Back to skill

Security audit

SocialVault

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent social-account credential vault, but it handles live account cookies through unsafe paste and command-line workflows and grants persistent account-use authority that users should review carefully.

Install only if you are comfortable giving this skill active social-platform session cookies that may let it act as your account. Prefer a dedicated, low-risk account, avoid pasting cookies into general chat or terminal commands, review scheduled tasks before enabling them, and be especially careful with long-lived or cross-service cookies such as BDUSS.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cookie-parser.ts:212
Finding

Authentication Cookies Exposed Through Process Command-Line Arguments

Content
View full analysis
[domain]"); ``` The documented invocation explicitly places the complete cookie value in a command-line argument: ```text npx tsx scripts/cookie-parser.ts '' '' ``` ### Technical Analysis Social-platform cookies are bearer credentials: possession can be sufficient to impersonate the authenticated user. The parser accepts the complete cookie string through `process.argv[2]`. Command-line arguments are not an appropriate secret-input channel. Depending on the operating system and execution environment, arguments may be exposed through: - Process inspection facilities such as `ps`, `/proc`, or process-monitoring tools. - Shell history when commands are entered interactively. - Agent, terminal, job-runner, or audit logs that record executed commands. - Parent-process telemetry and endpoint-monitoring products. - Error reports that capture process invocation details. Local AES-256-GCM encryption does not mitigate this exposure because it occurs before the cookie reaches the encrypted vault. ### Attack Path 1. A user provides a reusable social-platform cookie to SocialVault. 2. The documented workflow invokes `cookie-parser.ts` with the complete cookie as a command-line argument. 3. A local user, monitoring process, shell-history reader, or logging component captures the command line. 4. The observer extracts authentication values such as `SESSDATA`, `BDUSS`, `z_c0`, or `web_session`. 5. The observer submits the stolen cookie to the corresponding platform. 6. If the platform has not expired or otherwise bound the session, the ob ...[truncated 674 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/adapter-generator.ts:213
Finding

Path Traversal in Custom Adapter File Generation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:13
Finding

Non-Reproducible Dependency Installation Without a Lockfile

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (115)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The supplied code chunk does not act as a credential manager. Its primary purpose is generating and listing adapter documentation/configuration files in Markdown. It accepts platform metadata, auth method descriptions, session-check descriptions, and capability text, then writes these to adapter files after validating the endpoint domain. It also scans adapter directories and extracts platform IDs/names from existing files. While the declared description mentions adapter creation, the broader declared purpose centers on credential handling, encrypted storage, health monitoring, and automatic renewal, none of which are implemented in this code. Therefore the description materially overstates what this code chunk actually does, and the actual behavior is much narrower and configuration/documentation-oriented.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The supplied code is narrowly focused on cookie format detection and parsing. It converts user-provided cookie text into structured CookieEntry objects and reconstructs a raw header string. While this partially aligns with the declared 'importing cookies' aspect of the description, it does not implement credential storage, encryption, login-status checking, health monitoring, automatic refresh, adapter creation, or fingerprint management. Therefore the overall declared description materially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad credential/session management system with encrypted storage, monitoring, automatic renewal, cookie import, and adapter creation. The supplied code does not implement those core functions. Instead, it narrowly manages browser fingerprints: creating defaults, inferring locale/timezone from cookie domains, persisting fingerprint files, loading/deleting them, and emitting browser configuration commands. Browser fingerprint management is indeed mentioned in the description, but it is only one small subset. The primary behavior of this code chunk materially differs from the broader declared purpose, and an important declared security property—AES-256-GCM encrypted storage—is contradicted by plain JSON file writes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a broad credential-management system with encrypted storage, login checking, automatic refresh, adapter creation, and fingerprint management. The supplied code does not implement those core capabilities. Instead, it manages temporary QR login sessions by generating session IDs/tokens, persisting session metadata as JSON files, validating tokens, checking expiry, cleaning up files, and returning known login URLs. Although comments reference later encrypted storage of cookies by another component, this chunk itself neither encrypts credentials nor handles credential vault operations beyond plain session metadata files. Therefore the code's actual purpose is materially narrower and different from the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broader credential-management system with session acquisition, login checking, health monitoring, auto-renewal, adapter creation, and browser fingerprint management. The supplied code chunk is much narrower: it is specifically a local cryptographic vault module handling encrypted persistence and key rotation. AES-256-GCM encrypted storage is accurately represented, but most other declared capabilities are absent from this code. Creating a fingerprints directory alone does not constitute browser fingerprint management, and handling cookie/token fields in stored entries does not amount to importing cookies or refreshing sessions. Because the actual code’s primary behavior is encrypted storage rather than the wider operational account/session management described, this chunk does not accurately match the declared purpose.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
| `scripts/cookie-parser.ts` | 多格式 Cookie 解析 | `npx tsx scripts/cookie-parser.ts '<cookie-data>' '<domain>'` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
| `scripts/adapter-generator.ts` | 适配器自动生成 | `npx tsx scripts/adapter-generator.ts list` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 244)May include surrounding context.

