T09 · Insecure Skill Coding Practices
- Location
SKILL.md:117- Finding
Unsafe Cookie Injection Through Dynamically Evaluated JavaScript
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 117–123
Vulnerability Type: Authentication cookie exposure and JavaScript injection
Risk Level: MediumVulnerable Code
javascript // If QR-code login must be bypassed, cookie injection may be attempted: browser(action="act", request={ "kind": "evaluate", "fn": "document.cookie='<cookie string>'" })Technical Analysis
The Skill recommends interpolating a cookie string directly into JavaScript passed to the browser's
evaluateoperation. No escaping, validation, or structured cookie API is used.If an Agent replaces the placeholder with attacker-controlled content containing a single quote, the value can terminate the
document.cookieassignment and append arbitrary JavaScript. For example, a malicious value could conceptually close the string, execute an additional expression, and comment out the remaining syntax. The injected expression would execute in the context of the currently open Baijiahao page and with access to resources available to page-context JavaScript.This workflow also requires authentication material to pass through Agent and browser-tool arguments. Such values may consequently be retained in conversation history, diagnostic output, or tool logs. Cookies that are marked
HttpOnlycannot be set or read throughdocument.cookie, making this fallback both unsafe and potentially ineffective for important authentication cookies.Attack Path
- An attacker persuades a user or Agent to use the documented cookie-based login fallback.
- The attacker supplies a crafted cookie string containing a quote and additional JavaScript.
- The Agent substitutes that value into the
fnstring without escaping it. - The browser executes the resulting expression through the
evaluateaction. - The appended JavaScript runs in the open Baijiahao page context.
- Depending on the page's exposed state and browser ...[truncated 950 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the cookie-injection fallback and require the documented interactive QR-code login process.
- If cookie import is operationally necessary, use a dedicated browser cookie API rather than constructing JavaScript for
evaluate. - Validate cookie attributes using a strict allowlist:
- Permit only expected cookie names.
- Require the exact Baijiahao/Baidu domain and an appropriate path.
- Reject control characters, quotes, semicolons in values where unsupported, and unexpected attributes.
- Enforce
Secureand suitableSameSitesettings.
- Pass cookie names and values as structured data; never concatenate them into executable code.
- Mark cookie values as secrets and redact them from conversation transcripts, tool output, telemetry, and error logs.
- Avoid accepting cookies from untrusted users or third-party content.
- Use short-lived credentials and revoke or rotate any cookie that may already have been disclosed through this workflow.
- Add a mandatory user confirmation before importing authentication material or performing account-level publishing actions.
