Back to skill

Security audit

bilibili-research-kit

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Bilibili research helper, but it asks users or agents to use local browser cookies without adequately warning that those cookies are sensitive account credentials.

Review before installing. Use the cookie-based authentication command only on your own machine and account, and treat browser cookies like passwords: do not share them, paste them into logs, or run the command in shared environments. Prefer an isolated Python environment and a pinned yt-dlp version if you use the pip install path.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
= 2024.01.01`, this does not constrain installation to a known-good release. No evidence indicates that the current `yt-dlp` package or the documented package name is malicious. The risk arises because the effective dependency can change after this skill has been reviewed. If the package distribution channel, maintainer account, or a future release were compromised, users following this instruction could install code that was never covered by this audit. Python packages may execute code during installation or when subsequently invoked. ### Attack Path 1. An attacker compromises the dependency maintainer account, package distribution process, or package index infrastructure. 2. The attacker publishes a malicious release under the legitimate `yt-dlp` package name. 3. A user follows the skill's unpinned `pip install yt-dlp` instruction. 4. pip resolves the attacker-controlled release because no exact version or integrity hash is required. 5. Malicious package code executes during installation or when the user invokes `yt-dlp`. ### Impact Assessment Successful exploitation could permit arbitrary code execution with the privileges of the account running pip or invoking the installed package. Depending on those privileges, the attacker could access user-readable files, environment variables, browser data, authentication cookies, and network resources, or modify files owned by the user. If installation is performed with administrative privileges, the impact could extend across t ...[truncated 171 chars]
Remediation
View remediation
" ``` 2. Distribute a hash-locked requirements file and require hash verification: ```text yt-dlp== --hash=sha256: ``` ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 3. Obtain hashes directly from a trusted release artifact or package index and update them only after reviewing the new release. 4. Install the dependency in an isolated virtual environment rather than the system Python environment: ```bash python3 -m venv .venv . .venv/bin/activate python3 -m pip install --require-hashes -r requirements.txt ``` 5. Avoid running pip with root or administrator privileges. Use a trusted package index over TLS and consider disabling unexpected secondary indexes to reduce dependency-confusion exposure. 6. Add a documented dependency-update process that includes release review, integrity verification, and periodic vulnerability scanning. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
91% confidence
Finding

The --cookies-from-browser chrome pattern matches credential-access behavior because it extracts authenticated browser session cookies from a local browser profile. Although presented for legitimate access to user-authorized content, this is sensitive functionality that can expose account sessions if run in shared environments, logged, or repurposed by a malicious operator.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

, UP主 profiles, and collections for content research. Powered by yt-dlp locally — no API key required.

Version: 1.0.0 Prerequisite: yt-dlp >= 2024.01.01

Prerequisites

bash
# macOS
brew install yt-dlp

# pip
pip install yt-dlp

# Verify
yt-dlp --version

Authentication

Some Bilibili content requires login (higher quality, member-only). Export cookies:

bash
yt-dlp --cookies-from-browser chrome "URL"

Operations

1. Video Metadata

Extract title, UP主, stats, description, tags from a single video.

bash
yt-dlp --dump-json --skip-download "https://www.bilibili.com/video/BV_ID"

Key JSON fields:

FieldJSON path
Title.title
UP主.uploader
UP主 ID.uploader_id
Upload date.upload_date (YYYYMMDD → YYYY-MM-DD)
Duration.duration (seconds → H:MM:SS)
Views.view_count
Likes.like_count
Coins.comment_count (Bilibili maps this field)
Descript

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill tells users to export browser cookies for authenticated access without warning that browser cookies are sensitive credentials that may grant account access. In a security context, encouraging cookie extraction can normalize handling session tokens unsafely and may lead users to expose or reuse privileged authentication material in logs, shells, or shared environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The instructions tell the user to fetch danmaku XML and save it to danmaku.xml, which modifies local files. While the operation is not highly destructive, the skill description does not explicitly warn that it creates output files on disk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes a Bilibili research and extraction skill focused on metadata, subtitles, danmaku, profile, and collection analysis. In the workflow guide, the file additionally instructs how to respond to download requests and recommends an external download service, which goes beyond the stated analysis-focused scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.