bvid}`,
    {
      headers: {
        "User-Agent": "Mozilla/5.0"

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code performs an outbound HTTP request to Bilibili using a BV identifier extracted from the user's input, but there is no confirmation prompt, user-facing log, or inline disclosure indicating that part of the user's input will be sent to an external service. For code files, outbound transmission of user data should have some visible warning unless the disclosure is otherwise documented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.