T09 · Insecure Skill Coding Practices
- Location
scripts/cookie-parser.ts:212- Finding
Authentication Cookies Exposed Through Process Command-Line Arguments
- Content
View full analysis
[domain]"); ``` The documented invocation explicitly places the complete cookie value in a command-line argument: ```text npx tsx scripts/cookie-parser.ts '' '' ``` ### Technical Analysis Social-platform cookies are bearer credentials: possession can be sufficient to impersonate the authenticated user. The parser accepts the complete cookie string through `process.argv[2]`. Command-line arguments are not an appropriate secret-input channel. Depending on the operating system and execution environment, arguments may be exposed through: - Process inspection facilities such as `ps`, `/proc`, or process-monitoring tools. - Shell history when commands are entered interactively. - Agent, terminal, job-runner, or audit logs that record executed commands. - Parent-process telemetry and endpoint-monitoring products. - Error reports that capture process invocation details. Local AES-256-GCM encryption does not mitigate this exposure because it occurs before the cookie reaches the encrypted vault. ### Attack Path 1. A user provides a reusable social-platform cookie to SocialVault. 2. The documented workflow invokes `cookie-parser.ts` with the complete cookie as a command-line argument. 3. A local user, monitoring process, shell-history reader, or logging component captures the command line. 4. The observer extracts authentication values such as `SESSDATA`, `BDUSS`, `z_c0`, or `web_session`. 5. The observer submits the stolen cookie to the corresponding platform. 6. If the platform has not expired or otherwise bound the session, the ob ...[truncated 674 chars]- Remediation
View remediation
