T08 · Insecure Dependencies
- Location
SKILL.md:137- Finding
Unpinned Third-Party CLI Installation Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 137-144
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code
bash # Recommended: isolated installation with uv uv tool install bilibili-cli # Or: pipx pipx install bilibili-cli # Required for audio functionality uv tool install "bilibili-cli[audio]" pipx install "bilibili-cli[audio]"Technical Analysis
The installation commands resolve and install the latest available version of
bilibili-cliand its optional audio dependencies. They do not pin an audited version, enforce package hashes, use a lock file, or verify the resulting artifacts against a trusted release.The project itself contains only documentation and metadata; it does not include the CLI implementation. Consequently, the effective executable behavior is determined by mutable third-party registry content that was outside the reviewed artifact. If the package, one of its transitive dependencies, the package registry, or a maintainer account is compromised, following these instructions could install attacker-controlled code.
The exposure is especially significant because
SKILL.mdstates that the installed CLI can load credentials from~/.bilibili-cli/credential.jsonand extract cookies from Chrome, Firefox, Edge, and Brave. This sensitive access is declared functionality rather than evidence of malicious exfiltration, but it increases the potential consequences of dependency compromise.Attack Path
- An attacker compromises the
bilibili-clidistribution, a transitive dependency, or an authorized publisher account. - The attacker publishes a malicious release under the expected package name.
- A user or agent follows the unpinned
uv tool installorpipx installinstruction. - The package manager resolves the attacker-controlled release because no exact version or integrity hash is required.
- Malicious installation-time or runtime code execut ...[truncated 1084 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
bilibili-clito an exact version that has undergone security review, for example:bash uv tool install "bilibili-cli==X.Y.Z" pipx install "bilibili-cli==X.Y.Z" - Generate and enforce a hash-locked dependency manifest covering the package and all transitive dependencies.
- Explicitly identify and constrain the trusted package index rather than relying on ambient package-manager configuration.
- Verify release artifacts against signed tags, trusted provenance attestations, or published checksums.
- Review the source associated with the pinned release and confirm that the package registry artifact corresponds to that source.
- Run the CLI with least privilege and restrict access to unrelated browser profiles, cookie stores, credentials, and local files.
- Document where credentials are stored, which domains receive them, how browser cookies are obtained, and how users can disable automatic cookie extraction.
- Use automated dependency monitoring and require a new security review before updating the pinned version.
- Pin
