Back to skill

Security audit

Bilibili Helper

Security checks across malware telemetry and agentic risk

Overview

This Bilibili content-writing skill mostly describes text generation, but it asks for broad command, file, API, and credential-related capabilities that are not clearly needed or scoped.

Review this skill before installing. It may be usable as a prompt-only Bilibili writing helper, but do not grant shell, write, API credential, callback, or broad file access unless the publisher narrows the scope and explains exactly what commands, files, and services are used.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The documentation contains materially inconsistent statements about whether the skill performs API integration or requires credentials. In an agent setting, this can mislead operators into granting unnecessary secrets or enabling external-call pathways that are outside the skill's stated purpose, increasing the risk of over-privileged deployment and unsafe execution assumptions.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill first says no extra API key is required, then later instructs users to obtain and configure API keys or access credentials. This contradiction can cause users to inject secrets into the runtime unnecessarily, which is dangerous in a skill that also advertises exec/write capabilities and ambiguous external-service behavior.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill is presented as a Bilibili copywriting helper, but the body expands into broad file processing, API integration, command execution, and information retrieval capabilities unrelated to that narrow purpose. Scope inflation is dangerous because it normalizes powerful actions under an innocuous label, making reviewers and users more likely to approve tools or permissions that exceed the legitimate business need.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Generic command execution is not justified for a content-planning skill and materially increases the attack surface. If an agent or user follows this documentation, arbitrary shell commands could be run in contexts where only text generation should be necessary, enabling filesystem access, data exfiltration, or execution of hostile payloads.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.