Book a 30-minute demo →
Skill scan report

films-search

View on GitHub
49 Medium This skill sends sensitive values to an external host. Automated analysis flagged 2 additional risk patterns.

What this skill does

Search cloud drives for downloadable film and TV resources (movies, TV series, anime).

github/netease-youdao - Data Exfiltration - 5.9k stars

ThreatsData Exfiltration Insecure Configuration Loading

Threat analysis

Data Exfiltration2 findings
Insecure Configuration Loading2 findings

Skill info

Namenetease-youdao/films-search
Registrygithub
Versionbef896b
PURLpkg:github/netease-youdao/LobsterAI@bef896b?skill=films-search
Stars5.9k

Assessments (4)

Data Exfiltration2 findings HIGH
HIGH

Data Exfiltration via local-llm-review

scripts/film-search.js

The script loads configuration from environment variables (e.g., FILM_SEARCH_PREFERRED_PAN, FILM_SEARCH_DEFAULT_LIMIT, etc.), which could be used to control the behavior of the tool, including potenti
HIGH

Data Exfiltration via local-llm-review

scripts/shared/deep-extract.js

The deep-extract.js script contains functions for extracting links and codes from web pages, which could be used to exfiltrate sensitive data if the script is used on malicious or untrusted websites.
Insecure Configuration Loading2 findings HIGH
HIGH

Insecure Configuration Loading via local-llm-review

scripts/film-search.ps1

The PowerShell script loads a .env file and sets environment variables, which could be used to inject malicious configuration values if the .env file is not properly secured.
HIGH

Insecure Configuration Loading via local-llm-review

scripts/film-search.sh

The Bash script loads a .env file and sources it, which could be used to inject malicious configuration values if the .env file is not properly secured.

Badge

Add the Anomity scan badge for films-search to your README.

Anomity Skill Check badge

Markdown
[![Anomity Skill Check](https://anomity.ai/skills/badge.svg)](https://anomity.ai/skills/github/netease-youdao/films-search/)
HTML
<a href="https://anomity.ai/skills/github/netease-youdao/films-search/"><img src="https://anomity.ai/skills/badge.svg" alt="Anomity Skill Check"></a>
Image URL
https://anomity.ai/skills/badge.svg

How Anomity governs this at runtime

Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.

Book a 30-minute demo to see your own skill inventory.

Methodology and disputes

Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of films-search? Report an issue or request a rescan.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok