Back to skill

Security audit

baijiahao-publisher

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its publishing purpose, but it includes an unsafe cookie-injection login fallback that handles session credentials without adequate safeguards.

Review before installing. Use only the normal QR-code login flow under the account owner's control, do not paste cookies or session strings into the agent, and confirm the exact article, cover image, account, and publish action before letting it post live content.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:117
Finding

Unsafe Cookie Injection Through Dynamically Evaluated JavaScript

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 117–123
Vulnerability Type: Authentication cookie exposure and JavaScript injection
Risk Level: Medium

Vulnerable Code

javascript
// If QR-code login must be bypassed, cookie injection may be attempted:
browser(action="act", request={
  "kind": "evaluate",
  "fn": "document.cookie='<cookie string>'"
})

Technical Analysis

The Skill recommends interpolating a cookie string directly into JavaScript passed to the browser's evaluate operation. No escaping, validation, or structured cookie API is used.

If an Agent replaces the placeholder with attacker-controlled content containing a single quote, the value can terminate the document.cookie assignment and append arbitrary JavaScript. For example, a malicious value could conceptually close the string, execute an additional expression, and comment out the remaining syntax. The injected expression would execute in the context of the currently open Baijiahao page and with access to resources available to page-context JavaScript.

This workflow also requires authentication material to pass through Agent and browser-tool arguments. Such values may consequently be retained in conversation history, diagnostic output, or tool logs. Cookies that are marked HttpOnly cannot be set or read through document.cookie, making this fallback both unsafe and potentially ineffective for important authentication cookies.

Attack Path

  1. An attacker persuades a user or Agent to use the documented cookie-based login fallback.
  2. The attacker supplies a crafted cookie string containing a quote and additional JavaScript.
  3. The Agent substitutes that value into the fn string without escaping it.
  4. The browser executes the resulting expression through the evaluate action.
  5. The appended JavaScript runs in the open Baijiahao page context.
  6. Depending on the page's exposed state and browser ...[truncated 950 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the cookie-injection fallback and require the documented interactive QR-code login process.
  2. If cookie import is operationally necessary, use a dedicated browser cookie API rather than constructing JavaScript for evaluate.
  3. Validate cookie attributes using a strict allowlist:
    • Permit only expected cookie names.
    • Require the exact Baijiahao/Baidu domain and an appropriate path.
    • Reject control characters, quotes, semicolons in values where unsupported, and unexpected attributes.
    • Enforce Secure and suitable SameSite settings.
  4. Pass cookie names and values as structured data; never concatenate them into executable code.
  5. Mark cookie values as secrets and redact them from conversation transcripts, tool output, telemetry, and error logs.
  6. Avoid accepting cookies from untrusted users or third-party content.
  7. Use short-lived credentials and revoke or rotate any cookie that may already have been disclosed through this workflow.
  8. Add a mandatory user confirmation before importing authentication material or performing account-level publishing actions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The cookie-injection fallback handles authentication material but provides no warning about the sensitivity of cookie strings or the risks of importing active sessions into the browser. Users may expose session tokens, reuse stolen cookies, or unintentionally persist credentials in the automation environment, leading to account compromise.

Content

No source excerpt is available for this finding.

Ssd 1

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Suggesting document.cookie='<cookie string>' as a way to bypass login is a direct session-bypass technique. In this context, the skill is for publishing to a real user account, so enabling alternate authentication through arbitrary cookie material materially increases abuse potential and lowers the barrier to unauthorized account actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill automates submission of content and instructs copying a local image into a fixed upload path, but it does not clearly warn users that it will perform a real publish action and manipulate local files. This can lead to unintended publication, confusion about data handling, and accidental exposure of local content when users invoke the skill without understanding these side effects.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly documents a fallback to inject arbitrary cookies into the browser session to bypass interactive login. That expands the skill from normal user-assisted publishing into session/credential manipulation, which can enable unauthorized account access or use of stolen session material if an operator supplies cookies from another context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest declares a fixed language value in natural-language metadata without indicating that users can choose another language or opt in to this constraint. This can violate language/locale policy when a skill is forced into a specific language context by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.