Back to skill

Security audit

Bilibili Toolkit

Security checks across malware telemetry and agentic risk

Overview

This Bilibili operations skill is coherent with its stated purpose, but it asks for full browser session cookies and supports account-changing actions, so users should review it carefully before installing.

Install only if you are comfortable giving the agent Bilibili session-level access. Do not paste real cookies into chat logs or source files, avoid persistent storage unless necessary, clear stored credentials after use, and require confirmation before any upload, edit, draft, schedule, or bulk download action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill instructs users to extract and use full browser session cookies such as SESSDATA and bili_jct, which are highly sensitive account credentials equivalent to active session access. Combined with documented persistence support, this materially increases the risk of account takeover, unauthorized posting/editing, and long-lived credential exposure if the values are pasted into chats, logs, or local files.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill documents write-capable and file-writing operations including upload, edit, schedule, and batch download without a prominent upfront warning that they can modify account content or create local artifacts. In an agent context, insufficient disclosure raises the risk of unintended publication, unwanted edits, and unreviewed writes to disk, especially when paired with exec capability.

Ssd 3

High
Confidence
99% confidence
Finding
The skill explicitly tells users to retrieve full browser session cookies from developer tools and reuse them for account access. This encourages disclosure of live authentication material in plain language, making accidental leakage into prompts, terminal history, screenshots, logs, and version control much more likely; anyone obtaining these values may be able to act as the user on Bilibili.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.