Back to skill

Security audit

Bilibili Audio Transcribe

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it downloads audio from Bilibili links, transcribes it locally, and writes transcript files, with ordinary dependency and supply-chain cautions.

Before installing, use this only for Bilibili or b23.tv links, expect network downloads and local transcript/media files under the chosen output directory, and consider pinning dependency versions or reviewing the packages before running the bootstrap script. Run sudo package-manager commands only if you intentionally want to install ffmpeg system-wide.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:1
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: scripts/requirements.txt:1-2
Vulnerability Type: Unpinned dependencies without integrity verification
Risk Level: Medium

Vulnerable Code

text
yt-dlp
faster-whisper

The dependencies are installed by scripts/bootstrap_env.sh:10-11:

bash
python -m pip install --upgrade pip
python -m pip install -r "${REQ_FILE}"

Technical Analysis

The requirements file specifies package names without exact versions or cryptographic hashes. Consequently, each bootstrap run resolves whichever package releases are available from the configured Python package index at that time. The script also upgrades pip to a mutable latest version.

This makes the resulting environment non-reproducible and expands exposure to upstream package compromise, malicious replacement through a misconfigured package index, or unexpected behavior introduced by a new release. Python packages can execute package-controlled code during installation and subsequently run with the privileges of the user invoking the skill.

The reviewed files do not specify a suspicious package source, custom index, or known malicious package. Therefore, this is a supply-chain hardening deficiency rather than evidence that the current package names are malicious.

Attack Path

  1. An attacker compromises an upstream dependency release or controls the package index configured in the execution environment.
  2. The user follows the documented setup procedure and runs scripts/bootstrap_env.sh.
  3. pip resolves the mutable latest version of yt-dlp or faster-whisper without validating an expected version or hash.
  4. The compromised package is installed into the virtual environment.
  5. Malicious package code executes during installation or when the transcription script imports and uses the dependency.

Impact Assessment

Compromised dependency code would execute with the privileges of the use ...[truncated 347 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to a reviewed exact version, for example:

    text
    yt-dlp==REVIEWED_VERSION
    faster-whisper==REVIEWED_VERSION
    
  2. Generate and commit a lock file that includes reviewed transitive dependencies.

  3. Record cryptographic hashes and install with pip install --require-hashes -r requirements.txt.

  4. Use an explicitly trusted package index and prevent fallback to untrusted extra indexes.

  5. Remove the unconditional pip upgrade or pin pip to a reviewed version with integrity verification.

  6. Automate dependency vulnerability monitoring and review updates before changing pinned versions.

  7. Build dependencies in a restricted environment with only the filesystem and network access needed for installation.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (12)

Tainted flow: 'audio_path' from input (line 342, user input) → subprocess.run (code execution)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

External input (network, user) flows to a code execution sink. This enables remote code execution or command injection.

Content

Scanner excerpt · scripts/transcribe_bilibili.py (reported line 86)May include surrounding context.

python
def probe_duration(audio_path: Path) -> float:
    result = subprocess.run(
        [
            "ffprobe",
            "-v",

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
- `requirements.txt` — Python package list for the bootstrap script

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/troubleshooting.md (reported line 10)May include surrounding context.

md
Fix:
- macOS (Homebrew): `brew install ffmpeg`
- Debian/Ubuntu: `sudo apt-get update && sudo apt-get install -y ffmpeg`
- Verify: `ffmpeg -version` and `ffprobe -version`

## Missing Python packages

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes capabilities that require shell execution, network access, and local file writes, but it does not declare an explicit tool scope such as permissions or allowed-tools. This creates an authorization and transparency gap: an agent may invoke broader-than-expected capabilities to download remote content and write artifacts locally without clear policy boundaries.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 10)May include surrounding context.

md
Fix:
- macOS (Homebrew): `brew install ffmpeg`
- Debian/Ubuntu: `sudo apt-get update && sudo apt-get install -y ffmpeg`
- Verify: `ffmpeg -version` and `ffprobe -version`

## Missing Python packages

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code sets DEFAULT_LANGUAGE = "zh", which makes the skill assume a specific language by default rather than offering neutral auto-detection or explicit user choice. This is a natural-language locale policy concern because it forces a locale preference unless the user notices and overrides it.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/transcribe_bilibili.py (reported line 86)May include surrounding context.

python
def probe_duration(audio_path: Path) -> float:
    result = subprocess.run(
        [
            "ffprobe",
            "-v",

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs downloading media from external URLs and writing transcript files to local storage, but it does not explicitly warn the user that network access and local file creation will occur. This can lead to unexpected data transfer, storage side effects, or overwriting/accumulation of local artifacts in environments where users expect read-only assistance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The markdown includes a Chinese-only error string (未找到 ffmpeg 或 ffprobe) as the symptom, with no indication that the skill supports multiple locales or that this is a region-specific tool. This can reflect a natural-language locale constraint without user opt-in, which falls under the language/locale policy check.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency yt-dlp is unpinned, so installs may resolve to different versions over time, including versions with known security issues or breaking changes. In this skill, yt-dlp processes untrusted user-supplied Bilibili/b23.tv URLs and interacts with remote content, which increases the security risk of silently pulling a vulnerable release.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
yt-dlp
faster-whisper

Unverifiable Dependency: yt-dlp has 16 known advisory(ies) (CVE-2023-46121 (yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy Injection); GHSA-3v33-3wmw-3785 (yt-dlp has dependency on potentially malicious third-party code in Douyu extract); CVE-2023-40581 ( yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
97% confidence
Finding

yt-dlp has multiple known advisories, and because no version is pinned, there is no way to verify whether the installed package is fixed or still vulnerable. This is especially concerning in a skill designed to fetch and process attacker-influenced URLs from Bilibili/b23.tv, where downloader/parser flaws or command-injection-style bugs could be reached through normal skill use.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The dependency faster-whisper is also unpinned, which makes builds non-reproducible and can introduce vulnerable or incompatible versions without review. While it is less obviously exposed than the downloader, it still handles externally derived media/transcription workloads, so supply-chain and stability risk remain relevant.

Content

Scanner excerpt · scripts/requirements.txt (reported line 2)May include surrounding context.

text
yt-dlp
faster-whisper

Static analysis

No suspicious patterns detected.