Back to skill

Security audit

每日从集思录抓取可转债基本数据、强赎倒计时、下修倒计时,支持Cookie管理和本地持久化存储

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to collect the promised Jisilu bond data, but it handles live login cookies in an unsafe way.

Install only if you are comfortable giving this skill reusable Jisilu login cookies. Treat those cookie values and any generated cookie.json or cron.log files like passwords, restrict file access, avoid pasting cookies into shared chats or logs, and revoke or refresh the Jisilu session after use. There is no evidence of hidden exfiltration or destructive behavior, but the credential handling should be reviewed carefully.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/collect_jisilu_cb.py:52
Finding

Reusable authentication cookies stored in a plaintext file without access-control hardening

Content
View full analysis

Vulnerability Details

File Location: scripts/collect_jisilu_cb.py:52-61
Vulnerability Type: Plaintext storage of reusable session credentials
Risk Level: High

python
COOKIE_PATH.parent.mkdir(parents=True, exist_ok=True)
with open(COOKIE_PATH, "w", encoding="utf-8") as f:
    json.dump({
        "kbzw__user_login": cookie_val,
        "kbzw__Session": session_val,
        "updated_at": datetime.now().strftime("%Y-%m-%d %H:%M:%S")
    }, f, ensure_ascii=False, indent=2)
print(f"Cookie 已保存至: {COOKIE_PATH}")
return cookie_val, session_val

Technical Analysis

The Skill stores the reusable kbzw__user_login and kbzw__Session authentication cookies directly in references/cookie.json as plaintext. The file is created using the process's default permissions, which are controlled by the ambient umask; the code does not explicitly restrict access to the owning user. It also does not verify the ownership or permissions of an existing credential file before reading it.

These cookies represent an authenticated Jisilu browser session. Any process or local user able to read the file can copy and replay the complete credentials. The risk also extends to backups, archives, accidental repository commits, and copies of the entire Skill directory.

Attack Path

  1. A user runs the collection script and enters valid Jisilu authentication cookies.
  2. The script creates references/cookie.json using default filesystem permissions.
  3. An attacker, another local account, an overprivileged process, a backup service, or a recipient of an accidentally shared Skill archive obtains read access to the file.
  4. The attacker extracts kbzw__user_login and kbzw__Session.
  5. The attacker supplies both cookies in requests to Jisilu and replays the authenticated session until the cookies expire or are revoked.

Impact Assessment

Successful exploitation exposes the complete reusable session credentials ...[truncated 362 chars]

Remediation
View remediation

Remediation Suggestions

  • Prefer an operating-system keyring, agent secret store, or another credential manager instead of a plaintext JSON file.
  • If file storage is unavoidable, create the file atomically with owner-only mode 0600; do not rely on the ambient umask.
  • Verify that the credential file is a regular file, is owned by the expected user, and is not accessible by group or other users before reading it.
  • Store credentials outside the distributable Skill directory to reduce the risk of accidental packaging or sharing.
  • Add references/cookie.json to ignore and packaging-exclusion rules.
  • Document how users can revoke the Jisilu session and securely delete or rotate stored cookies.
  • Avoid following attacker-controlled symbolic links when creating or replacing the credential file.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/collect_jisilu_cb.py:209
Finding

Authentication-cookie prefixes disclosed through console and scheduled-task logs

Content
View full analysis

Vulnerability Details

File Location: scripts/collect_jisilu_cb.py:209-210
Vulnerability Type: Partial secret disclosure in application logs
Risk Level: Low

python
print(f"  kbzw__user_login 加载成功 (前10位: {cookie_login[:10]}...)")
print(f"  kbzw__Session 加载成功 (前10位: {cookie_session[:10]}...)\n")

Technical Analysis

After loading the authentication cookies, the script prints the first ten characters of each value to standard output. Authentication credentials should be treated as opaque secrets and should never be printed, even partially.

The documented cron command redirects standard output and standard error to output/cron.log, causing these prefixes to persist across scheduled runs. Partial values may assist credential correlation, reveal formatting or identifier information, and increase exposure if logs are shared for troubleshooting. The disclosed prefixes are not demonstrated to be sufficient for authenticating on their own, so the severity is lower than disclosure of the complete cookie file.

Attack Path

  1. The user runs the script directly or configures the documented cron command with output redirected to output/cron.log.
  2. On every run, the script writes the first ten characters of both authentication cookies to standard output.
  3. Under cron, these partial secrets are appended to the persistent log file.
  4. A person or process with access to terminal history, captured job output, support bundles, or the cron log obtains the prefixes.
  5. The exposed values may be used to correlate sessions or supplement credentials obtained from another source. The audited code does not establish that the prefixes alone permit session replay.

Impact Assessment

Exploitation exposes ten-character prefixes of two reusable authentication cookies. This is a confidentiality breach and unnecessarily expands the number of locations containing credential material. It does not independently establis ...[truncated 172 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove both cookie-value slices from the log messages.
  • Log only a non-sensitive confirmation such as Authentication cookies loaded successfully.
  • Treat existing output/cron.log files as potentially sensitive and delete or securely rotate them after fixing the script.
  • Apply owner-only permissions to scheduled-task logs and configure rotation with a limited retention period.
  • Ensure troubleshooting instructions prohibit sharing credential files or unredacted logs.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly asks the user to paste active authentication cookies into the chat and promises to save them for future reuse. Collecting bearer tokens through conversational input is high risk because chat logs, telemetry, prompt history, or downstream tooling may retain them, and reuse of those cookies could grant unauthorized access to the user's account.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill asks the user to supply live authentication cookies directly to the tool and optionally persist them in a local JSON file, which creates a credential-handling pathway outside the browser's protected session store. In the context of an agent skill, this is more dangerous because users may paste cookies into conversational interfaces, logs, or automation environments where secrets can be retained, leaked, or reused by other processes.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 54)May include surrounding context.

方式3:定时任务(本地)

bash
# crontab -e
# 每天 15:30 执行
30 15 * * * cd ~/.config/agents/skills/jisilu-cb-daily && python scripts/collect_jisilu_cb.py >> output/cron.log 2>&1

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly instructs users to extract active login session cookies from their browser and provide them to the skill, but it does not clearly warn that these values are equivalent to account credentials. Anyone who obtains these cookies can potentially impersonate the user on the target site until the session expires or is revoked, making accidental disclosure or mishandling a meaningful security risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill clearly performs network access and local file read/write, including persistence of authentication material, but declares no explicit tool scope or permission boundaries. In an agent environment, missing scope increases the chance that the skill is granted broader capabilities than necessary, making misuse or accidental overreach harder to detect and constrain.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs storing live login cookies in a local JSON file without any warning about their sensitivity, access controls, or theft risk. Session cookies are bearer credentials; if the file is exposed through local compromise, backups, sync tools, or other skills, an attacker may be able to hijack the user's authenticated session.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill metadata and all user-facing instructions are presented only in Chinese, and the example invocation at the end is likewise Chinese-only. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file-level description and all user-facing prompts/logs are written in Chinese, which effectively fixes the interaction language for the skill. Under the policy, locale or language constraints should either be optional for the user or clearly justified as region-specific tooling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.