T09 · Insecure Skill Coding Practices
- Location
kuaipu_skill.py:519- Finding
Unsafe Deserialization of Browser Session Cookies
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its stated Kuaipu automation purpose, but it needs Review because it stores sensitive login/session/page data locally and performs automatic dependency or driver downloads.
Install only after reviewing whether you are comfortable giving this skill Kuaipu credentials and letting it create local session, HTML, and screenshot artifacts. Use a least-privileged Kuaipu account, avoid running it as an administrator, keep the .env and tmp directory private, delete artifacts after use, and prefer pinned dependencies and a pre-provisioned Chrome driver before running it.
kuaipu_skill.py:519Unsafe Deserialization of Browser Session Cookies
kuaipu-skill.sh:57Automatic Installation of Unpinned Runtime Dependencies
kuaipu_skill.py:431Insufficient Protection of Authenticated Session and Page Artifacts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
uv pip install selenium==4.41.0 webdriver-manager==4.0.2 ddddocr==1.5.2
cp .env.example .env
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
uv pip install selenium==4.41.0 webdriver-manager==4.0.2 ddddocr==1.5.2
cp .env.example .env
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# import ddddocr
# 配置文件
CONFIG_FILE = os.path.join(os.path.dirname(__file__), ".env")
# 是否启用详细日志(调试用)
VERBOSE = os.getenv("KUAIPU_VERBOSE", "0") == "1"
The skill describes capabilities that read environment variables and save screenshots/HTML locally, but it does not declare any explicit tool scope such as permissions or allowed-tools. That mismatch weakens transparency and least-privilege controls, making it easier for a consumer to invoke a skill that accesses credentials or writes sensitive artifacts without clear upfront disclosure.
The skill explicitly states that screenshots and HTML are saved during automated operation, but it does not prominently warn that those artifacts may capture sensitive business data, session identifiers, internal workflow content, or personal information. In a login-and-approval automation context, local artifacts can become a secondary leakage channel even if the primary automation is functioning as intended.
The installation instructions use npx skills add chldong/kuaipu-skill without pinning a specific version or immutable reference. This creates a supply-chain risk because a later upstream change, compromise, or typo-resolved package behavior could cause users to install different code than expected.
The skill instructs users to store login credentials in a .env file but does not give an explicit security warning about plaintext credential handling, file permissions, secret rotation, or exclusion from source control. Because this skill automates access to a business approval system, compromised local credentials could enable unauthorized access to sensitive workflows and records.
The script automatically installs Python packages from external repositories at runtime via uv or pip3 before performing its login automation. This creates a supply-chain and integrity risk because executing network-fetched code is not necessary for a wrapper script unless dependencies are pinned, verified, and explicitly approved by the user.
The script makes system changes by installing packages and then executes a secondary Python script without giving the user a clear upfront warning or requiring consent. In an agent skill context, this is more dangerous because users may expect a benign helper, but the wrapper can alter the environment and run additional code paths automatically.
The skill persistently stores authenticated session cookies plus screenshots and HTML artifacts that are not clearly disclosed by the stated purpose. Those artifacts can contain sensitive business data, account context, and reusable session state, increasing the risk of credential theft or privacy leakage from local disk.
The fallback to webdriver_manager introduces network-based download and execution of a browser driver at runtime, expanding the trust boundary beyond the declared business-login function. This increases supply-chain and environment-manipulation risk, especially in restricted or high-trust agent environments.
Serializing authenticated session cookies to disk without clear disclosure creates a reusable local credential artifact. If an attacker obtains the cookie file, they may be able to hijack the logged-in session and access the target system without knowing the password.
The code deserializes cookies from a local .pkl file using pickle.load(), which can execute arbitrary Python code if that file is replaced or tampered with. Because the file lives in a predictable tmp path and is later trusted without integrity checks, an attacker with local write access or a supply-chain foothold could turn this into code execution.
# 加载 cookies
print("正在加载登录状态...")
with open(COOKIE_FILE, "rb") as f:
cookies = pickle.load(f)
for cookie in cookies:
driver.add_cookie(cookie)
This is a second unsafe deserialization path for the same cookie file, again using pickle.load() on attacker-modifiable local data. Any compromise of the cookie file can lead to arbitrary code execution before Selenium even applies the cookies.
try:
with open(COOKIE_FILE, "rb") as f:
cookies = pickle.load(f)
driver.delete_all_cookies()
for cookie in cookies:
The code writes approval-page HTML to local storage without warning, and approval workflows commonly contain names, business subjects, timestamps, and potentially confidential operational data. Silent persistence of such artifacts creates unnecessary exposure if the host is shared, backed up, or later compromised.
The approval-query logic performs broad discovery over links, containers, iframes, and several guessed paths instead of restricting itself to a known approval endpoint. In a hostile or unexpected web app context, this can over-collect sensitive data and trigger unintended navigation or actions outside the stated scope.
The skill always saves approval-center screenshots and HTML after navigation, regardless of whether debugging is enabled or the user agreed. These files can capture sensitive business records, workflow metadata, and personal information that should not be silently retained.
The script's comments and especially its user-visible echo output are written only in Chinese, with no option to choose locale or language. This can violate language/locale policy when a skill imposes one language on all users without documented justification or opt-in.
The script presents all user-facing prompts and status messages in Chinese, effectively forcing a language/locale without opt-in. The file does not document that this is intentionally restricted to a Chinese-speaking or region-specific environment.
No suspicious patterns detected.