Back to skill

Security audit

B站视频下载器

Security checks for vulnerabilities and agentic risk

Overview

This Bilibili downloader has a clear purpose, but its shell-command templates use user-provided URLs and paths without validation or safe argument handling.

Review before installing. Use only trusted Bilibili URLs and destination paths, avoid copying paths or URLs from untrusted parties, and prefer a revised version that pins yt-dlp and invokes it with safe argument handling rather than shell string interpolation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Third-Party Package Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:42
Finding

Shell Command Injection Through User-Controlled Path and URL Interpolation

Content
View full analysis
" | Out-Null yt-dlp -o "<目标目录>/%(title)s.%(ext)s" "" ``` ### Technical Analysis The Skill directs the Agent to place a user-provided destination path and URL directly into command strings executed by a shell. The syntax involving `mkdir -Force` and `Out-Null` indicates PowerShell-style command processing. Surrounding a value with double quotes is not sufficient when an attacker can provide an embedded quotation mark. A crafted value can terminate the intended quoted argument and introduce PowerShell command separators, comments, pipelines, or additional commands. Because the instructions do not require strict validation, shell-specific escaping, or a shell-free process API, the destination path and URL both represent potential command-injection inputs. For example, a malicious path shaped like the following could escape the quoted argument when substituted into the template: ```text D:\Videos"; whoami; # ``` The generated command would contain an attacker-controlled command after the prematurely closed path argument. The exact payload can be replaced with any command available to the executing account. ### Attack Path 1. An attacker asks the Agent to download a video and supplies a destination path or URL containing a quotation mark and PowerShell metacharacters. 2. The Agent follows the documented template and substitutes that input into the command string. 3. The shell interprets the injected quotation mark as the end of the intended argument. 4. A command separator causes the remaining attacker-controlled text to be parsed as an independent PowerShell command. 5. The injected command executes with the same operating-system privileges as the Agent. ### Impact Assessment Successful expl ...[truncated 515 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language instructions and examples are entirely in Chinese, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file instructs the agent to run mkdir and yt-dlp to create a directory and write downloaded media files, which can affect the user's filesystem. While the document explains the required -o path behavior, it does not explicitly warn the user about the file-creation/write side effects before execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.