mrkeyoor.com_
Wed 07 Oct 06:45 UTC
Automationevaluationupdated 07 Oct 2026

qiaomu-download review

qiaomu-download is a Chinese-language Agent Skill for downloading video, audio, or subtitles through a plain request such as "download this URL." The main documentation is in Chinese and there is no full English README; the skill wraps yt-dlp, adds post-download ffprobe checks, and has special paths for WeChat Channels and Spotify tracks.

Verdict

Our qiaomu-download run installed 35 packages in 11 seconds and passed all 43 tests, so its small Python layer is easy to verify. Use it if you read Chinese and want an agent to apply strict download, cookie, and ffprobe rules around yt-dlp. Use yt-dlp directly if you already know its command line, or avoid this skill when local proxy and certificate changes are unacceptable.

We ran it

Lab card: what happened when we ran qiaomu-downloadScreenshot of qiaomu-download (github.com/joeseesun/qiaomu-download)
Install✓ · 11s35 packages · 37 MB
Build✓ · 2s
Tests✓ · 6s43 passed · 0 failed of 43 (pytest)
Known vulns0(pip-audit)
Repo42 files~2,421 lines of source · 6.7 MB · 0 CI workflows · tests dir

Answers from our run

Does qiaomu-download build from source?

Dependencies installed in 11 seconds (35 packages), and the build succeeded in 2 seconds. We cloned commit 8e92fb0 into a clean Debian container with 3 CPUs and no project-specific setup.

Do qiaomu-download's tests pass?

Yes: 43 of 43 passed when we ran the project's own test command (pytest). Some failures need services or credentials a bare container does not have.

Does qiaomu-download have known vulnerabilities in its dependencies?

pip-audit found none in the dependency tree at the time of our run.

Who should not use qiaomu-download?

English-only teams: the main README, operating rules, and troubleshooting are written in Chinese, with no full English guide.

What are the alternatives to qiaomu-download?

yt-dlp, spotDL, wx_channels_download. Our qiaomu-download run installed 35 packages in 11 seconds and passed all 43 tests, so its small Python layer is easy to verify.

Setup4/511-second install; ffmpeg and site tools remain external
Docs4/5Specific Chinese guide, but no complete English documentation
Community3/5378 stars, one open issue, and a September 2026 release
Maturity3/543 tests passed; live site behavior can still change

Who it’s for

Chinese-speaking agent users who want one command shape across yt-dlp-supported sites.
Developers who want downloads checked for a real media stream, duration, codec, and nonzero file size.
Users who need a cautious public-first browser-cookie fallback.
People handling WeChat Channels links who can complete any required playback and certificate steps themselves.

Who it’s NOT for

English-only teams: the main README, operating rules, and troubleshooting are written in Chinese, with no full English guide.
Anyone expecting permanent support for every listed site: the README says extractors can break when sites change.
Users seeking DRM, paywall, membership, or region bypasses: the project explicitly refuses those jobs.
People who want Spotify's encrypted stream: the adapter takes public Spotify metadata and matches it to a YouTube audio source.
Operators unwilling to permit local proxy or certificate changes for WeChat capture: first use may require both, with separate consent and restoration steps.

Setup reality

Our sandbox installed commit 8e92fb0 in 11 seconds, adding 35 packages and using 37 MB. The build passed in 2 seconds, and pytest finished in 6 seconds with 43 passed and 0 failed of 43. Pip-audit found 0 known vulnerabilities.

The useful runtime needs Python 3.10+, yt-dlp, ffmpeg, and ffprobe. Browser cookies are optional and used only after public extraction fails. WeChat Channels may need a separately installed pinned backend, local certificate trust, and a temporary system proxy.

There is no Dockerfile or CI workflow in the repository. Site support moves with yt-dlp and the sites themselves, and the skill checks for a stable yt-dlp update at the start of each new download task.

One Chinese request routes video, audio, subtitles, or metadata

qiaomu-download turns a short instruction and URL into a bounded media task. The trigger rules distinguish a download request from a bare link, a request to summarize a video, or a request for an image or PDF. Once triggered, the skill chooses video, MP3, subtitles, or information-only mode and saves downloads to ~/Downloads unless you set another directory.

The main README and troubleshooting guide are written in Chinese. There is no complete English README, though a few example commands use English. That makes the project a natural fit for Chinese-speaking agent users and a harder maintenance choice for an English-only team. The code is less mysterious than the language boundary: Python scripts sit behind a concise skill entry point, and the README names each system dependency.

Public extraction gets one cookie fallback, then stops

The default policy tries a URL without cookies first. If that fails, the skill may read an existing Chrome, Edge, Firefox, or Safari session from the local machine. It does not print, copy, or save cookie contents, and --cookies-from-browser none disables the fallback. For sites prone to account checks, the agent tells the user that it is parsing the link and leaves logins, captchas, and two-factor prompts to the user.

