T09 · Insecure Skill Coding Practices
- Location
main.py:142- Finding
Untrusted Bilibili Content Is Exported as Active Markdown
- Content
View full analysis
**BV号**: `{video_info['bvid']}` ") lines.append(f"> **UP主**: {video_info['owner']} ") lines.append(f"> **弹幕总数**: {len(danmakus)} 条 ") lines.append(f"> **导出时间**: {datetime.now().strftime('%Y-%m-%d %H:%M:%S')} ") lines.append("") lines.append("---") lines.append("") lines.append(f"**视频简介**: {video_info['desc'][:200]}{'...' if len(video_info['desc']) > 200 else ''}") lines.append("") lines.append("---") lines.append("") lines.append(f"## 全部弹幕 (共 {len(danmakus)} 条)") lines.append("") for i, d in enumerate(danmakus, 1): time_str = format_time(d['time']) text = d['text'].replace('\n', ' ') lines.append(f"`[{time_str}]` {text}") ``` ### Technical Analysis The video title, description, owner name, and danmaku text originate from an external service and can contain uploader- or user-controlled content. The exporter places these values directly into a Markdown document without escaping Markdown metacharacters or removing raw HTML. Replacing newline characters in danmaku does not neutralize inline Markdown, links, images, or HTML. Depending on the Markdown renderer, crafted content can therefore create deceptive links, external image requests, forged document sections, or active HTML elements. If the generated Markdown is subsequently supplied to an AI agent, attacker-authored text could also be interpreted as instructions. That represents a potential indirect prompt-injection path in downstream workflows, although this script itself does not execute such instructions. ### Attack Path 1. An attacker publishes a Bilibili video with a crafted title or description, or submits crafted danmaku to a target video. 2. A user invokes the Skill to export that video's content ...[truncated 970 chars]- Remediation
View remediation
