T09 · Insecure Skill Coding Practices
- Location
scripts/collect_jisilu_cb.py:50- Finding
Jisilu Session Cookie Stored and Logged Insecurely
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to do its stated Jisilu data-collection job, but it asks for and stores a live login cookie in plaintext, so users should review the credential risk before installing.
Install only if you are comfortable giving the skill access to a live Jisilu session cookie. Treat kbzw__user_login like a password, avoid pasting it into shared chats, restrict access to references/cookie.json, delete or rotate the cookie if exposed, and be cautious with the optional cron log because the script prints part of the cookie.
scripts/collect_jisilu_cb.py:50Jisilu Session Cookie Stored and Logged Insecurely
README.md:21Third-Party Dependencies Are Installed Without Version or Integrity Pinning
The skill directs the agent to collect a live session cookie from the user and persist it for future reuse in a local JSON file. Persisting reusable session material substantially increases exposure: another local process, a malicious skill, backups, sync tools, or accidental disclosure can reuse the cookie to access the account until it expires or is revoked.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# crontab -e
# 每天 15:30 执行
30 15 * * * cd ~/.config/agents/skills/jisilu-cb-daily && python scripts/collect_jisilu_cb.py >> output/cron.log 2>&1
The README explicitly instructs users to extract a live login cookie (kbzw__user_login) from their browser and provide it to the skill or store it locally, but does not warn that this cookie is effectively a session credential. If the cookie file, logs, backups, or terminal history are exposed, an attacker may be able to hijack the user's session and access account-scoped data or actions on Jisilu.
The skill performs network access and reads/writes local files, but it declares no explicit tool scope or permission boundaries. In agent environments, missing scope declarations can cause overbroad execution privileges, making it harder to enforce least privilege or review what the skill is allowed to do.
The skill asks the user to provide a live login cookie and store it locally, but it does not clearly warn that this cookie is an authentication secret equivalent to account access. Users may disclose it casually, and any local compromise, logs, backups, or unintended file exposure could let an attacker hijack the user's Jisilu session.
The script stores an authentication cookie to a local JSON file in plaintext, and while it does tell the user where it is saved, it does not present a meaningful security warning about the sensitivity of that credential or the risks of local persistence. If another local user, process, backup system, or repository sync accesses that file, the cookie could be reused to impersonate the user’s authenticated session on Jisilu.
The natural-language strings in the module description and runtime prompts are exclusively in Chinese, which effectively fixes the interaction language without user opt-in or alternative locale handling. Under the policy, forcing a specific language without offering a choice can be a locale-policy violation unless clearly justified.
No suspicious patterns detected.