Back to skill

Security audit

一键扒爆款

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its content-rewriting purpose, but it asks users for raw platform session cookies and has unclear download/dependency boundaries.

Install only in an isolated environment, avoid giving the agent raw browser cookies when possible, and prefer public links or manually pasted text. Review any optional XHS-Downloader source yourself before installing, and treat download/ASR fallback as local media processing even though the skill's top-level description says it does not download video.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:32
Finding

Unpinned Third-Party Dependencies and Unspecified External Package Source

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 32-42
Vulnerability Type: Supply-chain exposure through unpinned dependencies and an unspecified third-party component source
Risk Level: Medium

Vulnerable Code Snippet

bash
# Core dependencies (required)
pip install httpx playwright openai-whisper moviepy

# Playwright browser (required, run once)
playwright install chromium

# Optional dependencies
# Bilibili video downloads require this
# Xiaohongshu collection requires installing XHS-Downloader and providing a Cookie

Technical Analysis

The setup instructions install httpx, playwright, openai-whisper, and moviepy without exact version constraints, package hashes, or a reviewed lockfile. They also require a Chromium binary managed by Playwright. Consequently, the components installed at setup time can differ from those reviewed during the Skill audit.

The optional XHS-Downloader component is referenced by name without an exact version, integrity checksum, or canonical repository URL. This creates additional ambiguity about which implementation the user should trust and install. Installation of Python packages can execute package-controlled build or installation logic, while downloaded browser binaries are executable components.

This is a supply-chain weakness rather than evidence that the named dependencies are currently malicious.

Attack Path

  1. An attacker compromises a dependency release or distribution account, or publishes an impersonating component where users search for the unspecified XHS-Downloader.
  2. A user follows the Skill's setup instructions without a lockfile, hashes, or an authoritative source.
  3. The package manager or manual installation process retrieves the attacker-controlled release.
  4. Package installation, import, or later execution runs attacker-controlled code with the privileges of the user running the Skill.
  5. The malicious comp ...[truncated 771 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every Python dependency to an audited exact version in a requirements or lock file.
  2. Require package hashes, such as with pip install --require-hashes -r requirements.txt.
  3. Document the canonical HTTPS repository and exact reviewed commit or signed release for XHS-Downloader; do not instruct users to locate it by name alone.
  4. Record and verify checksums or signatures for externally downloaded executable components, including browser binaries where supported.
  5. Run installation and execution in a dedicated virtual environment or isolated container under a non-privileged account.
  6. Regularly scan locked dependencies for known vulnerabilities and review changes before updating versions.
  7. Keep user cookies outside the project directory, restrict file permissions, and avoid exposing them to optional dependencies unless strictly necessary.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to obtain and use users' authenticated platform cookies to access third-party content. Session cookies are bearer secrets; if collected, logged, mishandled, or reused, they can enable account hijacking or unauthorized access well beyond the immediate content extraction task.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Requesting a login session cookie for 小红书 content extraction directly solicits a high-value secret from the user. In this context the danger is elevated because the skill is designed to process third-party platform content, so users may be nudged into bypassing platform controls and exposing credentials for convenience.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The listed activation phrases include broad terms such as “内容改写”, “改写输出”, and “视频转文章”, which can match many ordinary writing or editing requests beyond this specific skill. The description does not provide boundaries or negative examples clarifying when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly markets itself as not downloading video, but later documents video download as an ASR fallback. This inconsistency is security-relevant because it undermines user consent and transparency: users may provide links believing only text extraction occurs, while the workflow may fetch and locally process media instead.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation states the skill does not download video, yet subsequent instructions describe downloading video for ASR fallback. In a skill that processes third-party platform content, this kind of contradiction increases the risk of undisclosed collection, copyright exposure, and accidental handling of more data than the user expects.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

md
# 1. 提取 BV 号并获取视频信息
bvid = "BV1xxXXxXXxx"  # 从 URL 中提取
resp = httpx.get(f'https://api.bilibili.com/x/web-interface/view?bvid={bvid}', headers=headers)
data = json.loads(resp.content.decode('utf-8'))['data']
title = data['title']
desc = data.get('desc', '')  # 视频简介(通常含核心观点)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

md
# 1. 提取 BV 号并获取视频信息
bvid = "BV1xxXXxXXxx"  # 从 URL 中提取
resp = httpx.get(f'https://api.bilibili.com/x/web-interface/view?bvid={bvid}', headers=headers)
data = json.loads(resp.content.decode('utf-8'))['data']
title = data['title']
desc = data.get('desc', '')  # 视频简介(通常含核心观点)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The ASR example explicitly sets language="zh", and the surrounding documentation presents the skill as producing Chinese-platform outputs by default without an opt-in language choice. This is a natural-language locale policy concern because it forces a specific language behavior rather than letting the user choose or clearly declaring a justified region-only constraint.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Normalizing operational guidance to provide a web_session cookie makes secret sharing part of the expected user journey. Even if intended for convenience, this trains users to hand over authentication material and increases the chance of credential leakage through prompts, logs, transcripts, or downstream tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest presents the skill entirely in Chinese (for example, the display name and description) and does not offer any language choice or note that the skill is intended only for Chinese-speaking users. Under the policy, a locale or language constraint should be explicit and justified or offered as an opt-in choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.