md
| `scripts/adapter-generator.ts` | 适配器自动生成 | `npx tsx scripts/adapter-generator.ts list` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 267)May include surrounding context.

md
| `scripts/adapter-generator.ts` | 适配器自动生成 | `npx tsx scripts/adapter-generator.ts list` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 464)May include surrounding context.

md
| `scripts/adapter-generator.ts` | 适配器自动生成 | `npx tsx scripts/adapter-generator.ts list` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 452)May include surrounding context.

md
`session-verifier.ts` 内置**硬编码域名白名单**,仅允许向以下受信任域名发送认证头:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 465)May include surrounding context.

md
`session-verifier.ts` 内置**硬编码域名白名单**,仅允许向以下受信任域名发送认证头:

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide explicitly instructs users to export live Bilibili authentication cookies, including session and CSRF tokens, and paste them into an external agent, but it does not clearly warn that these values function as account bearer credentials. Anyone who obtains SESSDATA, bili_jct, and related cookies may be able to access or act on the user’s account, so treating them as ordinary copyable data is unsafe.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Directing users to copy and paste live session cookies and CSRF tokens into another service is a sensitive-secret disclosure pattern. In the context of a credential-management skill, this is especially dangerous because the transferred data can authenticate as the user, and plain-language paste workflows increase the chance of interception, logging, or misuse.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The tutorial repeatedly advises extracting complete cookie data from browser internals and handing it to another service, normalizing transfer of full authentication state outside the browser. This broadens the attack surface because the data may include all active cookies for the domain and can be accidentally stored in chat transcripts, clipboard managers, or support artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide explicitly instructs users to copy a long-lived Baidu authentication cookie from request headers and paste it into an external agent. BDUSS functions as a bearer credential for the account, so exposing it can enable account takeover without a password, and the document does not prominently warn users about the sensitivity, duration, or consequences of disclosure.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This workflow teaches users how to extract a long-lived authentication cookie and hand it to the agent in plain language. That is direct credential exfiltration guidance: anyone with the pasted value can often impersonate the user until the session expires or is revoked.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide recommends exporting STOKEN for write operations, which materially increases risk because it expands capability from read/status checks toward state-changing actions. Telling users to disclose that token to an agent without clear warnings or compensating controls exposes them to unauthorized posting or broader account abuse.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document tells users to use browser storage and console output to surface cookie contents and then share them with the agent. This normalizes exposing browser secrets through interfaces designed for debugging, increasing the chance of accidental leakage, clipboard compromise, logging exposure, or misuse by the receiving system.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The plugin workflow instructs users to export account cookies and paste the exported content into the agent, which is effectively bulk export of active session credentials. Even if framed as convenience, this creates a straightforward path for credential disclosure and replay by the system or anyone who gains access to the pasted data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The note states that BDUSS is shared across all Baidu products, which means compromise is not limited to Tieba and may affect multiple services tied to the same account. Presenting this as an operational convenience without a parallel warning understates the blast radius and can mislead users into disclosing a credential with cross-service impact.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide explicitly instructs users to copy live session cookies from request headers and paste them into the agent, which is direct handling of active authentication material. In this skill's context, that is especially dangerous because the product is designed to store and use platform credentials, so any insecure ingestion, transmission, logging, or abuse of those cookies could immediately enable unauthorized access to the social account.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide tells users to paste live Xiaohongshu cookies into the agent but does not clearly state that these cookies are equivalent to active session credentials and can allow account access without a password. In the context of a credential-management skill, this omission is dangerous because users may share highly sensitive tokens too casually, increasing the chance of account takeover if the agent, logs, clipboard, or storage path is compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide explicitly instructs users to export live Zhihu authentication cookies and paste them into an external agent, but does not warn that these values function as bearer credentials that can grant account access. In the context of a credential-management skill, this is especially dangerous because users may normalize sharing active session tokens without understanding the risk of session hijacking, replay, or unintended retention in logs or chat history.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document uses plain-language instructions to have users share active Zhihu authentication material with SocialVault, which directly facilitates disclosure of credentials to an external system. Even if the product is intended to manage credentials, normalizing credential pasting through documentation increases the chance of accidental exposure through clipboard history, screenshots, terminal/chat logs, or unauthorized access to the receiving system.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.