Back to skill

Security audit

HotBee B站数据采集

Security checks for vulnerabilities and agentic risk

Overview

The skill has a clear Bilibili collection purpose, but it tells users to run mutable remote GitHub code that can access a local API key and sends that key as a URL query parameter to a less clearly documented domain.

Review before installing. Only use this skill with a restricted environment, a low-privilege and easily rotatable HotBee API key, and minimal filesystem/environment access. Prefer a version that vendors or immutably pins the CLI implementation and sends credentials in headers or request bodies rather than URL query strings.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:13
Finding

Runtime Retrieval and Execution of Externally Hosted Code

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 13
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
npx -y github:shanye1402-hash/hotbee-social-data-skills#v1.1.0 call bilibili --url "https://www.bilibili.com/video/BV..."

Technical Analysis

The skill instructs the agent to use npx -y to retrieve and execute a package directly from an external GitHub repository. The package implementation is not included in the audited project, so its effective behavior cannot be verified from the local files.

The reference selects a repository tag rather than a content-integrity-verified artifact or immutable commit hash. If the external repository, maintainer account, or referenced release becomes compromised, the downloaded package could be changed after this skill has been reviewed. The -y option suppresses the normal installation confirmation, allowing the remote package to execute during routine skill invocation.

The executed process inherits the permissions and accessible environment of the agent process. In particular, the skill expects HOTBEE_API_KEY to be present in the environment, so remotely supplied code may be able to read that credential in addition to accessing files and network resources available to the current user.

Attack Path

  1. An attacker compromises the external GitHub repository, its maintainer account, or the referenced release/tag.
  2. The attacker causes the referenced package to contain malicious installation or runtime code.
  3. A user invokes the Bilibili collection skill.
  4. The documented npx -y command downloads the externally controlled package without interactive confirmation.
  5. The package executes with the current agent user's permissions.
  6. The malicious payload reads accessible environment variables, including HOTBEE_API_KEY, and may access local files or make arbitrary outbound requests within the process's security boundaries.

I

...[truncated 640 chars]

Remediation
View remediation

Remediation Suggestions

  1. Avoid executing code directly from a GitHub repository at runtime.
  2. Vendor the required implementation into the skill so it can be reviewed together with the project.
  3. If an external package is unavoidable, publish it through a trusted registry and pin an exact version using a lockfile with integrity hashes.
  4. Pin external source code to an immutable commit hash rather than a movable tag, and verify a trusted checksum or signature before execution.
  5. Remove automatic confirmation through npx -y where feasible, and require explicit approval before installing or running externally retrieved code.
  6. Execute the package in a restricted environment with minimal filesystem access, a limited environment-variable allowlist, and tightly controlled outbound network access.
  7. Ensure the child process receives only HOTBEE_API_KEY when required rather than inheriting the complete parent environment.

T09 · Insecure Skill Coding Practices

Warning
Location
references/api.md:5
Finding

API Credential Transmitted in URL Query Parameters

Content
View full analysis

Vulnerability Details

File Location: references/api.md, lines 5-7
Vulnerability Type: Sensitive credential exposure through URL query parameters
Risk Level: Medium

Vulnerable Code

markdown
- Endpoint: `POST https://www.smsz.xyz/prod-api/tool/bilibili/bilibili_video_data`
- Parameters: `key`, `video_url`
- Transport in the package CLI: query parameters with POST.

Technical Analysis

The documented CLI transports the API credential in the URL query string, even though the request uses the POST method. Using POST does not protect query parameters: the full URL can still be recorded by HTTP servers, reverse proxies, gateways, observability platforms, debugging tools, and error-reporting systems.

The credential is therefore exposed to every infrastructure component that processes or stores request URLs. Instructions elsewhere in the skill to redact signed query parameters from errors are a useful defensive measure, but they cannot guarantee that remote servers, proxies, or third-party logging systems will perform equivalent redaction.

The documented endpoint uses the smsz.xyz domain, while the advertised capability directory uses hotbee.cn. The audited files do not establish the ownership relationship between these domains. This does not prove malicious behavior, but it makes the credential trust boundary insufficiently clear and should be verified before transmitting an API key.

Attack Path

  1. The skill reads HOTBEE_API_KEY from the local environment.
  2. The external CLI constructs a POST request whose URL query string contains the key parameter.
  3. The request passes through the destination server and potentially through proxies, gateways, monitoring systems, or debugging infrastructure.
  4. One or more components record the complete request URL.
  5. An attacker or unauthorized operator with access to those logs extracts the API key.
  6. The exposed key is reused against services that accept it until it is revoked or ...[truncated 581 chars]
Remediation
View remediation

Remediation Suggestions

  1. Send the API key in an HTTP Authorization header, such as a bearer token, rather than in the URL.
  2. If the service cannot support an authorization header, place the credential in the POST request body and configure all relevant systems to redact that field.
  3. Never include credentials in URLs, command output, exception text, telemetry, or debug logs.
  4. Verify and document the ownership and trust relationship between smsz.xyz and the advertised HotBee service before sending credentials.
  5. Restrict the API key to the minimum required endpoint and permissions, and apply quota and rate limits.
  6. Use short-lived or readily rotatable credentials where supported.
  7. Rotate the existing key if it may already have been used through query-string transport.
  8. Add automated tests that confirm logs and errors never contain the API key or complete signed query strings.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill instructs execution of a remote package directly from a GitHub repository via npx -y github:...#v1.1.0, which is not a cryptographically pinned, immutable dependency. A tag or referenced source can be changed, the repository can be compromised, or its transitive dependencies can shift, resulting in arbitrary code execution on the host when the skill is used.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The example command invokes code directly from a GitHub repository via npx -y github:...#v1.1.0, which relies on a mutable remote source rather than a strongly pinned, integrity-verified package artifact. Even with a tag present, if the referenced repository, tag, or dependency chain is altered or compromised, users may execute unintended code when following the documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.