Back to skill

Security audit

Kuaipu Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated Kuaipu automation purpose, but it needs Review because it stores sensitive login/session/page data locally and performs automatic dependency or driver downloads.

Install only after reviewing whether you are comfortable giving this skill Kuaipu credentials and letting it create local session, HTML, and screenshot artifacts. Use a least-privileged Kuaipu account, avoid running it as an administrator, keep the .env and tmp directory private, delete artifacts after use, and prefer pinned dependencies and a pre-provisioned Chrome driver before running it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
kuaipu_skill.py:519
Finding

Unsafe Deserialization of Browser Session Cookies

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
kuaipu-skill.sh:57
Finding

Automatic Installation of Unpinned Runtime Dependencies

Content
View full analysis
/dev/null; then echo "正在安装 selenium..." if command -v uv &> /dev/null; then uv pip install selenium else pip3 install selenium fi fi # 检查 webdriver_manager if ! python3 -c "import webdriver_manager" 2>/dev/null; then echo "正在安装 webdriver_manager..." if command -v uv &> /dev/null; then uv pip install webdriver_manager else pip3 install webdriver_manager fi fi # 检查 ddddocr if ! python3 -c "import ddddocr" 2>/dev/null; then echo "正在安装 ddddocr..." if command -v uv &> /dev/null; then uv pip install ddddocr else pip3 install ddddocr fi fi ``` ### Technical Analysis The launcher automatically downloads and installs dependencies whenever an import check fails. No exact versions or artifact hashes are supplied, so dependency resolution relies on mutable package-index state and the user's current pip or uv configuration. This behavior conflicts with the documentation, which recommends exact versions for these packages. It also turns an ordinary Skill invocation into a software-installation operation without a separate, explicit setup step. Python packages can execute code during installation and later during import. If an upstream project, package-index account, configured mirror, or dependency in the transitive dependency graph is compromised, the launcher can install and execute attacker-controlled code. ### Attack Path 1. One or more required modules are absent from the active Python environment. 2. A victim invokes `kuaipu-skill.sh`. 3. The launcher calls `uv pip install` or `pip3 install` without a version or hash constraint. 4. The resolver contacts the configured package index or mirror and selects the currently available release and its tra ...[truncated 900 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
kuaipu_skill.py:431
Finding

Insufficient Protection of Authenticated Session and Page Artifacts

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

uv pip install selenium==4.41.0 webdriver-manager==4.0.2 ddddocr==1.5.2

配置环境变量

cp .env.example .env

编辑 .env 文件,填写快普系统登录信息

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

uv pip install selenium==4.41.0 webdriver-manager==4.0.2 ddddocr==1.5.2

配置环境变量

cp .env.example .env

编辑 .env 文件,填写快普系统登录信息

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · kuaipu_skill.py (reported line 15)May include surrounding context.

python
# import ddddocr

# 配置文件
CONFIG_FILE = os.path.join(os.path.dirname(__file__), ".env")

# 是否启用详细日志(调试用)
VERBOSE = os.getenv("KUAIPU_VERBOSE", "0") == "1"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes capabilities that read environment variables and save screenshots/HTML locally, but it does not declare any explicit tool scope such as permissions or allowed-tools. That mismatch weakens transparency and least-privilege controls, making it easier for a consumer to invoke a skill that accesses credentials or writes sensitive artifacts without clear upfront disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly states that screenshots and HTML are saved during automated operation, but it does not prominently warn that those artifacts may capture sensitive business data, session identifiers, internal workflow content, or personal information. In a login-and-approval automation context, local artifacts can become a secondary leakage channel even if the primary automation is functioning as intended.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

The installation instructions use npx skills add chldong/kuaipu-skill without pinning a specific version or immutable reference. This creates a supply-chain risk because a later upstream change, compromise, or typo-resolved package behavior could cause users to install different code than expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to store login credentials in a .env file but does not give an explicit security warning about plaintext credential handling, file permissions, secret rotation, or exclusion from source control. Because this skill automates access to a business approval system, compromised local credentials could enable unauthorized access to sensitive workflows and records.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script automatically installs Python packages from external repositories at runtime via uv or pip3 before performing its login automation. This creates a supply-chain and integrity risk because executing network-fetched code is not necessary for a wrapper script unless dependencies are pinned, verified, and explicitly approved by the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script makes system changes by installing packages and then executes a secondary Python script without giving the user a clear upfront warning or requiring consent. In an agent skill context, this is more dangerous because users may expect a benign helper, but the wrapper can alter the environment and run additional code paths automatically.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill persistently stores authenticated session cookies plus screenshots and HTML artifacts that are not clearly disclosed by the stated purpose. Those artifacts can contain sensitive business data, account context, and reusable session state, increasing the risk of credential theft or privacy leakage from local disk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The fallback to webdriver_manager introduces network-based download and execution of a browser driver at runtime, expanding the trust boundary beyond the declared business-login function. This increases supply-chain and environment-manipulation risk, especially in restricted or high-trust agent environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Serializing authenticated session cookies to disk without clear disclosure creates a reusable local credential artifact. If an attacker obtains the cookie file, they may be able to hijack the logged-in session and access the target system without knowing the password.

Content

No source excerpt is available for this finding.

Insecure deserialization: pickle.load()

Medium
Category
Dangerous Code Execution
Confidence
97% confidence
Finding

The code deserializes cookies from a local .pkl file using pickle.load(), which can execute arbitrary Python code if that file is replaced or tampered with. Because the file lives in a predictable tmp path and is later trusted without integrity checks, an attacker with local write access or a supply-chain foothold could turn this into code execution.

Content

Scanner excerpt · kuaipu_skill.py (reported line 520)May include surrounding context.

python
# 加载 cookies
        print("正在加载登录状态...")
        with open(COOKIE_FILE, "rb") as f:
            cookies = pickle.load(f)

        for cookie in cookies:
            driver.add_cookie(cookie)

Insecure deserialization: pickle.load()

Medium
Category
Dangerous Code Execution
Confidence
97% confidence
Finding

This is a second unsafe deserialization path for the same cookie file, again using pickle.load() on attacker-modifiable local data. Any compromise of the cookie file can lead to arbitrary code execution before Selenium even applies the cookies.

Content

Scanner excerpt · kuaipu_skill.py (reported line 617)May include surrounding context.

python
try:
                with open(COOKIE_FILE, "rb") as f:
                    cookies = pickle.load(f)

                driver.delete_all_cookies()
                for cookie in cookies:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code writes approval-page HTML to local storage without warning, and approval workflows commonly contain names, business subjects, timestamps, and potentially confidential operational data. Silent persistence of such artifacts creates unnecessary exposure if the host is shared, backed up, or later compromised.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The approval-query logic performs broad discovery over links, containers, iframes, and several guessed paths instead of restricting itself to a known approval endpoint. In a hostile or unexpected web app context, this can over-collect sensitive data and trigger unintended navigation or actions outside the stated scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill always saves approval-center screenshots and HTML after navigation, regardless of whether debugging is enabled or the user agreed. These files can capture sensitive business records, workflow metadata, and personal information that should not be silently retained.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's comments and especially its user-visible echo output are written only in Chinese, with no option to choose locale or language. This can violate language/locale policy when a skill imposes one language on all users without documented justification or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script presents all user-facing prompts and status messages in Chinese, effectively forcing a language/locale without opt-in. The file does not document that this is intentionally restricted to a Chinese-speaking or region-specific environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.