Back to skill

Security audit

每日从集思录抓取可转债基本数据、强赎倒计时、下修倒计时,支持Cookie管理和本地持久化存储

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do its stated Jisilu data-collection job, but it asks for and stores a live login cookie in plaintext, so users should review the credential risk before installing.

Install only if you are comfortable giving the skill access to a live Jisilu session cookie. Treat kbzw__user_login like a password, avoid pasting it into shared chats, restrict access to references/cookie.json, delete or rotate the cookie if exposed, and be cautious with the optional cron log because the script prints part of the cookie.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/collect_jisilu_cb.py:50
Finding

Jisilu Session Cookie Stored and Logged Insecurely

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
README.md:21
Finding

Third-Party Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
pandas== ``` 2. Generate and verify cryptographic hashes, such as through a hash-locked requirements file installed with: ```bash python -m pip install --require-hashes -r requirements.txt ``` 3. Lock transitive dependencies as well as direct dependencies. 4. Run dependency vulnerability and license scans when updating the lock file. 5. Recommend installation inside a dedicated virtual environment rather than a shared or system Python environment. 6. Document a controlled update process so dependency upgrades are reviewed, tested, and deliberately released. 7. Explicitly warn users not to run installation or collection commands as root or administrator. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill directs the agent to collect a live session cookie from the user and persist it for future reuse in a local JSON file. Persisting reusable session material substantially increases exposure: another local process, a malicious skill, backups, sync tools, or accidental disclosure can reuse the cookie to access the account until it expires or is revoked.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 60)May include surrounding context.

方式3:定时任务(本地)

bash
# crontab -e
# 每天 15:30 执行
30 15 * * * cd ~/.config/agents/skills/jisilu-cb-daily && python scripts/collect_jisilu_cb.py >> output/cron.log 2>&1

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly instructs users to extract a live login cookie (kbzw__user_login) from their browser and provide it to the skill or store it locally, but does not warn that this cookie is effectively a session credential. If the cookie file, logs, backups, or terminal history are exposed, an attacker may be able to hijack the user's session and access account-scoped data or actions on Jisilu.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill performs network access and reads/writes local files, but it declares no explicit tool scope or permission boundaries. In agent environments, missing scope declarations can cause overbroad execution privileges, making it harder to enforce least privilege or review what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill asks the user to provide a live login cookie and store it locally, but it does not clearly warn that this cookie is an authentication secret equivalent to account access. Users may disclose it casually, and any local compromise, logs, backups, or unintended file exposure could let an attacker hijack the user's Jisilu session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script stores an authentication cookie to a local JSON file in plaintext, and while it does tell the user where it is saved, it does not present a meaningful security warning about the sensitivity of that credential or the risks of local persistence. If another local user, process, backup system, or repository sync accesses that file, the cookie could be reused to impersonate the user’s authenticated session on Jisilu.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language strings in the module description and runtime prompts are exclusively in Chinese, which effectively fixes the interaction language without user opt-in or alternative locale handling. Under the policy, forcing a specific language without offering a choice can be a locale-policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.