Back to skill

Security audit

Bilibili 热门趋势分析

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated Bilibili trend-analysis purpose, but it automatically hands public ranking content to a spawned sub-agent and persists local history without clear permission scoping.

Review before installing if your OpenClaw sub-agents can read files, use tools, or access credentials. Prefer manual mode or a tool-restricted analysis agent, and set BILIBILI_WORKSPACE to a contained directory because the skill stores ranking data, creator fields, trend history, alerts, and reports locally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/common.py:139
Finding

Untrusted Bilibili Content Is Embedded Directly into a Sub-Agent Task

Content
View full analysis

Vulnerability Details

File Location: scripts/common.py:139-188 and scripts/common.py:194-203
Vulnerability Type: Indirect prompt injection
Risk Level: Medium

Vulnerable Code

python
def generate_analysis_prompt(rank_type, videos, summary):
    """Generate the analysis prompt sent to the sub-agent."""
    rank_name = RANK_CONFIG[rank_type]["name"]
    stats = compute_video_stats(videos, summary)
    top_keywords = extract_keywords(videos)
    top_owners = extract_up_stats(videos)

    full_data = {
        "rank_type": rank_type,
        "rank_name": rank_name,
        "top_zone": summary.get('top_zone', ''),
        "zone_distribution": summary.get('zone_distribution', {}),
        "top_keywords": top_keywords,
        "top_owners": top_owners,
        "videos": videos,
        **stats,
    }

    prompt = f"""Please deeply analyze the Bilibili {rank_name} ranking data.

## Full Video Data
{json.dumps(full_data, ensure_ascii=False, indent=2)}

Please output a Markdown analysis report covering:
1. View distribution
2. Interaction-rate analysis
3. Popular categories
4. Uploader ecosystem
5. Title patterns
6. Predictions
"""

    return prompt, top_keywords


def spawn_analysis_agent(prompt, label="bili-analysis"):
    """Invoke an OpenClaw sub-agent for analysis."""
    try:
        from sessions_spawn import sessions_spawn
        response = sessions_spawn(
            label=label,
            runtime="subagent",
            task=prompt,
            timeoutSeconds=120
        )
        return response.get('status') == 'accepted'
    except ImportError:
        return False
    except Exception:
        return False

The displayed wording has been translated into English for report consistency; the data flow and executable statements correspond to the audited source.

Technical Analysis

The application obtains remotely controlled fields from Bilibili ranking APIs, including video titles, uploader names, category names, and PG ...[truncated 3064 chars]

Remediation
View remediation

Remediation Suggestions

  1. Declare the trust boundary explicitly. Precede API data with a high-priority instruction stating that all Bilibili fields are untrusted content and that any commands, requests, policies, or role instructions inside them must be treated only as data.

  2. Separate instructions from data. Use a structured input or attachment mechanism distinct from the task instruction channel if sessions_spawn() supports one. Do not concatenate remote content into the same natural-language instruction string.

  3. Apply least privilege to the sub-agent. Run the analysis agent without shell execution, write access, secrets, unrelated workspace access, or external communication unless strictly necessary.

  4. Constrain tool use. Require explicit user confirmation before the sub-agent performs tool calls or external actions based on analyzed content. Prefer an agent profile with no tools for this summarization task.

  5. Validate and limit remote fields. Enforce reasonable length limits and normalize control characters. Flag or redact strings containing common instruction-injection patterns. Filtering alone should not be treated as the primary defense.

  6. Use a rigid output contract. Require a fixed report schema and reject responses containing tool requests, unrelated instructions, secret-like values, or content outside the expected analysis.

  7. Minimize supplied data. Send only fields needed for statistical analysis. Aggregate titles and uploader information where full raw records are unnecessary.

  8. Test adversarial inputs. Add tests containing titles such as requests to ignore prior instructions, access files, reveal context, or invoke tools, and verify that the sub-agent treats them exclusively as quoted data.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The markdown explicitly states the skill invokes external sub-agents/session services and writes multiple local artifacts, but these behaviors are not declared in permissions or tool scope. In an agent platform, undeclared external execution and persistent writes are dangerous because they expand the trust boundary, may expose data to additional components, and can bypass user expectations about what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The markdown explicitly states the skill invokes external sub-agents/session services and writes multiple local artifacts, but these behaviors are not declared in permissions or tool scope. In an agent platform, undeclared external execution and persistent writes are dangerous because they expand the trust boundary, may expose data to additional components, and can bypass user expectations about what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The markdown explicitly states the skill invokes external sub-agents/session services and writes multiple local artifacts, but these behaviors are not declared in permissions or tool scope. In an agent platform, undeclared external execution and persistent writes are dangerous because they expand the trust boundary, may expose data to additional components, and can bypass user expectations about what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/common.py (reported line 188)May include surrounding context.

