Bilibili Audio Transcribe

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Bilibili audio transcription helper that downloads requested media and saves local transcript files without hidden data access.

Install this only if you intend to download and transcribe Bilibili or b23.tv media locally. Use a virtualenv, process only links you are allowed to download, and delete downloaded audio or transcript files when they are no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
92% confidence
Finding
The skill description tells the agent to convert links into local transcript files but does not clearly warn that it will fetch remote content and create multiple files on disk. That omission can mislead users about side effects, especially in environments where network access, storage usage, or handling of untrusted media must be explicitly approved.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal