T09 · Insecure Skill Coding Practices
- Location
scripts/bilibili_to_notion_workflow.py:14- Finding
Shell Command Injection and Notion Token Exposure in Workflow Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent Bilibili-to-Notion purpose, but it asks for risky local execution and Notion-write behavior without enough scoping or confirmation.
Review this skill before installing. Use it only in a constrained environment with a minimally scoped Notion integration, avoid passing sensitive Bilibili cookies or private local files, verify BBDown yourself before execution, and do not allow automatic Notion cleanup/archive actions without seeing the exact target pages first.
scripts/bilibili_to_notion_workflow.py:14Shell Command Injection and Notion Token Exposure in Workflow Execution
scripts/create_notion_notes_with_images.py:17Arbitrary Local File Disclosure Through Markdown Image Uploads
scripts/upload_file_to_notion.py:49Bearer Token and File Data Forwarded to an Unvalidated Upload URL
SKILL.md:362Unverified Third-Party Executable Download and Unpinned Python Dependency
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
secret_xxx)# 编辑 ~/.bashrc 或 ~/.zshrc
echo 'export NOTION_API_KEY="secret_xxx"' >> ~/.bashrc
source ~/.bashrc
# 可选:设置默认数据库ID
echo 'export NOTION_DATABASE_ID="your_database_id"' >> ~/.bashrc
source ~/.bashrc
... 菜单# 安装Python依赖
pip install requests
# 下载BBDown(B站下载器)
curl -L -o /tmp/BBDown.zip "https://github.com/nilaoda/BBDown/releases/download/1.6.3/BBDown_1.6.3_20240814_linux-x64.z
整体主用途与声明大体一致:都是从 B站视频获取字幕、处理后创建 Notion 学习笔记,且支持 URL/BV 输入。没有发现明显越权、无关资源访问或恶意/不相关功能。不过,声明中的关键卖点“带截图的 Notion 学习笔记/生成带截图标记”在这段代码里没有得到体现;代码既没有下载视频帧,也没有调用 ffmpeg 进行截图,也没有构造明显的截图时间点字段。FFmpeg 仅被检查可用性,但未实际参与流程。因此描述比代码展示的能力更强,存在一定描述—行为不一致。
声明描述的是一个端到端的B站视频转Notion学习笔记工具,包含输入BV号/URL、下载字幕、分析内容、生成带截图笔记等多个环节。但提供的代码块只实现了最后一步:把调用方传入的字幕片段整理成Notion页面内容并上传。其输入要求是现成的video_title、video_url和segments JSON,而不是BV号或B站链接解析结果;也没有任何与B站、字幕抓取、截图提取相关的逻辑。因此,声明与实际行为存在明显的能力夸大和范围不一致。
声明描述的是一个面向 B 站视频的端到端流程工具:输入 BV 号或 URL,自动获取字幕、分析内容、生成带截图的 Notion 学习笔记。而代码片段仅覆盖流程的后半段——将外部传入的字幕片段或 Markdown 内容写入 Notion,并支持图片嵌入/上传。代码需要调用者直接提供 --video-title、--video-url、--segments,说明字幕提取与视频处理并未在此实现。虽然“创建带截图的 Notion 学习笔记”这一部分与声明部分吻合,但声明中的关键前置能力(B站输入支持、CC字幕下载、字幕提取)缺失,导致描述与实际行为存在实质性不匹配。
声明描述的是一个端到端技能:输入 B 站视频后,下载字幕、分析内容、生成带截图标记的结构化学习笔记,并创建 Notion 笔记。但提供的代码块实际只实现了字幕下载相关功能:检测 BBDown、调用其 --sub-only 下载字幕、在本地查找 .srt/.ass 文件并返回结果。代码中没有任何字幕解析、内容总结、结构化笔记生成、截图抓取、时间戳截图标记、Notion API 调用或写入逻辑。因此,实际行为仅覆盖声明中的一个前置子步骤,无法支持其宣称的主要用途,属于明显的描述与行为不一致。
声明描述的是一个端到端的B站视频转Notion学习笔记工具,包括接受BV号/URL、自动下载CC字幕、智能分析内容并创建Notion笔记。实际代码块仅是一个字幕后处理脚本,输入为本地字幕文件路径(--input),只支持解析SRT格式文本,不包含任何B站访问、URL解析、字幕下载、视频处理、截图采集或Notion API调用。它生成的是Markdown字符串和JSON结果,而非Notion页面。虽然“生成带截图标记的结构化学习笔记”这一小部分与实际行为部分吻合,但整体主用途和关键能力明显少于声明,因此属于描述与行为不一致。
声明描述的是一个较完整的 B 站视频到 Notion 学习笔记流水线,包括接收 B 站标识、下载 CC 字幕、分析内容、生成结构化笔记,并包含截图标记。实际代码并不处理 B 站、字幕、内容分析或 Notion;它只读取本地 Markdown,识别其中的 Screenshot-[hh:mm:ss] 标记,并对本地视频文件调用 ffmpeg 生成截图,再将标记替换为 Markdown 图片链接。这不是对声明功能的简单子步骤说明,而是一个明显更窄且不同的实际能力,因此属于描述与行为不匹配。
The declared description presents an end-user skill for fetching Bilibili CC subtitles, processing them, and producing Notion learning notes. However, the supplied code chunk is only a test utility that checks whether /tmp/BBDown and ffmpeg are installed and then prints instructions for using another script. Its primary purpose is environment validation, not subtitle extraction, note generation, or Notion integration. This is a material description-behavior mismatch.
