Back to skill

Security audit

Kuaishou Bilibili Publish

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it automates live social-media publishing with stealth browser spoofing and several under-scoped safety controls users should review carefully.

Install only if you are comfortable giving the skill control of a logged-in Chrome profile for live creator accounts. Use `--no-publish` first, verify the account and content in the browser, avoid `publish-all` until you have reviewed every destination, clear proxy environment variables unless intentionally needed, and do not run the debug scripts on sensitive accounts unless you can protect or delete the saved HTML output.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

other

Error
Location
scripts/kbs/cdp.py:104
Finding

Deliberate Concealment of Browser Automation and Fingerprint Spoofing

Content
View full analysis
{ const wd = Object.getOwnPropertyDescriptor(Navigator.prototype, 'webdriver'); if (wd && wd.get) { Object.defineProperty(Navigator.prototype, 'webdriver', { get: new Proxy(wd.get, { apply: () => false }), configurable: true, }); } if (!window.chrome) window.chrome = {}; if (!window.chrome.runtime) { window.chrome.runtime = { connect: () => {}, sendMessage: () => {} }; } Object.defineProperty(navigator, 'vendor', { get: () => 'Google Inc.', configurable: true, }); Object.defineProperty(navigator, 'languages', { get: () => ['zh-CN', 'zh', 'en-US', 'en'], configurable: true, }); const overrideWebGL = (proto) => { const original = proto.getParameter; proto.getParameter = function(p) { if (p === 37445) return '$$WEBGL_VENDOR$$'; if (p === 37446) return '$$WEBGL_RENDERER$$'; return original.call(this, p); }; }; overrideWebGL(WebGLRenderingContext.prototype); if (typeof WebGL2RenderingContext !== 'undefined') { overrideWebGL(WebGL2RenderingContext.prototype); } })(); """ S ...[truncated 2368 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/chrome_launcher.py:137
Finding

Authenticated Proxy Credentials May Be Exposed in Logs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/debug_cover.py:147
Finding

Authenticated Creator-Page HTML Is Persisted in Plaintext

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
pyproject.toml:8
Finding

Dependencies Are Installed Without Exact Version or Integrity Pinning

Content
View full analysis
=2.28.0", "websockets>=12.0", ] ``` From `scripts/requirements.txt:1-2`: ```text requests>=2.28.0 websockets>=12.0 ``` From `SKILL.md:252-258`: ```bash cd /Users/xiaohei/.openclaw/workspace/skills/kuaishou-bilibili-publish/scripts pip install -r requirements.txt # 或手动安装 pip install requests websockets ``` ### Technical Analysis Both dependency declarations specify only minimum versions. The alternative documented installation command supplies no version constraints at all. There is no lock file or package-integrity hash. As a result, installation may select any later release available from the configured package index. This weakens build reproducibility and prevents the installer from verifying that the exact reviewed artifacts are used. A future compromised release, compromised package index, or unexpected incompatible update would execute in the same Python process as the Skill. No evidence was found that the currently named `requests` or `websockets` packages are malicious. The vulnerability is the uncontrolled future dependency resolution and absence of artifact verification. ### Attack Path 1. A user follows the documented installation instructions. 2. `pip` queries the configured package index and resolves the newest versions satisfying the broad constraints. 3. A compromised, substituted, or otherwise unsafe future release is downloaded because no exact version or hash is required. 4. The package executes when imported by `scripts/chrome_launcher.py` or `scripts/kbs/cdp.py`. 5. The dependency inherits the Skill process's access to local files, environment variables, network connectivity, and the authenticated Chrome debugging session. ...[truncated 548 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (35)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

get_existing_page() attaches to any already-open non-blank browser page and enables DOM/Runtime control, allowing this skill to hijack an existing authenticated session without establishing its own isolated browsing context. In the context of social-media publishing automation, this is especially dangerous because it can inherit cookies, account state, and sensitive content from a user's live tab and act on their behalf.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill directs automated uploads to creator publishing pages and status checking, which are sensitive account actions that can modify user-controlled content and platform state. Because there is no warning, approval gate, rollback guidance, or account-safety notice, the automation could post unintended media, leak private content, or trigger policy/account consequences across multiple services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill interface and configuration are defined only in Chinese, including required field names such as 标题, 视频数据路径, 封面, and 关键词. There is no indication that users may choose another language or locale, which constitutes a language/locale policy issue under the stated rules.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation presents publish-all as a convenient one-click workflow that will sequentially publish to KuaiShou, Bilibili, and Douyin, but it does not place a clear, prominent warning immediately рядом that this action performs real submissions across all three accounts. In an automation skill that can operate on already logged-in browser sessions, this increases the risk of accidental mass posting, especially if the user expects a dry run or staged confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code implicitly honors KBS_PROXY, HTTPS_PROXY, or HTTP_PROXY and passes the proxy to Chrome without any user-facing confirmation. This can silently reroute all browser traffic, including authenticated sessions and scraped data, through an attacker-controlled or unexpected intermediary, increasing confidentiality and monitoring risks.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/chrome_launcher.py (reported line 143)May include surrounding context.

