T08 · Insecure Dependencies
- Location
skill.md:22- Finding
Unpinned Third-Party CLI Can Access Browser Authentication Cookies
- Content
View full analysis
Vulnerability Details
File Location:
skill.md, lines 22-32
Vulnerability Type: Supply-chain risk from an unpinned third-party executable
Risk Level: MediumVulnerable Code
markdown - **Not logged in** → Prompt the user: > Log in to BOSS Zhipin first: > ```bash > boss login > ``` > This automatically reads browser cookies or displays a QR code for login. > Trigger this skill again after login. > If boss-cli is not installed, install it first: > ```bash > uv tool install kabi-boss-cli > ```The original instructions direct the user to install
kabi-boss-cliwithout pinning a version, validating a package hash, identifying a reviewed source revision, or performing any other integrity verification. The same workflow states that the resulting executable can automatically read browser cookies.Technical Analysis
Installing a package by its mutable registry name delegates trust to the package registry, publisher account, dependency resolution process, and latest available release. The project contains only
skill.md; it does not include the CLI implementation or a lockfile, so the installed code and its transitive dependencies cannot be audited from this artifact.This creates a supply-chain exposure because a compromised publisher account, malicious future release, dependency-confusion event, or compromised transitive dependency could execute arbitrary code under the user's account. The risk is elevated by the documented authentication workflow: the executable may access browser-held BOSS session cookies, which are sensitive bearer credentials.
This finding does not establish that
kabi-boss-cliis currently malicious. It identifies the unsafe installation and trust model documented by the skill.Attack Path
- An attacker compromises the package publisher, registry distribution path, or one of the package's dependencies and publishes a malicious versi ...[truncated 1303 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
kabi-boss-clito a specific, security-reviewed version rather than installing the latest mutable release. - Require cryptographic hashes for the package and all resolved dependencies, using a lockfile or package-manager mode that enforces hash verification.
- Document the canonical source repository, package publisher, reviewed commit, and expected package signature or checksum.
- Audit the CLI and its transitive dependencies, particularly code that accesses browser profiles, cookie databases, process environments, and network destinations.
- Prefer QR-based or official OAuth-style authentication that does not require reading browser cookie stores.
- If cookie access is unavoidable, restrict it to the minimum required BOSS cookie data, obtain explicit user consent, avoid logging or persisting credentials, and document where authentication data is transmitted.
- Run the CLI with least privilege in an isolated environment, without administrator rights and without unnecessary access to unrelated files, credentials, or browser profiles.
- Establish an update-review process so that changing the pinned version requires renewed source and dependency inspection.
- Pin
