Back to skill

Security audit

番茄小说自动发布

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real Fanqie Novel publishing helper, but it needs review because it stores login cookies insecurely and automates live account publishing with weak safeguards.

Review this before installing. Use it only in a trusted, isolated environment, expect it to store reusable login cookies locally, and prefer draft mode until you verify target work and chapter details. Clear the cookie file after use and avoid running it with elevated privileges.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/browser.py:92
Finding

Authentication Cookies Persisted in an Unprotected Plaintext File

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/browser.py:41
Finding

Chromium Security Sandbox Explicitly Disabled

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/requirements.txt:1
Finding

Unnecessary Browser Credential-Access Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/publisher.py:366
Finding

Publication and Draft Operations Report Success Without Definitive Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (26)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This duplicate finding flags the same issue: the subprocess is launched via the shell for a simple clipboard utility. In security-sensitive automation, unnecessary shell usage is a real hardening weakness even when immediate exploitability is limited.

Content

Scanner excerpt · scripts/publisher.py (reported line 279)May include surrounding context.

python
elif system == "Windows":
                # Windows 使用 clip 命令,需要 utf-16le 编码
                proc = subprocess.Popen(['clip'], stdin=subprocess.PIPE, shell=True)
                proc.communicate(text.encode('utf-16le'))
                return True

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This duplicate finding flags the same issue: the subprocess is launched via the shell for a simple clipboard utility. In security-sensitive automation, unnecessary shell usage is a real hardening weakness even when immediate exploitability is limited.

Content

Scanner excerpt · scripts/publisher.py (reported line 279)May include surrounding context.

python
elif system == "Windows":
                # Windows 使用 clip 命令,需要 utf-16le 编码
                proc = subprocess.Popen(['clip'], stdin=subprocess.PIPE, shell=True)
                proc.communicate(text.encode('utf-16le'))
                return True

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill exposes capabilities consistent with file access, shell execution, and networked browser automation, but it does not declare any tool scope or permission boundaries. In a skill that logs into a writer backend and publishes content, this omission prevents meaningful consent and review, increasing the chance of unintended file access, command execution, or automated actions against external services.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad terms such as '发布章节' and '存入草稿箱', which can plausibly appear in normal conversation unrelated to this specific skill. Because this skill performs high-impact actions like login and automated publication, accidental invocation could lead to unintended automation against a live account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation describes automated login, chapter submission, and batch publishing, but does not clearly warn users about operational risks such as publishing to the wrong work, unintended live publication, account/session handling, or platform policy consequences. In this context, missing risk disclosure is dangerous because the skill interacts with a real publisher backend and can rapidly make irreversible external changes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code injects an anti-detection script to hide navigator.webdriver and launches Chromium with automation-evasion flags such as --disable-blink-features=AutomationControlled. For a chapter-publishing tool, this is not necessary for core functionality and instead enables stealthy automation that can bypass platform bot-detection controls, increasing the risk of terms-of-service evasion or abusive automated account activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool saves browser cookies directly to a local JSON file, which can persist authenticated session data and allow account reuse by anyone with filesystem access. In the context of an author-platform publishing tool, these cookies may grant access to the writer backend, drafts, and publishing functions without requiring the user to log in again.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring names the skill in Chinese, and the file also hard-codes Chinese UI text elsewhere, indicating the skill is designed around a single language/locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The selectors rely on Chinese text such as '登录', '工作台', '创建章节', '章节管理', and '定时发布', which constrains the skill to one language environment. The file does not provide any user choice or documented justification for this locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module title and all user-facing prompts are written in Chinese, including operational instructions such as login guidance. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code presents the workflow description and user-facing interaction model in a single fixed language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not shown here.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes browser-based publishing, drafting, login, and viewing works on 番茄小说. This file additionally imports subprocess and later uses platform-specific shell utilities to write arbitrary chapter content into the host system clipboard, an OS-level capability not justified by the stated skill purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module writes arbitrary chapter text to the host system clipboard through OS commands. In an agent setting, the clipboard is a shared system resource; overwriting it can leak sensitive content to other apps, destroy user clipboard contents, and create unexpected cross-application data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code copies chapter content to the global system clipboard without warning the user at the point of operation. Because clipboard contents are accessible to other local applications and will replace the user's current clipboard data, this creates a privacy and user-consent problem that is more significant in an automation skill running on a host machine.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/publisher.py (reported line 273)May include surrounding context.

