T09 · Insecure Skill Coding Practices
- Location
scripts/browser.py:92- Finding
Authentication Cookies Persisted in an Unprotected Plaintext File
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a real Fanqie Novel publishing helper, but it needs review because it stores login cookies insecurely and automates live account publishing with weak safeguards.
Review this before installing. Use it only in a trusted, isolated environment, expect it to store reusable login cookies locally, and prefer draft mode until you verify target work and chapter details. Clear the cookie file after use and avoid running it with elevated privileges.
scripts/browser.py:92Authentication Cookies Persisted in an Unprotected Plaintext File
scripts/browser.py:41Chromium Security Sandbox Explicitly Disabled
scripts/requirements.txt:1Unnecessary Browser Credential-Access Dependency
scripts/publisher.py:366Publication and Draft Operations Report Success Without Definitive Verification
This duplicate finding flags the same issue: the subprocess is launched via the shell for a simple clipboard utility. In security-sensitive automation, unnecessary shell usage is a real hardening weakness even when immediate exploitability is limited.
elif system == "Windows":
# Windows 使用 clip 命令,需要 utf-16le 编码
proc = subprocess.Popen(['clip'], stdin=subprocess.PIPE, shell=True)
proc.communicate(text.encode('utf-16le'))
return True
This duplicate finding flags the same issue: the subprocess is launched via the shell for a simple clipboard utility. In security-sensitive automation, unnecessary shell usage is a real hardening weakness even when immediate exploitability is limited.
elif system == "Windows":
# Windows 使用 clip 命令,需要 utf-16le 编码
proc = subprocess.Popen(['clip'], stdin=subprocess.PIPE, shell=True)
proc.communicate(text.encode('utf-16le'))
return True
The skill exposes capabilities consistent with file access, shell execution, and networked browser automation, but it does not declare any tool scope or permission boundaries. In a skill that logs into a writer backend and publishes content, this omission prevents meaningful consent and review, increasing the chance of unintended file access, command execution, or automated actions against external services.
The trigger phrases include broad terms such as '发布章节' and '存入草稿箱', which can plausibly appear in normal conversation unrelated to this specific skill. Because this skill performs high-impact actions like login and automated publication, accidental invocation could lead to unintended automation against a live account.
The documentation describes automated login, chapter submission, and batch publishing, but does not clearly warn users about operational risks such as publishing to the wrong work, unintended live publication, account/session handling, or platform policy consequences. In this context, missing risk disclosure is dangerous because the skill interacts with a real publisher backend and can rapidly make irreversible external changes.
The code injects an anti-detection script to hide navigator.webdriver and launches Chromium with automation-evasion flags such as --disable-blink-features=AutomationControlled. For a chapter-publishing tool, this is not necessary for core functionality and instead enables stealthy automation that can bypass platform bot-detection controls, increasing the risk of terms-of-service evasion or abusive automated account activity.
The tool saves browser cookies directly to a local JSON file, which can persist authenticated session data and allow account reuse by anyone with filesystem access. In the context of an author-platform publishing tool, these cookies may grant access to the writer backend, drafts, and publishing functions without requiring the user to log in again.
The module docstring names the skill in Chinese, and the file also hard-codes Chinese UI text elsewhere, indicating the skill is designed around a single language/locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The selectors rely on Chinese text such as '登录', '工作台', '创建章节', '章节管理', and '定时发布', which constrains the skill to one language environment. The file does not provide any user choice or documented justification for this locale restriction.
The module title and all user-facing prompts are written in Chinese, including operational instructions such as login guidance. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.
This code presents the workflow description and user-facing interaction model in a single fixed language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not shown here.
The manifest describes browser-based publishing, drafting, login, and viewing works on 番茄小说. This file additionally imports subprocess and later uses platform-specific shell utilities to write arbitrary chapter content into the host system clipboard, an OS-level capability not justified by the stated skill purpose.
The module writes arbitrary chapter text to the host system clipboard through OS commands. In an agent setting, the clipboard is a shared system resource; overwriting it can leak sensitive content to other apps, destroy user clipboard contents, and create unexpected cross-application data exposure.
The code copies chapter content to the global system clipboard without warning the user at the point of operation. Because clipboard contents are accessible to other local applications and will replace the user's current clipboard data, this creates a privacy and user-consent problem that is more significant in an automation skill running on a host machine.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
try:
if system == "Darwin": # macOS
proc = subprocess.Popen(['pbcopy'], stdin=subprocess.PIPE)
proc.communicate(text.encode('utf-8'))
return True
This Windows clipboard path uses subprocess.Popen(..., shell=True), which unnecessarily invokes the shell for an OS command. Even though the command is constant (clip) and the immediate injection surface is limited, using the shell expands the attack surface and is unsafe practice in an agent skill that handles untrusted content and runs on the host.
elif system == "Windows":
# Windows 使用 clip 命令,需要 utf-16le 编码
proc = subprocess.Popen(['clip'], stdin=subprocess.PIPE, shell=True)
proc.communicate(text.encode('utf-16le'))
return True
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
elif system == "Linux":
# Linux 优先尝试 xclip,其次 xsel
try:
proc = subprocess.Popen(['xclip', '-selection', 'clipboard'],
stdin=subprocess.PIPE)
proc.communicate(text.encode('utf-8'))
return True
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
except FileNotFoundError:
# xclip 不可用,尝试 xsel
try:
proc = subprocess.Popen(['xsel', '--clipboard', '--input'],
stdin=subprocess.PIPE)
proc.communicate(text.encode('utf-8'))
return True
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
return True
except FileNotFoundError:
print("[剪贴板] 错误: 请安装 xclip 或 xsel")
print(" Ubuntu/Debian: sudo apt install xclip")
print(" Arch Linux: sudo pacman -S xclip")
print(" Fedora: sudo dnf install xclip")
return False
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
return True
except FileNotFoundError:
print("[剪贴板] 错误: 请安装 xclip 或 xsel")
print(" Ubuntu/Debian: sudo apt install xclip")
print(" Arch Linux: sudo pacman -S xclip")
print(" Fedora: sudo dnf install xclip")
return False
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
return True
except FileNotFoundError:
print("[剪贴板] 错误: 请安装 xclip 或 xsel")
print(" Ubuntu/Debian: sudo apt install xclip")
print(" Arch Linux: sudo pacman -S xclip")
print(" Fedora: sudo dnf install xclip")
return False
Suspicious Unicode normalization or mixed-script content
Rule SQP-3 applies to all file types and covers language policy issues in natural-language text. This file consistently uses Chinese-only user-facing messages and documentation strings, with no indication that the skill is intentionally region-specific or that users can opt into another language.
The top-level natural-language documentation and user-facing strings are exclusively in Chinese, which can constitute a language policy issue when no opt-in or locale justification is provided. The file does not indicate that the skill is intentionally restricted to Chinese-speaking users or a China-specific compliance context.
The manifest focuses on publishing chapters, drafts, login, and viewing work status on the platform. This convenience function adds undeclared local file-reading behavior by loading an arbitrary path and parsing it for chapter content, which is broader than the manifest description in this file.
No suspicious patterns detected.