Caveat verdict
maxhub-bilibili
bilibili-aggregate-scraper
Accesses credentials AND makes external network calls
The skill uses network capabilities to query data from Bilibili APIs, which is in line with its stated purpose and does not show any malicious behavior.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but Caveat detects co-occurrence — it does not verify that one flows into another. Read the code to confirm a live chain.
Accesses credentials AND makes external network calls — potential credential theft
LLM02 · ASI03
Findings (1)
Possible hardcoded credential
SKILL.md · prose · downgraded · API_KEY="你的_API_KEY
Permissions & capabilities
Requires 1 environment variable. (1 sensitive: MAXHUB_API_KEY). Requires 1 system binary. (1 elevated: curl).
network_outnetwork_incredential_access Thanks — recorded.