bili-following-latest
Pass
Audited by Gen Agent Trust Hub on Jun 27, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local Python scripts such as
download_bili_following_latest.pyandpostprocess_bili_videos.pyto manage the workflow. It also relies on standard CLI tools likelark-cliandyt-dlp, which are common for media scraping and API integration tasks. The execution is limited to the local project pathE:\projects\codexProjects\AI博主爬取. - [DATA_EXFILTRATION]: Data is transferred between Bilibili and the user's Feishu Base as part of the intended functionality. The skill provides clear security instructions to avoid printing or persisting cookie plaintext, reducing the risk of accidental credential exposure during debugging or execution.
- [PROMPT_INJECTION]: The skill ingests untrusted content from Bilibili, including video descriptions and user comments, for the purpose of summarization. While this constitutes an indirect prompt injection surface, the risk is mitigated as the skill treats the content as data to be processed rather than instructions to be obeyed.
- [REMOTE_CODE_EXECUTION]: A Python verification script is provided within the documentation to be executed locally. This script performs manifest validation and checks for local file existence; it does not contain logic for fetching or executing code from remote sources.
Audit Metadata