bilibili-video

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is coherent for a Bilibili downloader, and its network flows point to official Bilibili APIs rather than an interception service. The main risk is credential forwarding: a user’s Bilibili session cookie may be handed to the external yt-dlp binary, and the actual wrapper behavior cannot be verified from the excerpt. Script-name inconsistencies further reduce trust, so this is not malicious on its face but carries medium security risk.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Apr 17, 2026, 06:03 AM
Package URL
pkg:socket/skills-sh/giarld%2Fskills%2Fbilibili-video%2F@d06a2a9a8970cc32648cb2c5c5559ee970fef933
Security Audit — socket — bilibili-video