Back to skill

Security audit

bilibili-danmaku-extractor ​

Security checks across malware telemetry and agentic risk

Overview

This skill does what it claims: it fetches Bilibili danmaku for a user-provided video and saves JSON and Markdown files locally.

Install only if you are comfortable contacting Bilibili's public APIs for the video you provide and storing the extracted danmaku locally. Use a dedicated output folder, avoid sharing exported files without considering platform rules and user-generated content privacy, and avoid running bulk extraction aggressively.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill exports full danmaku content and associated video metadata to local files but does not prominently warn users that this may include sensitive, personal, or copyrighted user-generated content. That omission increases the risk of unintended retention, redistribution, or mishandling of scraped content.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal