Back to skill

Security audit

b站视频自动生成高质量图文笔记自动截图并上传至Notion笔记

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent Bilibili-to-Notion purpose, but it asks for risky local execution and Notion-write behavior without enough scoping or confirmation.

Review this skill before installing. Use it only in a constrained environment with a minimally scoped Notion integration, avoid passing sensitive Bilibili cookies or private local files, verify BBDown yourself before execution, and do not allow automatic Notion cleanup/archive actions without seeing the exact target pages first.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/bilibili_to_notion_workflow.py:14
Finding

Shell Command Injection and Notion Token Exposure in Workflow Execution

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/create_notion_notes_with_images.py:17
Finding

Arbitrary Local File Disclosure Through Markdown Image Uploads

Content
View full analysis
Dict[str, Any]: """ 上传文件到Notion 返回文件上传ID """ file_path = Path(file_path_str) if not file_path.exists(): return {"success": False, "error": f"文件不存在: {file_path_str}"} ``` It then opens and transmits the file without checking that it is an expected screenshot: ```python with open(file_path, "rb") as f: files = {"file": (file_path.name, f, mime_type)} response = requests.post(upload_url, headers=headers_upload, files=files) ``` Markdown image paths are normalized and uploaded: ```python def _normalize_image_path(url: str, base_dir: str) -> str: if url.startswith(("http://", "https://")): return url if os.path.isabs(url): return url return os.path.join(base_dir, url) ``` ```python def _upload_local_image(local_path: str) -> Optional[str]: if not upload_local_images: return None try: from upload_file_to_notion import upload_file_to_notion res = upload_file_to_notion(notion_token, local_path) if res.get("success"): return res.get("file_upload_id") return None except Exception: return None ``` ```python img_match = re.search(r"!\[(.*?)\]\((.*?)\)", line) if img_match: flush_paragraph() alt, url = img_match.group(1), img_match.group(2) full = _normalize_image_path(url, images_base_dir) if full.startswith(("http://", "https://")): blocks.append( { "object": "block", "type": "image", "image": {"type": "external", "external": {"url": full}}, } ) ...[truncated 2297 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/upload_file_to_notion.py:49
Finding

Bearer Token and File Data Forwarded to an Unvalidated Upload URL

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:362
Finding

Unverified Third-Party Executable Download and Unpinned Python Dependency

Content
View full analysis
Remediation
View remediation
/tmp/BBDown.zip" | sha256sum --check - ``` 2. Prefer a cryptographically signed release and verify the signature against a pinned maintainer key. 3. Do not execute binaries directly from a shared `/tmp` path. Install into a user-owned directory with restrictive permissions, such as `$HOME/.local/lib/bilibili-cc-to-notion/`. 4. Before execution, verify that the binary is a regular file, is owned by the expected user, is not a symlink, and matches the approved digest. 5. Pin Python dependencies to reviewed versions and hashes using a lock file or requirements file: ```text requests== --hash=sha256: ``` 6. Prefer distribution-maintained packages or build the utility from a pinned, reviewed source commit in a controlled build environment. 7. Run BBDown in a sandbox with a restricted filesystem view, no access to unrelated credentials, and only the network destinations needed for Bilibili. 8. Avoid passing account cookies on command lines. Use a protected credential mechanism and scope Bilibili authentication to the minimum permissions required. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (76)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · CONFIGURATION.md (reported line 16)May include surrounding context.

配置说明

📋 快速配置指南

1. 获取Notion API Token

  1. 访问 Notion Integrations
  2. 点击 "New integration"
  3. 填写名称并选择工作空间
  4. 复制 Internal Integration Token(格式:secret_xxx)

2. 设置环境变量

bash
# 编辑 ~/.bashrc 或 ~/.zshrc
echo 'export NOTION_API_KEY="secret_xxx"' >> ~/.bashrc
source ~/.bashrc

# 可选:设置默认数据库ID
echo 'export NOTION_DATABASE_ID="your_database_id"' >> ~/.bashrc
source ~/.bashrc

3. 分享数据库给Integration

  1. 打开你的Notion数据库
  2. 点击右上角 ... 菜单
  3. 选择 "Connections"(连接)
  4. 搜索并选择你创建的integration

4. 安装依赖

bash
# 安装Python依赖
pip install requests

# 下载BBDown(B站下载器)
curl -L -o /tmp/BBDown.zip "https://github.com/nilaoda/BBDown/releases/download/1.6.3/BBDown_1.6.3_20240814_linux-x64.z

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

整体主用途与声明大体一致:都是从 B站视频获取字幕、处理后创建 Notion 学习笔记,且支持 URL/BV 输入。没有发现明显越权、无关资源访问或恶意/不相关功能。不过,声明中的关键卖点“带截图的 Notion 学习笔记/生成带截图标记”在这段代码里没有得到体现;代码既没有下载视频帧,也没有调用 ffmpeg 进行截图,也没有构造明显的截图时间点字段。FFmpeg 仅被检查可用性,但未实际参与流程。因此描述比代码展示的能力更强,存在一定描述—行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个端到端的B站视频转Notion学习笔记工具,包含输入BV号/URL、下载字幕、分析内容、生成带截图笔记等多个环节。但提供的代码块只实现了最后一步:把调用方传入的字幕片段整理成Notion页面内容并上传。其输入要求是现成的video_title、video_url和segments JSON,而不是BV号或B站链接解析结果;也没有任何与B站、字幕抓取、截图提取相关的逻辑。因此,声明与实际行为存在明显的能力夸大和范围不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个面向 B 站视频的端到端流程工具:输入 BV 号或 URL,自动获取字幕、分析内容、生成带截图的 Notion 学习笔记。而代码片段仅覆盖流程的后半段——将外部传入的字幕片段或 Markdown 内容写入 Notion,并支持图片嵌入/上传。代码需要调用者直接提供 --video-title、--video-url、--segments,说明字幕提取与视频处理并未在此实现。虽然“创建带截图的 Notion 学习笔记”这一部分与声明部分吻合,但声明中的关键前置能力(B站输入支持、CC字幕下载、字幕提取)缺失,导致描述与实际行为存在实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个端到端技能:输入 B 站视频后,下载字幕、分析内容、生成带截图标记的结构化学习笔记,并创建 Notion 笔记。但提供的代码块实际只实现了字幕下载相关功能:检测 BBDown、调用其 --sub-only 下载字幕、在本地查找 .srt/.ass 文件并返回结果。代码中没有任何字幕解析、内容总结、结构化笔记生成、截图抓取、时间戳截图标记、Notion API 调用或写入逻辑。因此,实际行为仅覆盖声明中的一个前置子步骤,无法支持其宣称的主要用途,属于明显的描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个端到端的B站视频转Notion学习笔记工具,包括接受BV号/URL、自动下载CC字幕、智能分析内容并创建Notion笔记。实际代码块仅是一个字幕后处理脚本,输入为本地字幕文件路径(--input),只支持解析SRT格式文本,不包含任何B站访问、URL解析、字幕下载、视频处理、截图采集或Notion API调用。它生成的是Markdown字符串和JSON结果,而非Notion页面。虽然“生成带截图标记的结构化学习笔记”这一小部分与实际行为部分吻合,但整体主用途和关键能力明显少于声明,因此属于描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个较完整的 B 站视频到 Notion 学习笔记流水线,包括接收 B 站标识、下载 CC 字幕、分析内容、生成结构化笔记,并包含截图标记。实际代码并不处理 B 站、字幕、内容分析或 Notion;它只读取本地 Markdown,识别其中的 Screenshot-[hh:mm:ss] 标记,并对本地视频文件调用 ffmpeg 生成截图,再将标记替换为 Markdown 图片链接。这不是对声明功能的简单子步骤说明,而是一个明显更窄且不同的实际能力,因此属于描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents an end-user skill for fetching Bilibili CC subtitles, processing them, and producing Notion learning notes. However, the supplied code chunk is only a test utility that checks whether /tmp/BBDown and ffmpeg are installed and then prints instructions for using another script. Its primary purpose is environment validation, not subtitle extraction, note generation, or Notion integration. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的核心功能是围绕 B 站视频字幕到 Notion 学习笔记的完整处理流程,但提供的代码与该流程基本无关。代码没有访问 B 站、没有处理视频链接、没有下载或解析字幕、没有生成任何笔记内容;它唯一的功能是把指定本地文件上传到 Notion 并返回上传 ID。虽然上传文件到 Notion 可能在更大系统中作为辅助步骤存在,但单独这段代码的主要目的与声明的主要目的明显不一致,且体现出一个未声明的独立能力,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The duplicate-page cleanup step archives pages in Notion, which is a destructive integrity-affecting action against user data, but the skill lacks a prominent warning and explicit approval flow for that behavior. If triggered incorrectly, it could archive legitimate user notes with matching titles, causing data loss or workflow disruption.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This is a concrete tool-parameter abuse issue because the workflow builds shell commands from multiple untrusted parameters and executes them with shell=True. The skill context makes this more dangerous, not less, because it is designed to ingest external video URLs and content and then chain several tools together, allowing one malicious input to propagate into command execution across the workflow.

Content

Scanner excerpt · scripts/bilibili_to_notion_workflow.py (reported line 21)May include surrounding context.

python
print(f"\n🔍 {description}...")

    try:
        result = subprocess.run(
            cmd, shell=True, capture_output=True, text=True, check=True
        )
        return json.loads(result.stdout)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all instructions and user-facing guidance exclusively in Chinese, which effectively forces a specific language/locale on users. The policy allows locale constraints only when justified or when the user is offered a choice, neither of which is present here.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · CONFIGURATION.md (reported line 38)May include surrounding context.

md
pip install requests

# 下载BBDown(B站下载器)
curl -L -o /tmp/BBDown.zip "https://github.com/nilaoda/BBDown/releases/download/1.6.3/BBDown_1.6.3_20240814_linux-x64.zip"
unzip /tmp/BBDown.zip -d /tmp/
chmod +x /tmp/BBDown

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 61)May include surrounding context.

md
pip install requests

# 下载BBDown(B站下载器)
curl -L -o /tmp/BBDown.zip "https://github.com/nilaoda/BBDown/releases/download/1.6.3/BBDown_1.6.3_20240814_linux-x64.zip"
unzip /tmp/BBDown.zip -d /tmp/
chmod +x /tmp/BBDown

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

L025 明确写道“不再使用固定的process_subtitles.py程序”,表示字幕处理已改由大模型负责。但 L146-L147 和 L214-L216 的分步执行与场景示例仍要求运行/调用 process_subtitles.py,文档内部对技能实际工作方式形成直接矛盾。

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The document instructs users to download and execute a binary directly from an external release URL into /tmp without any integrity verification such as checksum or signature validation. If the release asset, transport path, or hosting account were compromised, users could run tampered code on their systems.

Content

Scanner excerpt · FINAL_SUMMARY.md (reported line 107)May include surrounding context.

md
pip install requests

# 2. 下载BBDown
curl -L -o /tmp/BBDown.zip "https://github.com/nilaoda/BBDown/releases/download/1.6.3/BBDown_1.6.3_20240814_linux-x64.zip"
unzip /tmp/BBDown.zip -d /tmp/
chmod +x /tmp/BBDown

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instructions describe sending subtitle text, screenshots, and metadata to external services and creating or modifying Notion content without a clear disclosure of data transmission or workspace modification. This can cause users to upload sensitive video content, notes, or images to third parties unintentionally, especially because the skill is designed to automate the full workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation explicitly describes uploading local files to Notion and creating pages through Notion API/CLI, but it does not warn users that local content, screenshots, and derived notes will be transmitted to a third-party cloud service. This creates a real privacy and consent risk because users may assume the workflow is local-only or may not realize potentially sensitive material is being exported externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The one-click workflow is presented as a convenience feature while bundling several external and state-changing actions: downloading content, generating screenshots, uploading files, and creating remote Notion pages. Without a warning or confirmation boundary, users may trigger a chain of operations that affects remote accounts and discloses data unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README describes a workflow that uploads subtitles, screenshots, and derived notes to Notion, but it does not clearly warn users that video content may contain sensitive, copyrighted, or personal information that will be transmitted to a third-party service. In this skill’s context, the omission matters because the entire purpose of the skill is to extract and republish content externally, increasing the chance of unintended data disclosure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill exposes broad capabilities—network access, shell execution, and file read/write—without any explicit tool scoping or allowlist. In an agent setting, this increases the blast radius of prompt injection or misuse because the runtime is permitted to perform powerful actions beyond the minimal set clearly constrained in metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is designed to upload local screenshots and create Notion pages, which modifies user-owned remote content, yet the user-facing description does not prominently warn that external data transfer and content creation will occur. This weakens informed consent and can lead to unintended disclosure of local files or unauthorized writes to a user's workspace.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

L052-L128 requires a full seven-section learning-note structure including course overview, knowledge framework, detailed study content, concept summaries, reflections, formulas/methods, and FAQ. But the example at L282-L300 shows a much simpler segment-by-segment note format, and the later example at L221-L242 also presents a different simplified chapter layout. This is active documentation inconsistency about what the skill is supposed to generate.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill instructs downloading and executing a binary from an external release URL via curl/unzip/chmod without any integrity verification such as checksums or signature validation. This creates a supply-chain risk: if the release is tampered with, replaced, or intercepted in a compromised environment, the agent may run untrusted code.

Content

Scanner excerpt · SKILL.md (reported line 365)May include surrounding context.

md
pip install requests

# 下载BBDown(B站下载器)
curl -L -o /tmp/BBDown.zip "https://github.com/nilaoda/BBDown/releases/download/1.6.3/BBDown_1.6.3_20240814_linux-x64.zip"
unzip /tmp/BBDown.zip -d /tmp/
chmod +x /tmp/BBDown

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

At L507-L513, Step 2 says the model must '逐字保留' all subtitle text and forbids summarization or omission. Earlier requirements at L024-L049 and L130-L150 require understanding the course, extracting knowledge points, building a knowledge framework, and adding learner reflections, which is materially different from verbatim preservation. These instructions describe conflicting intents for the core behavior of the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.