Back to skill

Security audit

Bilibili Subtitles

Security checks for vulnerabilities and agentic risk

Overview

This skill has a legitimate subtitle-extraction purpose, but it recommends using local browser cookies without enough consent and scoping safeguards.

Review before installing. Use the skill for Bilibili subtitle extraction only, and do not let an agent access browser cookies unless you explicitly approve that step. Prefer a Bilibili-scoped cookies.txt file, avoid printing or pasting cookie contents, and delete exported cookie files after use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
84% confidence
Finding

The matched string resembles info-stealer behavior because --cookies-from-browser chrome accesses browser-stored session cookies. In this specific skill the apparent purpose is functional access to bilibili subtitles rather than credential theft, but the mechanism is still security-sensitive: if an agent executes it automatically or exposes outputs, it could retrieve and mishandle live authenticated session data.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

��模型)

bash
# 简单去时间轴与标记(按需调整路径)
sed -e '/^WEBVTT/d' -e '/^NOTE/d' -e '/^[0-9][0-9]:/d' -e '/^$/d' -e 's/<[^>]*>//g' \
  "某文件.zh-Hans.vtt" | sed '/^$/d' > bilibili_subtitles_plain.txt

若出现 HTTP 412 / 无法下载网页

B 站可能对匿名请求限流。按顺序尝试:

  1. 用浏览器 Cookie(推荐)

    bash
    yt-dlp --cookies-from-browser chrome --list-subs "URL"
    

    可将 chrome 换成 safari、firefox(本机需已登录 bilibili.com)。

  2. 导出 Netscape 格式 cookies.txt,再:
    yt-dlp --cookies /path/to/cookies.txt ...

  3. 升级 yt-dlp 后重试。

详见 reference.md。

对 Agent 的提示

  • 先 --list-subs,无可用语言则明确告知用户「该 BV 无字幕轨」,不要假装已提取。
  • 提取成功后,优先读 .srt/.vtt 再总结;长文本可先落盘再分段阅读。
  • 勿在回复中粘贴完整 Cookie 或账号秘密

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · reference.md (reported line 15)May include surrounding context.

md
# B 站字幕 — 参考与排错

## 官方与工具

- [yt-dlp](https://github.com/yt-dlp/yt-dlp) — 提取器含 BiliBili。
- B 站接口与风控会变,**优先保持 yt-dlp 最新**。

## 常见错误

### HTTP 412 Precondition Failed

- **原因**:匿名或异常请求被拦;部分网络环境更易触发。
- **处理**:
  1. `yt-dlp -U` 或 `brew upgrade yt-dlp`
  2. `--cookies-from-browser chrome`(或本机常用浏览器)
  3. 使用从浏览器导出的 `cookies.txt` + `--cookies cookies.txt`
  4. 换网络/VPN 再试(若政策允许)

### 没有字幕语言列出

- 该稿件可能确实无字幕;换有「CC」或 UP 注明字幕的稿件测试。

### 只有繁体/英文

- 调整 `--sub-langs`,例如 `zh-Hant,zh-Hans,en`。

## v2 可能扩展(未实现)

- 无字幕时:下载音频 + 本地 Whisper / 已有 `openai-whisper` skill。
- 统一封装 CLI:`bili-subs BVxxx`(若单独开源可再挂 ClawHub)。

## 合规

- 仅处理

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/fetch-subs.sh (reported line 20)May include surrounding context.

sh
# B 站字幕 — 参考与排错

## 官方与工具

- [yt-dlp](https://github.com/yt-dlp/yt-dlp) — 提取器含 BiliBili。
- B 站接口与风控会变,**优先保持 yt-dlp 最新**。

## 常见错误

### HTTP 412 Precondition Failed

- **原因**:匿名或异常请求被拦;部分网络环境更易触发。
- **处理**:
  1. `yt-dlp -U` 或 `brew upgrade yt-dlp`
  2. `--cookies-from-browser chrome`(或本机常用浏览器)
  3. 使用从浏览器导出的 `cookies.txt` + `--cookies cookies.txt`
  4. 换网络/VPN 再试(若政策允许)

### 没有字幕语言列出

- 该稿件可能确实无字幕;换有「CC」或 UP 注明字幕的稿件测试。

### 只有繁体/英文

- 调整 `--sub-langs`,例如 `zh-Hant,zh-Hans,en`。

## v2 可能扩展(未实现)

- 无字幕时:下载音频 + 本地 Whisper / 已有 `openai-whisper` skill。
- 统一封装 CLI:`bili-subs BVxxx`(若单独开源可再挂 ClawHub)。

## 合规

- 仅处理

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

L03 将“做摘要”“根据视频内容回答问题时使用”作为触发条件,但未明确限定必须是 B 站视频且需以字幕提取为前提。这类表述容易与大量普通总结/问答请求重叠,导致技能被误触发。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs use of browser cookies and cookies.txt to access subtitle data when anonymous requests are blocked, but it does not clearly warn that these credentials can expose an authenticated bilibili session if mishandled. In an agent context, guidance to extract browser cookies is sensitive because it can normalize credential access and increase the chance of secret leakage to logs, model context, or downstream tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage and installation messages are written only in Chinese, which imposes a specific language on users without any opt-in or documented justification. This matches the policy category for language/locale constraints in natural-language content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.