Back to skill

Security audit

Youtube and Bilibili Subtitle Extraction and Summary

Security checks for vulnerabilities and agentic risk

Overview

This video-summary skill does what it claims, but it can automatically install or update software and extract persistent browser cookies for Bilibili without clear upfront user control.

Review before installing. Use only if you are comfortable with the agent installing/updating yt-dlp and, for Bilibili links, accessing Chrome/keychain cookies and keeping a reusable cookie file in your home directory. Prefer a version that asks before installs or cookie access, uses a temporary or user-supplied cookie file with restrictive permissions, and avoids automatic self-updates.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:18
Finding

Unpinned Dependency Installation and Automatic Self-Update

Content
View full analysis
/dev/null; then echo "yt-dlp not found, installing..." pip install -q yt-dlp || pip3 install -q yt-dlp fi yt-dlp -U --quiet 2>/dev/null || true ``` ### Technical Analysis The Skill automatically installs the latest available `yt-dlp` package from the user's configured Python package index without pinning a reviewed version or validating a cryptographic hash. It then invokes `yt-dlp -U`, allowing the executable to update itself whenever the Skill runs. Consequently, the code executed by the Skill can change after the Skill has been reviewed. The effective source of the installed package also depends on environment-level package-index configuration, including `PIP_INDEX_URL`, `PIP_EXTRA_INDEX_URL`, and user-level pip configuration. A compromised package repository, malicious package release, or attacker-controlled package source could therefore cause arbitrary package code to run under the Agent's operating-system account. Suppressing update errors and continuing with `|| true` also prevents users from noticing that update behavior failed or behaved unexpectedly. ### Attack Path 1. An attacker compromises the configured package source, publishes a malicious upstream release, or causes the environment to use an attacker-controlled Python package index. 2. The Skill is invoked on a system where `yt-dlp` is missing, or its unconditional update command is executed against an existing installation. 3. `pip install yt-dlp` retrieves an unpinned package, or `yt-dlp -U` retrieves an unreviewed update. 4. Installation hooks or the resulting executable run attacker-controlled code. 5. The malicious code executes with the permissions of the Agent process and can access files, credentials, network resources, and other data available t ...[truncated 585 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:58
Finding

Automatic Chrome Cookie Extraction into a Persistent Plaintext File

Content
View full analysis
/dev/null | wc -l | tr -d ' ')" -gt 0 ]; then echo "Bilibili cookies older than 30 days, refreshing..." NEED_REFRESH=true fi if [ "$NEED_REFRESH" = true ]; then echo "Reading cookies from Chrome (one-time keychain prompt)..." yt-dlp --cookies-from-browser chrome --cookies "$BILI_COOKIES" \ --skip-download -i "https://www.bilibili.com/" 2>/dev/null fi COOKIE_ARGS="--cookies $BILI_COOKIES" ``` ### Technical Analysis The Skill automatically accesses Chrome's cookie storage whenever its persistent cookie file is missing or more than 30 days old. The extracted authentication material is written to `$HOME/bilibili_cookies.txt` by default and is subsequently supplied to network requests. The workflow does not first attempt unauthenticated access, request explicit informed approval before browser-cookie extraction, enforce restrictive permissions on the output file, verify that only the minimum Bilibili cookies were exported, or delete the cookie file after the operation. It also suppresses extraction errors, reducing visibility into unexpected browser or keychain access behavior. Authentication cookies are bearer credentials. Any process or local account able to read the resulting file may be able to reuse valid Bilibili sessions without knowing the user's password. The persistent location also extends exposure beyond the lifetime of the subtitle-processing operation. ### Attack Path 1. A Bilibili URL invokes the Skill when `$HOME/bilibili_cookies.txt` is absent or considered stale. 2. The Skill invokes `yt-dlp --cookies-from-browser chrome`, potentially prompting ...[truncated 1167 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (6)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger logic is overly broad and says to invoke the skill immediately for any matching video URL while forbidding safer alternatives like fetch-content. That reduces user choice and can cause the skill to run automatically in contexts where the user did not consent to software installation, cookie access, or file writes.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The visible skill description focuses on subtitle extraction and summarization but does not clearly warn that execution may install software, access browser cookies/keychain, contact external services, and write raw transcripts plus summaries to disk. This is a consent and transparency failure that materially increases risk because users may trigger the skill without understanding the privileged actions it performs.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
91% confidence
Finding

The 'always use a cookies file' and 'refresh from Chrome' workflow matches information-stealer patterns because it programmatically harvests session cookies from the browser and persists them for reuse. Even if the stated goal is subtitle access, this behavior is security-sensitive and could be repurposed to access the user's authenticated account sessions.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

the appropriate strategy.

bash
URL="<user-provided URL>"
TMPDIR=$(mktemp -d)
SUB_FILE=""
SUBTITLE_LANG=""

# Detect platform
if echo "$URL" | grep -qE '(bilibili\.com|b23\.tv)'; then
  PLATFORM="bilibili"
  SITE_NAME="Bilibili"
  SITE_DOMAIN="bilibili.com"
else
  PLATFORM="youtube"
  SITE_NAME="YouTube"
  SITE_DOMAIN="youtube.com"
fi

Bilibili branch

Bilibili subtitles require login cookies. Always use a cookies file — refresh from Chrome if missing or stale (>30 days):

bash
if [ "$PLATFORM" = "bilibili" ]; then
  BILI_COOKIES="${BILIBILI_COOKIES_FILE:-$HOME/bilibili_cookies.txt}"

  NEED_REFRESH=false
  if [ ! -f "$BILI_COOKIES" ]; then
    NEED_REFRESH=true
  elif [ "$(find "$BILI_COOKIES" -mtime +30 2>/dev/null | wc -l | tr -d ' ')" -gt 0 ]; then
    echo "Bilibili cookies older than 30 days, refreshing..."
    NEED_REFRESH=true
  fi

  if [ "$NEED_REFRESH" = true ]; then
    echo "Reading cookies from Chrome (one-time keychain prompt)..."
    yt-dlp --cookies-fr

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

The command uses --cookies-from-browser chrome and explicitly mentions a keychain prompt, meaning the skill accesses protected browser credentials to extract authentication material. Accessing secrets from the browser/keychain is a high-risk privileged action and is especially dangerous in a skill that can be auto-invoked from a URL match.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
fi

  if [ "$NEED_REFRESH" = true ]; then
    echo "Reading cookies from Chrome (one-time keychain prompt)..."
    yt-dlp --cookies-from-browser chrome --cookies "$BILI_COOKIES" \
      --skip-download -i "https://www.bilibili.com/" 2>/dev/null
  fi

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs extracting authenticated Bilibili cookies from the user's Chrome profile and storing them in a reusable file under the home directory. Browser cookies are bearer tokens; reading them from Chrome/keychain and persisting them to disk expands the attack surface, can bypass normal user awareness, and may expose account access if the file is reused, copied, or read by other tools.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill performs runtime installation and self-update of yt-dlp via pip without explicit user confirmation or environment isolation. Pulling and executing packages at runtime increases supply-chain risk, changes the host unexpectedly, and can execute unreviewed code in the user's environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.