Back to skill

Security audit

Weibo 微博数据备份

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Weibo backup skill, but it handles browser login cookies in risky ways that should be reviewed before installation.

Install only if you are comfortable with a local script storing Weibo login cookies and downloading potentially large amounts of account-linked content. Prefer an isolated browser profile, avoid connecting it to your normal browser over CDP, use --no-save-cookies when possible, keep output and cookies.json out of shared or synced folders, and do not use --download-video on untrusted pages until media URL and redirect allowlisting is added.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
weibo_favorites_4skill.py:508
Finding

Browser-context cookies can be exfiltrated through attacker-controlled media URLs

Content
View full analysis
bool: try: # This obtains every cookie available in the browser context. cookies = await context.cookies() cookie_str = "; ".join([f"{c['name']}={c['value']}" for c in cookies]) headers = { "Referer": "https://weibo.com/", "Cookie": cookie_str, } if user_agent: headers["User-Agent"] = user_agent timeout = aiohttp.ClientTimeout(total=timeout_ms / 1000) async with aiohttp.ClientSession(timeout=timeout) as session: async with session.get(video_url, headers=headers) as response: if response.status != 200: print(f"视频下载失败(HTTP {response.status}): {video_url}") return False downloaded_size = 0 with open(target_path, 'wb') as f: async for chunk in response.content.iter_chunked(8192): if chunk: f.write(chunk) downloaded_size += len(chunk) print(f"✓ 视频下载成功: {target_path.name} ({d ...[truncated 2634 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
weibo_favorites_4skill.py:438
Finding

Authentication cookies are persisted in plaintext by default

Content
View full analysis
bool: """从文件加载 cookies""" if not COOKIES_FILE.exists(): return False try: cookies = json.loads(COOKIES_FILE.read_text(encoding='utf-8')) await context.add_cookies(cookies) print(f"✓ 已加载登录状态: {COOKIES_FILE}") return True except Exception as e: print(f"⚠️ 加载 cookies 失败: {e}") return False ``` ```python parser.add_argument( "--save-cookies", action="store_true", default=True, help="保存登录状态到文件(默认启用)" ) parser.add_argument( "--no-save-cookies", action="store_true", help="不保存登录状态" ) ``` ### Technical Analysis The Skill serializes complete browser cookie objects into `cookies.json` as unencrypted JSON. Saving is enabled by default, meaning a normal run creates or updates this file unless the user explicitly passes `--no-save-cookies`. `Path.write_text()` does not explicitly establish restrictive permissions. The resulting access mode depends on the operating system and process umask. The implementation also does not use a credential manager, encryption, atomic secure-file creation, or a check preventing the file from being placed in a shared or source-controlled directory. Cookie files commonly contain session tokens that are equivalent to credentials. Possession of a valid cookie may allow authentication witho ...[truncated 1129 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:25
Finding

Recommended installation retrieves mutable remote Skill content without integrity pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
| `weibo_favorites_4skill.py` | Main python script entry point |

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

The README instructs users to run npx skills add against a remote skill URL without pinning a specific version, commit, or immutable artifact. That creates a supply-chain risk: the referenced package or hosted skill content could change later and cause users to install different code than originally reviewed.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 29)May include surrounding context.

md
- 自动安装Skill (推荐)
  npx skills add https://www.modelscope.cn/skills/hhjinhh/weibo-data-backup
- 手动安装Skill
  把项目clone到本地, 把weibo-data-backup 目录复制到agent skills目录下, 如 .opencode/skills 或 .claude/skills/目录下

## 手动运行脚本

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is explicitly designed for bulk downloading and local writing of Weibo posts, images, videos, and articles, yet the README does not prominently warn that it may copy large amounts of account-linked or third-party content to disk. That omission raises privacy, compliance, and unintended data-retention risks, especially when used on favorites or other users' content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that subsequent runs will reuse cookies.json to access an already authenticated Weibo session, but it does not clearly warn users that local login state will be read and reused to access account data. This can surprise users, increase privacy risk, and normalize handling sensitive session artifacts without guidance on storage, protection, or revocation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes a Playwright-based downloader that necessarily reads authentication material, writes downloaded content to disk, and accesses the network, yet the manifest declares no explicit tool scope or permissions. This creates an authorization ambiguity where an agent may execute sensitive file and network operations without clear user-visible constraints, increasing the chance of unintended data access or exfiltration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger text is overly broad and includes catch-all language for essentially any Weibo backup-related request, which can cause the skill to activate in contexts the user did not intend. Because the skill can use cookies or browser profiles and perform automated collection of third-party content, over-triggering increases the risk of privacy-impacting or policy-violating actions being launched with insufficient confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions tell the agent to use cookies.json or a browser user-data directory for automated authenticated access, but they do not provide a clear privacy and security warning about the sensitivity of these artifacts. Cookies and browser profiles can contain active session tokens and other personal data, so mishandling them could expose the user's account, private content, or broader browsing data beyond the stated task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The default configuration defines a persistent cookies file in the working directory, setting up storage of authentication material on disk without any prominent safety disclosure. Session cookies are credential equivalents for many web apps; if the file is copied or exposed, an attacker may be able to hijack the user's logged-in Weibo session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This function serializes the full browser cookie jar to cookies.json in plaintext, with no encryption, permission hardening, or meaningful user confirmation. Because these cookies likely include live session tokens, local disclosure of the file can enable session replay or account takeover for the associated Weibo account.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code can attach to any already running Chromium instance over CDP, which grants this script access to a much broader browser session than needed for a Weibo downloader. If pointed at a live personal browser, the skill may inherit cookies, tabs, and authenticated context for unrelated sites, significantly increasing exposure if misused or compromised.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description frames this as a Weibo favorites/history backup tool, but the runtime behavior explicitly tells the user to navigate to '收藏页 / 本人主页 / 他人主页' and then scrapes whatever page is open. That scope expansion enables collection of other users' historical posts and media, creating a privacy/compliance risk and making the skill materially broader than advertised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.