python
请用中文输出,直接输出报告内容。"""

    return prompt, top_keywords


# ========== 子 Agent 调用 ==========

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares no explicit tool scope or permissions despite describing capabilities that require network access, file reads/writes, environment access, and sub-agent/session spawning. This is dangerous because reviewers and enforcement systems cannot accurately constrain execution, creating a gap between apparent and actual authority.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow describes automatically calling an external API and spawning a sub-agent to analyze the results, but it does not warn the user that data will be transmitted externally or passed to another agent context. Automatic multi-step execution increases risk because users may not realize when content is being fetched, relayed, or processed beyond the initial command, which weakens transparency and informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow explicitly states that fetched data, trend history, and generated analysis reports are automatically written to persistent workspace paths, but it provides no user warning, consent step, retention guidance, or data minimization controls. Even if the source API is public, the persisted artifacts may include metadata such as owner fields and accumulated historical analysis that outlives the session, creating an avoidable storage and disclosure risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language module description and output strings are Chinese-only, which imposes a specific language on users without offering a language choice or documenting a justified locale restriction. Under the language/locale policy, forcing a language without opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains user-facing natural-language strings entirely in Chinese, including the module description, command descriptions, status messages, and help text. Under the policy rule for language/locale, this is a violation because the skill imposes a specific language on users without any opt-in, alternative locale selection, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Tainted flow: 'TREND_FILE' from os.environ.get (line 28, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/common.py (reported line 73)May include surrounding context.

python
trend["records"] = trend["records"][-60:]

    with open(TREND_FILE, "w", encoding="utf-8") as f:
        json.dump(trend, f, ensure_ascii=False, indent=2)

Tainted flow: 'filepath' from os.environ.get (line 90, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/common.py (reported line 83)May include surrounding context.

python
timestamp = datetime.now().strftime("%Y-%m-%d-%H-%M-%S")
    filename = f"{rank_name}_{timestamp}.md"
    filepath = os.path.join(ANALYSIS_DIR, filename)
    with open(filepath, "w", encoding="utf-8") as f:
        f.write(content)
    return filepath

Tainted flow: 'filepath' from os.environ.get (line 90, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
78% confidence
Finding

save_summary_report constructs a filename from the prefix argument without sanitization, so if prefix is attacker-controlled it can include path traversal sequences or absolute paths and cause arbitrary file overwrite within the process's write permissions. Because the joined base directory is not canonicalized or checked after joining, this can escape ANALYSIS_DIR.

Content

Scanner excerpt · scripts/common.py (reported line 91)May include surrounding context.

python
def save_summary_report(prefix, content):
    """保存周/月总结报告"""
    filepath = os.path.join(ANALYSIS_DIR, f"{prefix}.md")
    with open(filepath, "w", encoding="utf-8") as f:
        f.write(content)
    return filepath

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function calls sessions_spawn(..., task=prompt, ...) to hand off analysis work to a sub-agent, and the prompt generated elsewhere includes complete ranking data. There is no confirmation prompt, visible disclosure, or warning near this transfer of data to another agent runtime.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/common.py (reported line 280)May include surrounding context.

python
def fetch_ranking_v2(rid):
    """抓取普通视频排行榜"""
    return api_get(
        "https://api.bilibili.com/x/web-interface/ranking/v2",
        params={"rid": rid, "type": "all", "pn": 1, "ps": 30},
    )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/common.py (reported line 288)May include surrounding context.

python
def fetch_ranking_v2(rid):
    """抓取普通视频排行榜"""
    return api_get(
        "https://api.bilibili.com/x/web-interface/ranking/v2",
        params={"rid": rid, "type": "all", "pn": 1, "ps": 30},
    )

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill notes local persistence but does not clearly warn that output files include creator-identifying fields such as owner/UP history and that these records are retained over time. This is risky because users may underestimate the privacy and compliance implications of storing identifiable creator metadata in trend, alert, and history artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The function persists generated alerts to alerts.json, modifying local user/workspace data, but there is no confirmation prompt, logging/print statement, or inline documentation disclosing that this file write occurs. For a code file, silent file writes are in scope when they lack any visible user disclosure and are not clearly surfaced here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This function writes discovered creator identifiers to up_history_<rank_type>.json without any user-facing notice, confirmation, or explanatory comment. Because it stores historical tracking data derived from analyzed content, the persistence should be disclosed somewhere visible to the user.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction 请用中文输出 forces a specific language in generated output. Under the policy, locale or language constraints should either be user-selectable or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.