T09 · Insecure Skill Coding Practices
- Location
auto_publish.py:25- Finding
Authentication Cookies Stored in Predictable Plaintext Files Without Explicit Access Controls
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a real video publisher, but it stores reusable account sessions in plaintext and can automatically post public content with under-disclosed defaults.
Review before installing. Use only accounts you control, assume commands may immediately upload and publish publicly, avoid the default generated content unless you have checked it, and do not store or share the generated cookies directory. Prefer a version that pins dependencies, removes anti-detection claims, documents all supported platforms, stores sessions securely, and requires an explicit final confirmation or dry run before posting.
auto_publish.py:25Authentication Cookies Stored in Predictable Plaintext Files Without Explicit Access Controls
requirements.txt:1Unbounded Playwright Dependency Permits Unreviewed Future Releases
The documented behavior does not fully match the detected functionality: undisclosed platform support, cookie read/save/reuse, local directory scanning, and automatic metadata generation materially expand what the skill can do. Hidden or under-described capabilities are dangerous because they prevent informed consent and can lead to unreviewed publication, credential handling, or local data processing beyond what the user expects.
This markdown file instructs the user to run a publishing command that posts videos to B站、抖音、小红书, including an example that publishes to all platforms, but it does not warn that the action may upload content publicly or affect external accounts. For markdown files, safety-affecting behavior that can impact user data or account integrity should be disclosed clearly.
The README promotes persistent cookie storage and detailed logging but does not warn that cookies may grant full account access or that logs may capture sensitive metadata, paths, or operational details. This omission can lead users to store authentication material insecurely and expose account data if the host or repository is compromised.
The README explicitly advertises '反检测技术' to bypass anti-bot and anti-crawling protections, which signals intent to evade platform safeguards rather than simply automate a legitimate workflow. Even in documentation, this increases the likelihood the skill is designed to violate platform controls and can facilitate account restrictions, abuse, or policy evasion.
The documentation encourages one-command automated publishing and button-click automation without emphasizing that posting is an externally visible, potentially irreversible action. Users may accidentally publish unintended content across multiple platforms, causing reputational, legal, or compliance harm.
The skill describes capabilities that imply local file access and state persistence, but it does not declare an explicit tool scope such as permissions or allowed-tools. That makes the effective access boundary unclear to users and reviewers, increasing the risk of unintended file reads/writes such as cookie storage, log creation, or scanning local video directories.
The documentation mentions cookie persistence and detailed logging without warning users about credential and privacy risks. Persisted cookies can expose authenticated sessions, and logs may capture sensitive account, file, or publication details; in an automation skill handling multiple social-media accounts, that materially increases the chance of account compromise or privacy leakage.
The skill's default invocation appears to immediately publish content to live third-party platforms, but the documentation does not present a prominent warning or confirmation requirement. In a publishing automation context, this is especially risky because a single command can cause irreversible external actions such as public posting, account policy violations, or accidental release of sensitive or wrong content.
The skill description claims support for three Chinese platforms, but the code also supports Kuaishou and can publish to all platforms in bulk. This mismatch undermines user consent and transparency because the tool can act on an additional account/platform beyond what the metadata advertises.
The script saves live authenticated browser cookies for creator accounts to local JSON files without encryption, permission hardening, or an explicit warning. Anyone with filesystem access can potentially reuse those cookies to hijack social media sessions and publish or manage content as the victim.
The script is presented as a generic auto-publisher, but it automatically generates and publishes specific Iran war / Middle East news content. That hidden specialization increases the risk of deceptive or unauthorized content posting, especially for sensitive geopolitical topics where mistakes or misuse can cause account, reputational, or policy harm.
The main workflow performs real submission actions to one or more platforms after only a menu choice, without a final explicit confirmation summarizing the irreversible consequences. Because the tool automates authenticated posting across social accounts, a mistaken selection or bad generated content can immediately cause unintended public publication.
The module docstring states the publish order is "B站 → 抖音 → 快手 → 小红书" and describes full automation for that sequence. However, the actual platform list at L57-L58 explicitly removes Kuaishou and only iterates over bilibili, douyin, and xiaohongshu, creating a direct mismatch between claimed behavior and implemented behavior.
The module docstring and all user-facing log messages are written in Chinese, and the skill description presents this as the default behavior without any opt-in or alternative locale support. Under the policy for natural-language constraints, forcing a specific language without user choice is a violation unless it is explicitly justified as region-specific.
The startup log at L35-L36 tells the operator the tool will publish in the order "B站 → 抖音 → 小红书," while the top-level docstring at L2 claims "B站 → 抖音 → 快手 → 小红书." The code at L57-L58 confirms Kuaishou is omitted, so the file contains conflicting intent documentation about what platforms are actually handled.
The command-line description states the skill publishes only to "中国三大平台(B站、抖音、小红书)", which imposes a China-specific platform/locale scope in user-facing natural language without presenting any language or locale choice. Under the policy, locale constraints should be opt-in or explicitly justified as region-specific tooling.
The file content is entirely in Chinese and does not indicate that the language is optional, user-selectable, or justified as a region-specific constraint. This can constitute a natural-language locale policy issue when a skill effectively forces a specific language without opt-in or explanation.
The README content is entirely in Chinese, effectively forcing a specific language for operation and documentation without user opt-in or explanation. The policy allows locale constraints when clearly documented and justified, but this file does not state that the skill is intentionally limited to Chinese-speaking users or a China-specific operational context.
The natural-language documentation appears entirely in Chinese, which can amount to a language/locale constraint for users who do not read Chinese. The file does not explicitly state that the skill is intended only for Chinese-speaking users or provide an opt-in language choice or alternate-language documentation.
The natural-language strings and descriptions throughout the file are exclusively in Chinese, with no indication that language choice is configurable or user-selected. This can violate language/locale policy when a skill implicitly forces one language rather than offering opt-in or documenting a justified locale restriction.
The dependency is specified with a lower-bound only (playwright>=1.40.0), which allows future unreviewed major or minor versions to be installed. This can introduce supply-chain risk, unexpected breaking changes, or newly introduced vulnerable transitive dependencies into an automation skill that interacts with external web platforms.
playwright>=1.40.0
No suspicious patterns detected.