Scan Report
20 /100
rrbdagent
RRBD Admin项目智能助手,支持数字人形象管理和视频创建
这是一个合法的数字人视频创建AI技能,仅调用配置的外部API(rrbd20.yzidea.net)进行身份认证和视频管理,无恶意行为。存在权限声明宽泛的轻微瑕疵。
Safe to install
可安全使用。建议:1) 避免在config.json中存储明文凭证 2) 明确声明allowed-tools权限范围
Findings 3 items
| Severity | Finding | Location |
|---|---|---|
| Low | 权限声明不明确 | SKILL.md:1 |
| Low | config.json包含敏感配置 | config.json:1 |
| Low | memory.json记录历史视频 | memory.json:1 |
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Filesystem | READ | WRITE | ✓ Aligned | index.js:47-53 memory.json写入; api_client.js:41-45 config.json写入 |
| Network | READ | READ | ✓ Aligned | api_client.js:67-89 仅调用配置的API端点 |
| Shell | NONE | NONE | — | grep未发现subprocess/child_process/eval/exec |
28 findings
Medium External URL 外部 URL
https://rrbd20.yzidea.net/api SKILL.md:112 Medium External URL 外部 URL
https://rrbd20ims.oss-cn-shenzhen.aliyuncs.com/1962755608750927873/20260318/db53e8268c9a4459a9f1280890962099.mp4 memory.json:8 Medium External URL 外部 URL
https://rrbd20ims.oss-cn-shenzhen.aliyuncs.com/1962755608750927873/20260318/2fd0e5fe338745899348050aad92fa03.mp4 memory.json:14 Medium External URL 外部 URL
https://rrbd20ims.oss-cn-shenzhen.aliyuncs.com/1962755608750927873/20260318/174f34fc8bce4dc4b7d38e7b5c2818bd.mp4 memory.json:20 Medium Wallet Address 加密货币钱包地址
174f34fc8bce4dc4b7d38e7b5c2818bd memory.json:20 Medium External URL 外部 URL
https://registry.npmmirror.com/asynckit/-/asynckit-0.4.0.tgz package-lock.json:17 Medium External URL 外部 URL
https://registry.npmmirror.com/axios/-/axios-1.13.6.tgz package-lock.json:22 Medium External URL 外部 URL
https://registry.npmmirror.com/call-bind-apply-helpers/-/call-bind-apply-helpers-1.0.2.tgz package-lock.json:32 Medium External URL 外部 URL
https://registry.npmmirror.com/combined-stream/-/combined-stream-1.0.8.tgz package-lock.json:44 Medium External URL 外部 URL
https://registry.npmmirror.com/delayed-stream/-/delayed-stream-1.0.0.tgz package-lock.json:55 Medium External URL 外部 URL
https://registry.npmmirror.com/dunder-proto/-/dunder-proto-1.0.1.tgz package-lock.json:63 Medium External URL 外部 URL
https://registry.npmmirror.com/es-define-property/-/es-define-property-1.0.1.tgz package-lock.json:76 Medium External URL 外部 URL
https://registry.npmmirror.com/es-errors/-/es-errors-1.3.0.tgz package-lock.json:84 Medium External URL 外部 URL
https://registry.npmmirror.com/es-object-atoms/-/es-object-atoms-1.1.1.tgz package-lock.json:92 Medium External URL 外部 URL
https://registry.npmmirror.com/es-set-tostringtag/-/es-set-tostringtag-2.1.0.tgz package-lock.json:103 Medium External URL 外部 URL
https://registry.npmmirror.com/follow-redirects/-/follow-redirects-1.15.11.tgz package-lock.json:117 Medium External URL 外部 URL
https://registry.npmmirror.com/form-data/-/form-data-4.0.5.tgz package-lock.json:136 Medium External URL 外部 URL
https://registry.npmmirror.com/function-bind/-/function-bind-1.1.2.tgz package-lock.json:151 Medium External URL 外部 URL
