T09 · Insecure Skill Coding Practices
- Location
zhihu-fetch.py:49- Finding
Authenticated Zhihu Cookie May Be Exposed Through Redirect Following
- Content
View full analysis
str: if not COOKIE_FILE.exists(): sys.exit(f"Cookie file not found: {COOKIE_FILE}") return COOKIE_FILE.read_text().strip() def curl_json(url: str, cookie: str) -> dict: r = subprocess.run( ["curl", "-sL", "-A", UA, "-H", f"Cookie: {cookie}", url], capture_output=True, text=True, timeout=30 ) try: return json.loads(r.stdout) except json.JSONDecodeError as e: sys.exit(f"Invalid JSON response: {e}") def curl_text(url: str, cookie: str, timeout: int = 30) -> str: r = subprocess.run( ["curl", "-sL", "-A", UA, "-H", f"Cookie: {cookie}", url], capture_output=True, text=True, timeout=timeout ) return r.stdout ``` ### Technical Analysis The Skill loads the complete authenticated Zhihu cookie string and manually adds it as an HTTP `Cookie` header. The `-L` option instructs curl to follow redirects. All initial request URLs are internally constructed from fixed HTTPS Zhihu endpoints. Therefore, the behavior is directly related to the declared functionality, and no intentional third-party exfiltration destination was identified. However, the code does not independently validate the destination of each redirect or restrict redirects to an explicit host allowlist. Security consequently depends on curl's version-specific handling of sensitive custom headers during cross-origin redirects. This is unsafe for a credential capable of representing the user's authenticated Zhihu session. ### Attack Path 1. The user places an authenticated Zhihu cookie in the configured cookie file. 2. The Skill calls a fixed Zhihu API or article endpoint. 3. The endpoint, a compromised upstream component, or another network-layer condition returns an HTTP redirect. 4. Curl f ...[truncated 722 chars]- Remediation
View remediation
