bili-daily-update-check
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes several project-local scripts, such as
download_bili_following_latest.py,postprocess_bili_videos.py, andsync_bilibili_comments_to_feishu.py. It also useslark-cliwith a specific profile to interact with Feishu Base. - [EXTERNAL_DOWNLOADS]: The skill fetches video streams, metadata, and comments from Bilibili using
yt-dlpand Playwright-based scraping logic. These network operations are core to its functionality and target well-known services. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted text from Bilibili (video titles, descriptions, and comments) to generate automated summaries and pain points for Feishu records. This constitutes an attack surface where malicious content in a video description or comment could influence the agent's output.
- Ingestion points: Video descriptions and titles extracted via
scripts/bilibili_chrome_latest_helper.mjsand comment data from the Bilibili API. - Boundary markers: The instructions do not specify the use of clear delimiters or 'ignore' instructions for the LLM during the summarization step.
- Capability inventory: The skill possesses file system access, the ability to execute subprocesses, and network access to Feishu.
- Sanitization: Minimal sanitization (whitespace normalization) is performed on external text before it is processed by the agent.
Audit Metadata