bibi
Fail
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill documentation and check script suggest installing the BibiGPT CLI on Linux using a piped bash command:
curl -fsSL https://bibigpt.co/install.sh | bash. While this is a high-risk execution pattern, it targets the vendor's official domain for the purpose of setting up the required environment for the skill. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and process transcripts, subtitles, and summaries from external platforms like YouTube, Bilibili, and Podcasts.
- Ingestion points: Media content (transcripts/subtitles) is fetched from external URLs via
workflows/quick-summary.md,workflows/transcript-extract.md, andworkflows/article-rewrite.md. - Boundary markers: The instructions do not define explicit boundary markers or warnings for the agent to ignore instructions embedded within the processed video content.
- Capability inventory: The skill has access to shell execution via the
bibiCLI andcurl, and file system write capabilities inworkflows/export-notes.md. - Sanitization: No explicit sanitization or filtering of the ingested transcript content is performed before the agent processes it for summarization or rewriting.
- [COMMAND_EXECUTION]: The skill makes extensive use of the
bibiCLI to perform its tasks (summarizing, searching library, managing collections). It also usescurlto interact with the BibiGPT API when the CLI is not available. - [EXTERNAL_DOWNLOADS]: The skill fetches its OpenAPI specification and live documentation from the vendor's site (
https://bibigpt.co/api/openapi.json) and raw content from the project's GitHub repository to ensure the instructions remain up-to-date.
Recommendations
- HIGH: Downloads and executes remote code from: https://bibigpt.co/install.sh - DO NOT USE without thorough review
Audit Metadata