Back to skill

Security audit

Yq Bilibili Skill

Security checks for vulnerabilities and agentic risk

Overview

This Bilibili skill is coherent, but it should be reviewed because it can reuse local browser/login sessions and perform account-changing actions without clear consent gates.

Install only if you are comfortable with an agent using your Bilibili login state, including saved credentials or browser cookies. Prefer QR login or a dedicated browser/profile if possible, avoid ambiguous requests that could trigger likes/coins/triples/unfollows, and require explicit confirmation before any authenticated or account-changing command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:137
Finding

Unpinned Third-Party CLI Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 137-144
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
# Recommended: isolated installation with uv
uv tool install bilibili-cli

# Or: pipx
pipx install bilibili-cli

# Required for audio functionality
uv tool install "bilibili-cli[audio]"
pipx install "bilibili-cli[audio]"

Technical Analysis

The installation commands resolve and install the latest available version of bilibili-cli and its optional audio dependencies. They do not pin an audited version, enforce package hashes, use a lock file, or verify the resulting artifacts against a trusted release.

The project itself contains only documentation and metadata; it does not include the CLI implementation. Consequently, the effective executable behavior is determined by mutable third-party registry content that was outside the reviewed artifact. If the package, one of its transitive dependencies, the package registry, or a maintainer account is compromised, following these instructions could install attacker-controlled code.

The exposure is especially significant because SKILL.md states that the installed CLI can load credentials from ~/.bilibili-cli/credential.json and extract cookies from Chrome, Firefox, Edge, and Brave. This sensitive access is declared functionality rather than evidence of malicious exfiltration, but it increases the potential consequences of dependency compromise.

Attack Path

  1. An attacker compromises the bilibili-cli distribution, a transitive dependency, or an authorized publisher account.
  2. The attacker publishes a malicious release under the expected package name.
  3. A user or agent follows the unpinned uv tool install or pipx install instruction.
  4. The package manager resolves the attacker-controlled release because no exact version or integrity hash is required.
  5. Malicious installation-time or runtime code execut ...[truncated 1084 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin bilibili-cli to an exact version that has undergone security review, for example:
    bash
    uv tool install "bilibili-cli==X.Y.Z"
    pipx install "bilibili-cli==X.Y.Z"
    
  2. Generate and enforce a hash-locked dependency manifest covering the package and all transitive dependencies.
  3. Explicitly identify and constrain the trusted package index rather than relying on ambient package-manager configuration.
  4. Verify release artifacts against signed tags, trusted provenance attestations, or published checksums.
  5. Review the source associated with the pinned release and confirm that the package registry artifact corresponds to that source.
  6. Run the CLI with least privilege and restrict access to unrelated browser profiles, cookie stores, credentials, and local files.
  7. Document where credentials are stored, which domains receive them, how browser cookies are obtained, and how users can disable automatic cookie extraction.
  8. Use automated dependency monitoring and require a new security review before updating the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Referencing loading credentials from ~/.bilibili-cli/credential.json indicates the skill/tool can access persisted authentication tokens from local storage. In this skill context, access to stored credentials increases the chance that an agent can perform authenticated actions without fresh user intent, especially when combined with write-capable commands.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
## 认证说明

bilibili-cli采用3层认证策略:
1. **已保存凭证** - 从 `~/.bilibili-cli/credential.json` 加载
2. **浏览器Cookies** - 自动从Chrome/Firefox/Edge/Brave提取
3. **扫码登录** - `bili login` 在终端显示二维码

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
88% confidence
Finding

Automatic extraction of browser cookies from Chrome, Firefox, Edge, or Brave matches credential-harvesting behavior because it accesses sensitive browser-stored session data. Although presented as a convenience feature rather than overt malware, in an agent-executed environment it is dangerous because it can silently inherit the user's authenticated sessions and enable account access or actions without transparent consent.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

| |------|------| | --page N | 分页号 | | --max N | 最大结果数 | | --offset N | 翻页游标 | | -o PATH | 输出目录 | | --day N | 排行榜天数(3或7) |

环境变量

bash
# 覆盖默认输出模式
OUTPUT=yaml|json|rich|auto

认证说明

bilibili-cli采用3层认证策略:

  1. 已保存凭证 - 从 ~/.bilibili-cli/credential.json 加载
  2. 浏览器Cookies - 自动从Chrome/Firefox/Edge/Brave提取
  3. 扫码登录 - bili login 在终端显示二维码

权限说明:

  • 大部分命令无需登录
  • 字幕/收藏/关注/稍后观看/历史/动态需要登录
  • 点赞/投币/三连/取关/发布动态需要写入权限

常见问题排查

问题解决方案
需要登录运行 bili login 扫码,或确保浏览器已登录bilibili
HTTP 412 限流等待后重试,或减少 --max 数量
无法提取BV号检查BV格式,必须是BV+10位字符
NetworkError检查网络

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly documents write-capable actions such as like, coin, triple, and unfollow, but it does not clearly warn that these commands modify the user's Bilibili account and can trigger irreversible or user-visible actions. In an agent context, this is risky because the assistant may invoke account-affecting operations on ambiguous prompts or without explicit confirmation, causing unauthorized social/account changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The authentication section states that browser cookies may be automatically extracted from installed browsers without any privacy or consent warning. In an agent skill, this can normalize silent access to sensitive session material and may lead to unintended use of authenticated browser state, exposing the user's account context beyond what they explicitly approved.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest advertises a wide range of data-access and account-affecting capabilities, including login, history/favorites access, follow/unfollow, and like/coin/triple actions, but does not state when those actions may be invoked, what requires explicit user consent, or what boundaries apply. In an agent setting, this ambiguity can lead to overbroad invocation, unintended access to private account data, or execution of state-changing actions beyond the user's clear intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description includes interactive operations that can affect a user's Bilibili account, such as liking, coin donations, three-in-one interactions, following/unfollowing, and access to favorites/history, but it provides no warning that these actions are account-sensitive. Without an explicit warning, users or upstream agents may treat the skill as informational only and accidentally trigger irreversible or privacy-impacting operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.