bbc-skill

Fail

Audited by Socket on Sep 10, 2026

3 alerts found:

Malwarex2Anomaly
MalwareHIGH
bbc/cookie/chrome_macos.py

This code is designed to harvest and decrypt browser authentication cookies, including a targeted Bilibili `SESSDATA` session cookie, by accessing the macOS Keychain and browser cookie databases. Although no external exfiltration is shown, returning decrypted session credentials is malicious or highly unsafe in a package context. The fragment is also syntactically incomplete at the end.

Confidence: 99%Severity: 98%
AnomalyLOW
cookie-extraction.md

No direct evidence of malware or intentional exfiltration appears in this documentation-only fragment. It describes sensitive browser-cookie and Keychain extraction capabilities, creating a meaningful credential-theft risk if implemented insecurely or combined with an untrusted API client. The actual extraction and network code is required for a complete assessment.

Confidence: 97%Severity: 62%
MalwareHIGH
bbc/cookie/firefox.py

The code is designed to locate Firefox profiles and extract Bilibili cookies, including the SESSDATA session cookie. This is unauthorized credential/session-token harvesting behavior and represents a high security risk even though no exfiltration mechanism appears in the provided fragment. The incomplete final statement also makes the supplied code invalid Python.

Confidence: 99%Severity: 98%
Audit Metadata
Analyzed At
Sep 10, 2026, 06:57 AM
Package URL
pkg:socket/skills-sh/agents365-ai%2F365-skills%2Fbbc-skill%2F@66342ca66712e2de9d131914b48159c87eefe62afba11017245d94343bfc969d
Security Audit — socket — bbc-skill