python
try:
            if system == "Darwin":  # macOS
                proc = subprocess.Popen(['pbcopy'], stdin=subprocess.PIPE)
                proc.communicate(text.encode('utf-8'))
                return True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

This Windows clipboard path uses subprocess.Popen(..., shell=True), which unnecessarily invokes the shell for an OS command. Even though the command is constant (clip) and the immediate injection surface is limited, using the shell expands the attack surface and is unsafe practice in an agent skill that handles untrusted content and runs on the host.

Content

Scanner excerpt · scripts/publisher.py (reported line 279)May include surrounding context.

python
elif system == "Windows":
                # Windows 使用 clip 命令,需要 utf-16le 编码
                proc = subprocess.Popen(['clip'], stdin=subprocess.PIPE, shell=True)
                proc.communicate(text.encode('utf-16le'))
                return True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/publisher.py (reported line 286)May include surrounding context.

python
elif system == "Linux":
                # Linux 优先尝试 xclip,其次 xsel
                try:
                    proc = subprocess.Popen(['xclip', '-selection', 'clipboard'], 
                                          stdin=subprocess.PIPE)
                    proc.communicate(text.encode('utf-8'))
                    return True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/publisher.py (reported line 293)May include surrounding context.

python
except FileNotFoundError:
                    # xclip 不可用,尝试 xsel
                    try:
                        proc = subprocess.Popen(['xsel', '--clipboard', '--input'], 
                                              stdin=subprocess.PIPE)
                        proc.communicate(text.encode('utf-8'))
                        return True

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/publisher.py (reported line 299)May include surrounding context.

python
return True
                    except FileNotFoundError:
                        print("[剪贴板] 错误: 请安装 xclip 或 xsel")
                        print("  Ubuntu/Debian: sudo apt install xclip")
                        print("  Arch Linux: sudo pacman -S xclip")
                        print("  Fedora: sudo dnf install xclip")
                        return False

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/publisher.py (reported line 300)May include surrounding context.

python
return True
                    except FileNotFoundError:
                        print("[剪贴板] 错误: 请安装 xclip 或 xsel")
                        print("  Ubuntu/Debian: sudo apt install xclip")
                        print("  Arch Linux: sudo pacman -S xclip")
                        print("  Fedora: sudo dnf install xclip")
                        return False

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/publisher.py (reported line 301)May include surrounding context.

python
return True
                    except FileNotFoundError:
                        print("[剪贴板] 错误: 请安装 xclip 或 xsel")
                        print("  Ubuntu/Debian: sudo apt install xclip")
                        print("  Arch Linux: sudo pacman -S xclip")
                        print("  Fedora: sudo dnf install xclip")
                        return False

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Rule SQP-3 applies to all file types and covers language policy issues in natural-language text. This file consistently uses Chinese-only user-facing messages and documentation strings, with no indication that the skill is intentionally region-specific or that users can opt into another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The top-level natural-language documentation and user-facing strings are exclusively in Chinese, which can constitute a language policy issue when no opt-in or locale justification is provided. The file does not indicate that the skill is intentionally restricted to Chinese-speaking users or a China-specific compliance context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest focuses on publishing chapters, drafts, login, and viewing work status on the platform. This convenience function adds undeclared local file-reading behavior by loading an arbitrary path and parsing it for chapter content, which is broader than the manifest description in this file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.