This restraint matters because the support table is not a guarantee. YouTube, Bilibili, X, TikTok, Instagram, Twitch, and other entries depend largely on the installed yt-dlp extractor. Sites change their pages and APIs. The README promises a dynamic probe, one browser-cookie fallback after public extraction fails, and a stop rather than repeated requests that could increase account risk.

What happened when we ran it

Our sandbox installed commit 8e92fb0 in 11 seconds, pulling 35 packages and using 37 MB on disk. The build completed in 2 seconds. Pytest then finished in 6 seconds with 43 passed and 0 failed of 43. Pip-audit reported 0 known vulnerabilities. The checkout held 42 files, about 2,421 lines of source, and occupied 6.7 MB.

We ran those checks in a fresh Debian container with 3 CPUs, 8 GB of RAM, Python 3.12, no secrets, and no elevated privileges. The repository has a tests directory, but our scan found 0 CI workflow files and no Dockerfile. This run verifies the Python package and tests. It does not prove that a particular site's current extractor works, that browser cookies are available, or that WeChat capture can operate in an unprivileged container.

A completed file must pass ffprobe, not just exit cleanly

The skill does not accept yt-dlp's zero exit code as the whole result. It checks that the file exists, has a nonzero size, contains the expected video or audio stream, and reports a valid duration. The completion response includes the container, codec, resolution, duration, and absolute path. Failed or interrupted work cleans only the new format fragments created by that task, leaving older files alone.

That is the strongest reason to install this layer instead of asking an agent to improvise a yt-dlp command. The skill also disables playlist expansion by default, avoids overwriting an existing file, and locks duplicate work. Each new task checks yt-dlp's official stable release and upgrades through the package manager that installed it. If an update fails, the previous version remains in place and the failure stage is reported.

WeChat capture can change certificate trust and the system proxy

WeChat Channels uses an adapter bundled with the skill, while local capture relies on a separately installed pinned backend. If a page must be opened or played, the user performs that action. The agent does not click, refresh, or operate the WeChat interface. Sending a public share URL to the fixed online parser requires explicit permission, and the policy excludes cookies, login state, device data, and captured traffic from that request.

The local route has a meaningful setup cost. First use may change certificate trust and the system proxy, each behind a separate explanation and authorization. The skill records the old proxy state and restores it after the task. That is better than making hidden machine changes, but it remains too invasive for a locked-down workstation. Review the pinned backend license too: the README says it uses MIT with a Commons Clause.

Spotify tracks are matched to YouTube audio

A Spotify URL supplies public track metadata. The adapter scores YouTube candidates using title, artist, duration, channel verification, popularity, and penalties for unwanted versions, then stops when confidence is low. The resulting file receives Spotify title, artist, and album tags, while the output identifies YouTube as the audio source. It does not read or decrypt Spotify's offline cache.

Only single open.spotify.com/track/... links take this automatic path. Albums and playlists are not expanded, which prevents one request from turning into an unbounded batch. If Spotify matching is the central need, spotDL covers a wider Spotify-shaped workflow. qiaomu-download earns its place when one agent must handle several media sites under the same safety and verification rules.

Version 1.3.0 is recent, but site compatibility remains live data

GitHub showed 378 stars, 60 forks, and 1 open issue on October 7, 2026. The last push and v1.3.0 release both landed on September 20. The open request asks for Threads video and image support, a feature the current trigger rules do not claim. There are no open pull requests in the fetched issue list.

The repository is young and actively packaged, with a clean 43-test run on our box. Its value lies in the behavior around yt-dlp: bounded triggers, public-first access, a single cookie fallback, file validation, and explicit consent for the invasive WeChat path. If those policies match your work and Chinese documentation is comfortable, it is an easy trial. Otherwise, direct tools have fewer layers to maintain.

Alternatives

ProjectWhat it isPick it when
yt-dlp gh↗The command-line media downloader that handles most of this skill's general site extraction.pick this instead when you are comfortable with flags and do not need agent routing or ffprobe-based completion rules.
spotDLA tool that uses Spotify metadata to find and download matching audio from YouTube Music.pick this instead when Spotify track, album, and playlist matching is the main job.
wx_channels_download gh↗A focused local downloader for WeChat Channels media.pick this instead when WeChat Channels is your only target and you want the upstream tool directly.

What people are saying

  1. [velocity-scout] joeseesun/qiaomu-download

Sources

  1. qiaomu-download README
  2. qiaomu-download repository
  3. qiaomu-download v1.3.0 release
  4. Threads support request

More automation reviews

third-hand · Jev-cu · jev-browser-use · herdr-projects · repopilot · mobile-jev · the whole board →