T09 · Insecure Skill Coding Practices
- Location
scripts/post_carousel.py:20- Finding
TikTok Session Cookies Stored in Plaintext
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly matches a TikTok carousel workflow, but it handles TikTok account sessions in a risky and under-disclosed way.
Review before installing. Treat TikTok cookies as full account credentials, avoid using this on an important TikTok account, and do not run the login/posting flow unless you are comfortable with plaintext local cookie storage and browser automation. Prefer a version that uses an official delegated posting flow or stores credentials in an OS secret manager with clear deletion and consent controls.
scripts/post_carousel.py:20TikTok Session Cookies Stored in Plaintext
scripts/post_carousel.py:48Chrome Security Sandbox Disabled for External Web Content
SKILL.md:8Documented TikTok Cookie Environment Secret Is Unused and Conflicts with Actual Storage
This mismatch is especially risky because it involves automated TikTok authentication, cookie reuse, browser automation, and local cookie storage while presenting itself as a benign content-generation skill. Hidden auth-handling behavior can enable account takeover, unauthorized posting, or session theft if cookies are exposed or reused outside the user's expectations.
This mismatch is especially risky because it involves automated TikTok authentication, cookie reuse, browser automation, and local cookie storage while presenting itself as a benign content-generation skill. Hidden auth-handling behavior can enable account takeover, unauthorized posting, or session theft if cookies are exposed or reused outside the user's expectations.
The script persists TikTok authentication cookies to a local JSON file, which effectively stores reusable session credentials. If that file is read by another local user, process, backup system, or accidentally committed, an attacker may hijack the TikTok session without needing the password or MFA.
The Selenium automation loads saved cookies into a browser session and then performs account actions, enabling automated use of a TikTok account outside the generation-only purpose described for the skill. In context, this makes the skill more dangerous because it bridges from content creation into authenticated account control, which could be abused for unauthorized posting or account misuse.
The skill declares access to sensitive environment variables and implies operational capabilities, but it does not declare an explicit tool scope or permissions boundary. This creates a transparency and least-privilege problem: an agent or user may authorize the skill without understanding that it can access secrets and local state, increasing the chance of unintended secret exposure or file misuse.
The documentation instructs users to provide TikTok session cookies for posting without warning that session cookies are effectively account credentials. If mishandled, these cookies can permit unauthorized account access, posting, or account compromise, and the social-media automation context makes the consequence more severe because it directly targets a live user account.
The manifest says this skill generates TikTok photo carousels, and this record is labeled with niche 'music' and product 'gothic rock band Forsaken'. However, the actual slide prompts describe a kitchen, food scanning, meal prep, progress charts, and an app/dashboard, which is a different subject entirely. This indicates the generated/stored output behavior is inconsistent with the skill’s claimed purpose for this carousel instance.
The manifest description says the skill 'includes learning loop for continuous improvement,' but this file only defines data file paths and never reads, updates, or uses metrics/prompts data to adapt future carousel generation. Carousel generation is based on hardcoded templates and timestamp-based hook selection rather than any feedback-driven optimization.
The file header presents this as a simple TikTok poster, while the skill metadata says the skill generates AI carousels. That mismatch matters because the script handles authentication state and posting automation, which are materially more sensitive capabilities than content generation and can surprise users or downstream systems reviewing the skill.
The script's core behavior is browser automation, login state reuse, and upload flow handling rather than carousel generation or a learning loop. This creates a deceptive capability gap: operators may approve or run a generation tool without realizing it also automates access to a real TikTok account.
Sensitive authentication material is written to disk without a meaningful warning, consent flow, or explanation of retention. Users may not realize they are creating a long-lived local credential artifact, increasing the chance of accidental exposure through shared machines, backups, logs, or source-control mistakes.
Describing automatic tracking of views, conversion metrics, and strategy updates without a user-facing notice creates a consent and privacy issue. While less severe than credential misuse, silent analytics collection and behavioral automation can still expose user or audience data practices that operators did not knowingly approve.
The top-level documentation presents the skill as producing a fixed 6-slide format, but the code accepts a user-supplied --slides value and generate_carousel() iterates over any requested count. That is a direct contradiction between the documented intent and actual behavior, not merely omitted detail.
This code generates user-facing content such as hooks and post text entirely in English, and the CLI exposes no option to select language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.
This is a code file, so SQP-2 applies to safety-relevant file writes. Although the script performs visible writes to metrics data, strategy data, and hook performance data, the only disclosure is brief internal docstrings and post-write status prints, which do not clearly warn users in advance that running the command will persist or overwrite local analytics files.
The function docstring says 'Post carousel to TikTok' and the module says it 'Posts carousels to TikTok using cookies,' but the implementation only checks login, clicks upload, and prints 'Would post carousel' while noting the upload is a placeholder. This is an active mismatch between the code documentation and actual behavior.
Detected: suspicious.dynamic_code_execution, suspicious.exposed_secret_literal, suspicious.insecure_tls_verification (+1 more)