Back to skill

Security audit

Bilibili 视频监控

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a Bilibili reporting workflow, but it needs review because its push behavior is under-specified and one helper script builds shell commands from configurable inputs.

Review this before installing. Use it only in a controlled local environment, with a low-risk Bilibili account cookie, a trusted WeChat sender script, and trusted values for WECHAT_SEND_PY and the contact argument. Do not rely on the advertised Agent Mail/two-stage confirmation because it is not present in the shipped scripts; add confirmation and replace shell-string execSync with argument-based process execution before using it for unattended automation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
bilibili_wechat_push.js:76
Finding

Shell Command Injection Through Contact Name and Configurable Script Path

Content
View full analysis
attacker-command " ``` The precise operators depend on the host shell. The resulting command would be interpreted as multiple shell operations rather than as a single contact argument. The environment-controlled script path presents an additional injection surface ...[truncated 1256 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
bibili_weekly.js:192
Finding

Stale Report Can Be Sent When the Current Run Produces No Videos

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding indicates the push workflow is misrepresented: the second channel is absent, confirmation is absent, and the actual mechanism depends on a local Python path/environment variable rather than the declared skill interface. Such hidden implementation details can bypass user expectations and security review, potentially sending content through undeclared automation paths or using broader host capabilities than intended.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This finding indicates the push workflow is misrepresented: the second channel is absent, confirmation is absent, and the actual mechanism depends on a local Python path/environment variable rather than the declared skill interface. Such hidden implementation details can bypass user expectations and security review, potentially sending content through undeclared automation paths or using broader host capabilities than intended.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
配置)。触发场景:用户请求"查看B站播报"、"运行播报脚本"、"生成本周投稿报告"、或类似表达。也适用于自动化定时任务执行完毕后读取报告内容并推送。脚本路径:`bibili_weekly.js`;报告文件路径:`./bilibili_report.txt`;Cookie 文件路径:`./bilibili_cookie.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
配置)。触发场景:用户请求"查看B站播报"、"运行播报脚本"、"生成本周投稿报告"、或类似表达。也适用于自动化定时任务执行完毕后读取报告内容并推送。脚本路径:`bibili_weekly.js`;报告文件路径:`./bilibili_report.txt`;Cookie 文件路径:`./bilibili_cookie.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
配置)。触发场景:用户请求"查看B站播报"、"运行播报脚本"、"生成本周投稿报告"、或类似表达。也适用于自动化定时任务执行完毕后读取报告内容并推送。脚本路径:`bibili_weekly.js`;报告文件路径:`./bilibili_report.txt`;Cookie 文件路径:`./bilibili_cookie.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
71% confidence
Finding

The skill declares operational behavior involving local files, Node.js execution, cookie handling, and likely environment-dependent integrations, but does not define an explicit tool/permission scope. That gap can cause the agent runtime to overgrant capabilities or leave reviewers unable to verify what the skill is allowed to access, increasing the chance of unintended secret exposure or unsafe execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Ambiguous catch-all trigger wording can cause the skill to activate on loosely related user requests or automated contexts, which is risky for a skill that runs scripts, reads reports, and may push messages externally. Overbroad invocation increases the chance of unintended execution and accidental disclosure of report contents or use of stored cookies/integrations without sufficiently clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

One or more listed trigger phrases are broad enough to overlap with normal conversation, making accidental invocation plausible. In a skill that processes local files and may initiate outbound communications, unintended triggering can expose private report data or activate external automation without a deliberate request.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This request sends the user's Bilibili authentication cookie to an external service to validate login state and obtain WBI signing material. Although this is expected for the feature, it is still a true data-transmission risk because the skill handles account credentials and performs authenticated outbound requests.

Content

Scanner excerpt · bibili_weekly.js (reported line 82)May include surrounding context.

js
}

async function wbiSign(params) {
    const nav = await httpGet('https://api.bilibili.com/x/web-interface/nav');
    const imgUrl = nav.data?.wbi_img?.img_url || '';
    const subUrl = nav.data?.wbi_img?.sub_url || '';
    const imgKey = imgUrl.match(/\/([^\/]+)\.png$/)?.[1] || '';

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The script performs an authenticated outbound request to fetch the monitored account's video list, sending the local Bilibili cookie along with the request. In a skill advertised mainly as reading and pushing a local report, this hidden external collection increases privacy and credential-handling risk.

Content

Scanner excerpt · bibili_weekly.js (reported line 109)May include surrounding context.

js
async function fetchVideoList() {
    const params = {mid: UID, ps: 30, pn: 1, order: 'pubdate', jsonp: 'jsonp'};
    const signedQuery = await wbiSign(params);
    return await httpGet(`https://api.bilibili.com/x/space/wbi/arc/search?${signedQuery}`);
}

async function fetchTopComments(aid) {

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The skill fetches top comments from Bilibili via outbound authenticated requests, again transmitting the local cookie. This expands the collected data set to third-party user content and creates a broader privacy surface than a simple local report reader would suggest.

Content

Scanner excerpt · bibili_weekly.js (reported line 113)May include surrounding context.

js
}

async function fetchTopComments(aid) {
    return await httpGet(`https://api.bilibili.com/x/v2/reply?type=1&oid=${aid}&ps=5&pn=1&sort=2`);
}

// ============================================================

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata says it should read an already generated report and push it, but the script actually performs authenticated collection from Bilibili using a local cookie and generates the report itself. This scope expansion is security-relevant because running the skill causes network activity and account-authenticated access that a user may not expect from the manifest description.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The main flow initiates authenticated communication with Bilibili to verify account login status before continuing. In the skill context, this makes the behavior more dangerous because the advertised purpose is report handling/pushing, yet execution also consumes local credentials and contacts an external platform automatically.

Content

Scanner excerpt · bibili_weekly.js (reported line 176)May include surrounding context.

js
console.log('[B站播报] 开始获取数据...\n');

    // 验证登录
    const nav = await httpGet('https://api.bilibili.com/x/web-interface/nav');
    if (!nav.data?.isLogin) {
        console.error('❌ Cookie 失效,请重新获取!');
        process.exit(1);

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a skill that reads the generated report, organizes it into text, and pushes it through two channels: WeChat and Agent Mail with a two-step confirmation. This file only runs the Bilibili script, verifies/reads the report file, and invokes a WeChat sender; there is no email delivery path, no confirmation flow, and no transformation of the report content beyond passing the file through.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill documentation is written as a Chinese-only experience and presents the skill as a fixed Chinese-language workflow, with no indication that users can choose another language or that the locale restriction is intentional and justified. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes report and cookie paths using './...' semantics, which conventionally means the current working directory. The code anchors file access to path.join(__dirname, ...), making the effective location the script's directory instead; this is a behavioral mismatch that can change which files are used in automation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The manifest frames delivery around a configured default UID/contact and automated report push scenarios. This code allows any operator-provided contact name via process arguments, expanding the delivery target beyond the stated configured recipient model and enabling ad hoc redirection of report contents.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
bilibili_wechat_push.js:30