bili-following-latest

Pass

Audited by Gen Agent Trust Hub on Jun 27, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local Python scripts such as download_bili_following_latest.py and postprocess_bili_videos.py to manage the workflow. It also relies on standard CLI tools like lark-cli and yt-dlp, which are common for media scraping and API integration tasks. The execution is limited to the local project path E:\projects\codexProjects\AI博主爬取.
  • [DATA_EXFILTRATION]: Data is transferred between Bilibili and the user's Feishu Base as part of the intended functionality. The skill provides clear security instructions to avoid printing or persisting cookie plaintext, reducing the risk of accidental credential exposure during debugging or execution.
  • [PROMPT_INJECTION]: The skill ingests untrusted content from Bilibili, including video descriptions and user comments, for the purpose of summarization. While this constitutes an indirect prompt injection surface, the risk is mitigated as the skill treats the content as data to be processed rather than instructions to be obeyed.
  • [REMOTE_CODE_EXECUTION]: A Python verification script is provided within the documentation to be executed locally. This script performs manifest validation and checks for local file existence; it does not contain logic for fetching or executing code from remote sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 27, 2026, 07:27 AM
Security Audit — agent-trust-hub — bili-following-latest