python
logger.info("使用代理: %s", proxy)

    logger.info("启动 Chrome: port=%d, headless=%s, profile=%s", port, headless, user_data_dir)
    process = subprocess.Popen(
        args,
        stdout=subprocess.DEVNULL,
        stderr=subprocess.DEVNULL,

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · scripts/chrome_launcher.py (reported line 172)May include surrounding context.

python
try:
        import requests

        resp = requests.get(f"http://127.0.0.1:{port}/json/version", timeout=2)
        if resp.status_code == 200:
            ws_url = resp.json().get("webSocketDebuggerUrl")
            if ws_url:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

After attempting graceful shutdown, the code enumerates any process bound to the debugging port and kills it, without verifying that the process is actually the Chrome instance started by this module. That can terminate unrelated local services on the same port, causing denial of service or disrupting other applications unexpectedly.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/chrome_launcher.py (reported line 264)May include surrounding context.

python
def _find_pids_by_port(port: int) -> list[int]:
    try:
        if sys.platform == "win32":
            result = subprocess.run(
                ["netstat", "-ano", "-p", "TCP"],
                capture_output=True,
                text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/chrome_launcher.py (reported line 279)May include surrounding context.

python
with contextlib.suppress(ValueError, IndexError):
                        pids.append(int(parts[-1]))
            return list(set(pids))
        result = subprocess.run(
            ["lsof", "-ti", f":{port}"],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/chrome_launcher.py (reported line 299)May include surrounding context.

python
def _kill_pid(pid: int) -> None:
    try:
        if sys.platform == "win32":
            subprocess.run(
                ["taskkill", "/PID", str(pid), "/F"],
                capture_output=True,
                timeout=5,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's docstring and all user-facing print statements are in Chinese, which imposes a specific language on users without any visible opt-in or alternative locale handling. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code deliberately alters browser fingerprint surfaces and injects stealth JavaScript to hide automation indicators such as navigator.webdriver, spoof Chrome metadata, and override WebGL and language signals. In an unknown-purpose automation skill, this materially increases the ability to evade bot detection and platform safeguards, which is risky because the surrounding docstring explicitly targets automated publishing to third-party platforms.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The stealth script forces navigator.languages to a Chinese-preferred list regardless of actual user settings or consent. While less severe than session hijacking, this is still deceptive fingerprint manipulation that can misrepresent the user environment, undermine transparency, and contribute to evasion of locale-based checks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The module docstring specifies operation in '抖音创作者中心' and all user-facing messages are written only in Chinese, which indicates a fixed language/locale expectation. There is no visible opt-in, language choice, or justification that this skill is intentionally limited to a Chinese-language environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code file contains user-facing natural-language strings and documentation entirely in Chinese, including the module description and configuration instructions. The skill does not offer any language or locale choice, which can violate language/locale policy when a specific language is imposed without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

User-facing comments and terminal output throughout the script are written entirely in Chinese, including operational instructions and status messages. This effectively forces a specific language for interaction without user opt-in, which is a natural-language policy concern under the stated rules.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The task scope is overly broad: it instructs generation of an automation script that uploads content to multiple publishing platforms without defining explicit trigger conditions, operator confirmation points, or platform/account boundaries. In an automation context tied to authenticated creator accounts, vague activation criteria can cause unintended posting actions, misuse of the wrong account, or execution against live production endpoints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file uses Chinese throughout for headings, instructions, warnings, and examples, but does not indicate that the skill is Chinese-only or provide an opt-in language choice. Under the language/locale policy, forcing a single language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file contains user-facing operational instructions exclusively in Chinese, and there is no note that the skill supports multiple languages or that Chinese is an intentional user-selected locale. Under the language/locale policy check, forcing a single language without opt-in can be a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The package description is written only in Chinese ("快手/B 站/抖音视频发布技能,基于 CDP 浏览器自动化"), which imposes a specific language for core user-facing metadata without offering any language choice or opt-in. Under the stated policy, language-only metadata can be a natural-language policy violation when it forces a locale without documented justification.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
87% confidence
Finding

The dependency specification allows any requests version at or above 2.28.0, so builds are not reproducible and may resolve to versions with known advisories depending on installer behavior, mirrors, or lockfile absence. While this file alone does not prove a vulnerable version is installed, the lack of upper bounds or pinning makes it impossible to verify that deployments avoid affected releases.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: websockets has 4 known advisory(ies) (CVE-2018-1000518 (websockets is vulnerable to denial of service by memory exhaustion); CVE-2021-33880 (Observable Timing Discrepancy in aaugustin websockets library); CVE-2018-1000518 (aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly C) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
85% confidence
Finding

The manifest permits any websockets version at or above 12.0 without a lockfile or exact pin, which prevents verification of the actual installed version across environments. This creates supply-chain uncertainty and may expose users to known vulnerable releases if dependency resolution or future transitive changes select an affected version.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language documentation strings are exclusively in Chinese, which imposes a language choice on users and maintainers without opt-in or explanation. Under the stated policy, forcing a specific language can be a locale/language policy violation unless choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code file presents its top-level docstring, usage instructions, and user-facing CLI help entirely in Chinese, with no indication that users can select another language or locale. That can violate language/locale policy when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.