bilibili

Warn

Audited by Socket on Jul 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent with Bilibili article management, but it relies on high-value browser session cookies captured through a third-party connector flow instead of an official scoped auth model, and it enables real public posting/deletion actions. No strong malware or supply-chain indicators are present, but the credential scope and account-impacting actions make it medium-high risk.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Jul 9, 2026, 06:42 PM
Package URL
pkg:socket/skills-sh/acedatacloud%2Fskills%2Fbilibili%2F@af66744f4393604a98762e72dc38a245db5fddd1d96c7355f875716a05b8cda9
Security Audit — socket — bilibili