bilibili-video-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions designed to override standard safety protocols by directing the agent to install dependencies "automatically without asking the user to confirm" and explicitly stating "do not request separate approval."
  • [EXTERNAL_DOWNLOADS]: The skill mandates the installation of software from an external domain (browseract.com) that is not identified as a trusted vendor, posing a significant supply chain risk.
  • [COMMAND_EXECUTION]: The skill's operation depends on the browser-act CLI, which executes commands on the host system.
  • [REMOTE_CODE_EXECUTION]: The automatic fetching and installation of remote software components without user review or integrity validation constitutes a remote code execution risk.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests untrusted data from Bilibili pages. Ingestion points: Bilibili video titles, stats, and metadata. Boundary markers: None (missing delimiters to separate data from instructions). Capability inventory: Execution of browser-act CLI and access to the workspaces/ directory. Sanitization: The instructions do not define any sanitization or escaping for the scraped content.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:14 AM
Security Audit — agent-trust-hub — bilibili-video-scraper