T09 · Insecure Skill Coding Practices
- Location
scripts/collect_jisilu_cb.py:52- Finding
Reusable authentication cookies stored in a plaintext file without access-control hardening
- Content
View full analysis
Vulnerability Details
File Location:
scripts/collect_jisilu_cb.py:52-61
Vulnerability Type: Plaintext storage of reusable session credentials
Risk Level: Highpython COOKIE_PATH.parent.mkdir(parents=True, exist_ok=True) with open(COOKIE_PATH, "w", encoding="utf-8") as f: json.dump({ "kbzw__user_login": cookie_val, "kbzw__Session": session_val, "updated_at": datetime.now().strftime("%Y-%m-%d %H:%M:%S") }, f, ensure_ascii=False, indent=2) print(f"Cookie 已保存至: {COOKIE_PATH}") return cookie_val, session_valTechnical Analysis
The Skill stores the reusable
kbzw__user_loginandkbzw__Sessionauthentication cookies directly inreferences/cookie.jsonas plaintext. The file is created using the process's default permissions, which are controlled by the ambientumask; the code does not explicitly restrict access to the owning user. It also does not verify the ownership or permissions of an existing credential file before reading it.These cookies represent an authenticated Jisilu browser session. Any process or local user able to read the file can copy and replay the complete credentials. The risk also extends to backups, archives, accidental repository commits, and copies of the entire Skill directory.
Attack Path
- A user runs the collection script and enters valid Jisilu authentication cookies.
- The script creates
references/cookie.jsonusing default filesystem permissions. - An attacker, another local account, an overprivileged process, a backup service, or a recipient of an accidentally shared Skill archive obtains read access to the file.
- The attacker extracts
kbzw__user_loginandkbzw__Session. - The attacker supplies both cookies in requests to Jisilu and replays the authenticated session until the cookies expire or are revoked.
Impact Assessment
Successful exploitation exposes the complete reusable session credentials ...[truncated 362 chars]
- Remediation
View remediation
Remediation Suggestions
- Prefer an operating-system keyring, agent secret store, or another credential manager instead of a plaintext JSON file.
- If file storage is unavoidable, create the file atomically with owner-only mode
0600; do not rely on the ambientumask. - Verify that the credential file is a regular file, is owned by the expected user, and is not accessible by group or other users before reading it.
- Store credentials outside the distributable Skill directory to reduce the risk of accidental packaging or sharing.
- Add
references/cookie.jsonto ignore and packaging-exclusion rules. - Document how users can revoke the Jisilu session and securely delete or rotate stored cookies.
- Avoid following attacker-controlled symbolic links when creating or replacing the credential file.