声明描述的核心功能是围绕 B 站视频字幕到 Notion 学习笔记的完整处理流程,但提供的代码与该流程基本无关。代码没有访问 B 站、没有处理视频链接、没有下载或解析字幕、没有生成任何笔记内容;它唯一的功能是把指定本地文件上传到 Notion 并返回上传 ID。虽然上传文件到 Notion 可能在更大系统中作为辅助步骤存在,但单独这段代码的主要目的与声明的主要目的明显不一致,且体现出一个未声明的独立能力,因此应判定为描述与行为不匹配。
The duplicate-page cleanup step archives pages in Notion, which is a destructive integrity-affecting action against user data, but the skill lacks a prominent warning and explicit approval flow for that behavior. If triggered incorrectly, it could archive legitimate user notes with matching titles, causing data loss or workflow disruption.
This is a concrete tool-parameter abuse issue because the workflow builds shell commands from multiple untrusted parameters and executes them with shell=True. The skill context makes this more dangerous, not less, because it is designed to ingest external video URLs and content and then chain several tools together, allowing one malicious input to propagate into command execution across the workflow.
print(f"\n🔍 {description}...")
try:
result = subprocess.run(
cmd, shell=True, capture_output=True, text=True, check=True
)
return json.loads(result.stdout)
This markdown file presents all instructions and user-facing guidance exclusively in Chinese, which effectively forces a specific language/locale on users. The policy allows locale constraints only when justified or when the user is offered a choice, neither of which is present here.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
pip install requests
# 下载BBDown(B站下载器)
curl -L -o /tmp/BBDown.zip "https://github.com/nilaoda/BBDown/releases/download/1.6.3/BBDown_1.6.3_20240814_linux-x64.zip"
unzip /tmp/BBDown.zip -d /tmp/
chmod +x /tmp/BBDown
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
pip install requests
# 下载BBDown(B站下载器)
curl -L -o /tmp/BBDown.zip "https://github.com/nilaoda/BBDown/releases/download/1.6.3/BBDown_1.6.3_20240814_linux-x64.zip"
unzip /tmp/BBDown.zip -d /tmp/
chmod +x /tmp/BBDown
L025 明确写道“不再使用固定的process_subtitles.py程序”,表示字幕处理已改由大模型负责。但 L146-L147 和 L214-L216 的分步执行与场景示例仍要求运行/调用 process_subtitles.py,文档内部对技能实际工作方式形成直接矛盾。
The document instructs users to download and execute a binary directly from an external release URL into /tmp without any integrity verification such as checksum or signature validation. If the release asset, transport path, or hosting account were compromised, users could run tampered code on their systems.
pip install requests
# 2. 下载BBDown
curl -L -o /tmp/BBDown.zip "https://github.com/nilaoda/BBDown/releases/download/1.6.3/BBDown_1.6.3_20240814_linux-x64.zip"
unzip /tmp/BBDown.zip -d /tmp/
chmod +x /tmp/BBDown
The instructions describe sending subtitle text, screenshots, and metadata to external services and creating or modifying Notion content without a clear disclosure of data transmission or workspace modification. This can cause users to upload sensitive video content, notes, or images to third parties unintentionally, especially because the skill is designed to automate the full workflow.
The documentation explicitly describes uploading local files to Notion and creating pages through Notion API/CLI, but it does not warn users that local content, screenshots, and derived notes will be transmitted to a third-party cloud service. This creates a real privacy and consent risk because users may assume the workflow is local-only or may not realize potentially sensitive material is being exported externally.
The one-click workflow is presented as a convenience feature while bundling several external and state-changing actions: downloading content, generating screenshots, uploading files, and creating remote Notion pages. Without a warning or confirmation boundary, users may trigger a chain of operations that affects remote accounts and discloses data unintentionally.
The README describes a workflow that uploads subtitles, screenshots, and derived notes to Notion, but it does not clearly warn users that video content may contain sensitive, copyrighted, or personal information that will be transmitted to a third-party service. In this skill’s context, the omission matters because the entire purpose of the skill is to extract and republish content externally, increasing the chance of unintended data disclosure.
The skill exposes broad capabilities—network access, shell execution, and file read/write—without any explicit tool scoping or allowlist. In an agent setting, this increases the blast radius of prompt injection or misuse because the runtime is permitted to perform powerful actions beyond the minimal set clearly constrained in metadata.
The skill is designed to upload local screenshots and create Notion pages, which modifies user-owned remote content, yet the user-facing description does not prominently warn that external data transfer and content creation will occur. This weakens informed consent and can lead to unintended disclosure of local files or unauthorized writes to a user's workspace.
L052-L128 requires a full seven-section learning-note structure including course overview, knowledge framework, detailed study content, concept summaries, reflections, formulas/methods, and FAQ. But the example at L282-L300 shows a much simpler segment-by-segment note format, and the later example at L221-L242 also presents a different simplified chapter layout. This is active documentation inconsistency about what the skill is supposed to generate.
The skill instructs downloading and executing a binary from an external release URL via curl/unzip/chmod without any integrity verification such as checksums or signature validation. This creates a supply-chain risk: if the release is tampered with, replaced, or intercepted in a compromised environment, the agent may run untrusted code.
pip install requests
# 下载BBDown(B站下载器)
curl -L -o /tmp/BBDown.zip "https://github.com/nilaoda/BBDown/releases/download/1.6.3/BBDown_1.6.3_20240814_linux-x64.zip"
unzip /tmp/BBDown.zip -d /tmp/
chmod +x /tmp/BBDown
At L507-L513, Step 2 says the model must '逐字保留' all subtitle text and forbids summarization or omission. Earlier requirements at L024-L049 and L130-L150 require understanding the course, extracting knowledge points, building a knowledge framework, and adding learner reflections, which is materially different from verbatim preservation. These instructions describe conflicting intents for the core behavior of the skill.
No suspicious patterns detected.