https://registry.npmmirror.com/get-intrinsic/-/get-intrinsic-1.3.0.tgz package-lock.json:159 Medium External URL 外部 URL
https://registry.npmmirror.com/get-proto/-/get-proto-1.0.1.tgz package-lock.json:182 Medium External URL 外部 URL
https://registry.npmmirror.com/gopd/-/gopd-1.2.0.tgz package-lock.json:194 Medium External URL 外部 URL
https://registry.npmmirror.com/has-symbols/-/has-symbols-1.1.0.tgz package-lock.json:205 Medium External URL 外部 URL
https://registry.npmmirror.com/has-tostringtag/-/has-tostringtag-1.0.2.tgz package-lock.json:216 Medium External URL 外部 URL
https://registry.npmmirror.com/hasown/-/hasown-2.0.2.tgz package-lock.json:230 Medium External URL 外部 URL
https://registry.npmmirror.com/math-intrinsics/-/math-intrinsics-1.1.0.tgz package-lock.json:241 Medium External URL 外部 URL
https://registry.npmmirror.com/mime-db/-/mime-db-1.52.0.tgz package-lock.json:249 Medium External URL 外部 URL
https://registry.npmmirror.com/mime-types/-/mime-types-2.1.35.tgz package-lock.json:257 Medium External URL 外部 URL
https://registry.npmmirror.com/proxy-from-env/-/proxy-from-env-1.1.0.tgz package-lock.json:268 File Tree
38 files · 138.8 KB · 4024 lines JavaScript 30f · 3121L
JSON 5f · 516L
Markdown 1f · 275L
Python 2f · 112L
├─
▾
scripts
│ ├─
check_video_status.js
JavaScript
│ ├─
check_video_status.py
Python
│ ├─
create_another_video.js
JavaScript
│ ├─
create_laozeng_video.js
JavaScript
│ ├─
create_video_custom_title.js
JavaScript
│ ├─
create_video_fixed.js
JavaScript
│ ├─
generate_new_video.js
JavaScript
│ ├─
get_videos_now.js
JavaScript
│ ├─
just_get_videos.js
JavaScript
│ ├─
laozeng_video.js
JavaScript
│ ├─
login_and_check.js
JavaScript
│ ├─
make_video_now.js
JavaScript
│ ├─
quick_check.js
JavaScript
│ ├─
show_me_videos.js
JavaScript
│ ├─
test_fixed_code.js
JavaScript
│ ├─
test_szr_api.js
JavaScript
│ └─
videos_please.js
JavaScript
├─
_meta.json
JSON
├─
api_client.js
JavaScript
├─
check_now.js
JavaScript
├─
check_simple.js
JavaScript
├─
check_videos_now.js
JavaScript
├─
config.json
⚠
JSON
├─
create_video_different_template.js
JavaScript
├─
create_video_laozeng_shuai.js
JavaScript
├─
create_video_laozeng_shuai2_final.js
JavaScript
├─
create_video_laozeng_shuai2.js
JavaScript
├─
create_video_using_skill.js
JavaScript
├─
index.js
JavaScript
├─
list_videos_final.js
JavaScript
├─
list_videos_simple.js
JavaScript
├─
list_videos.js
JavaScript
├─
list_videos.py
Python
├─
memory.json
JSON
├─
package-lock.json
JSON
├─
package.json
JSON
├─
quick_check.js
JavaScript
└─
SKILL.md
Markdown
Dependencies 1 items
| Package | Version | Source | Known Vulns | Notes |
|---|---|---|---|---|
axios | ^1.6.2 | npm | No | 主流HTTP客户端,无已知漏洞 |
Security Positives
✓ 无shell执行、eval、base64解码等恶意模式
✓ 无环境变量遍历收割凭证行为
✓ 无外部IP请求,所有API调用指向配置的后端服务
✓ 无数据外泄,所有数据仅在用户授权下传输到目标API
✓ 代码功能单一明确,专注视频创建业务
✓ 依赖项简单,仅使用axios,无第三方恶意依赖风险