T09 · Insecure Skill Coding Practices
- Location
SKILL.md:20- Finding
Authenticated Chrome Profile Exposed Through Persistent Remote Debugging Configuration
- Content
View full analysis
~/bin/google-chrome << 'EOF' #!/bin/bash exec /usr/bin/google-chrome --remote-debugging-port=9222 "$@" EOF chmod +x ~/bin/google-chrome echo 'export PATH="$HOME/bin:$PATH"' >> ~/.bashrc export PATH="$HOME/bin:$PATH" ``` From `SKILL.md:35-40`: ```bash DISPLAY=:0 google-chrome \ --remote-debugging-port=9222 \ --user-data-dir=$HOME/.config/google-chrome/Default \ --new-window \ --no-sandbox \ > /tmp/chrome-debug.log 2>&1 & ``` From `scripts/start-chrome-debug.sh:15-21`: ```bash google-chrome \ --remote-debugging-port=9222 \ --user-data-dir=$HOME/.config/google-chrome/Default \ --new-window \ --no-sandbox \ > /tmp/chrome-debug.log 2>&1 & ``` ### Technical Analysis The setup instructions create a persistent wrapper named `google-chrome` and prepend its directory to `PATH` through `.bashrc`. Consequently, future calls to `google-chrome` automatically enable the Chrome DevTools Protocol on port 9222, even when remote debugging is unrelated to the current task. The debug instance is launched against the user's normal Chrome profile, which may contain authenticated sessions, browsing data, and access to sensitive account pages. A process capable of connecting to the DevTools endpoint can remotely control tabs, execute JavaScript in page contexts, inspect network activity, and interact with authenticated websites. The browser is also started with `--no-sandbox`. This disables an important isolation boundary and increases the potential impact of a browser or renderer compromise caused by hostile web content. ### Attack Path 1. The user follows the documented setup and creates the `~/bin/google-chrome` wra ...[truncated 1233 chars]- Remediation
View remediation
