T09 · Insecure Skill Coding Practices
- Location
scripts/distribute.py:464- Finding
Chromium Browser Sandbox Explicitly Disabled
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a high-impact social posting automation package whose documentation overstates implemented publishing behavior and lacks sufficient safeguards for accounts, sessions, CAPTCHA handling, and scheduled/batch posting.
Review before installing. Treat this as a prototype, not a reliable publishing tool: it may report success without posting. Do not run it against real social accounts until publishing is implemented, sandboxing is fixed, dependencies are pinned, cookie storage is secured, and live batch/scheduled posting requires explicit confirmation or dry-run review.
scripts/distribute.py:464Chromium Browser Sandbox Explicitly Disabled
requirements.txt:4Unpinned and Unverified Third-Party Dependencies
scripts/distribute.py:620Distribution Operation Reports Success Without Publishing Content
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# 清除登录缓存
rm -rf data/cookies/*
# 强制重新登录
python3 scripts/distribute.py --relogin
The declared description presents a full-featured cross-platform publishing automation tool triggered by Xiaohongshu posting and supporting media adaptation, metadata filling, and captcha processing. The supplied code chunk does not implement those capabilities directly. Instead, it performs batch orchestration: reading note IDs, optionally generating placeholder recent IDs, calling an external distribute.py script, spacing executions, and printing a summary. While this wrapper is related to content distribution in a broad sense, its actual behavior is materially narrower than the declared functionality, and several advertised capabilities are absent from the code shown.
该描述与代码存在实质性不匹配。描述强调这是一个可用的“自动分发工具”,核心价值在于:从小红书获取已发布内容,并自动同步发布到抖音、视频号、快手。代码确实包含若干与该目标相关的支撑模块,例如图片按平台比例处理、标题/描述/标签截断与补充、验证码处理辅助、以及浏览器自动化基类。但最关键的能力并未真正实现:_fetch_source_content 只是返回硬编码/示例内容,明确带有 TODO;_distribute_to_platform 也没有真实执行任何平台登录或发布动作,只是处理内容后输出“发布成功”日志并返回 True。因此,代码更像是“分发工具脚手架/原型”,而不是描述中的已实现自动分发系统。此外,描述中的“在小红书发布后”暗示某种自动触发或监听机制,但代码只有 CLI 参数入口,没有触发器。验证码方面也并非完全自动,短信验证码需要用户手动输入。综合来看,声明的核心功能成熟度和自动化程度明显高于代码实际行为,应判定为不匹配。
声明描述的是一个在“小红书发布后”自动同步到多个平台的分发工具,并强调内容处理与验证码处理能力;但提供的代码片段实际实现的是一个独立的定时调度器。它通过解析命令行参数计算下一次运行时间,循环等待,并在到点后调用 scripts/distribute.py。也就是说,该代码的直接行为是‘定时执行分发脚本’,而不是监听“小红书发布后”事件,也没有在该片段中实现图片处理、标题标签填写或验证码处理。定时执行可以被视为分发系统的相关辅助功能,但它属于声明中未提及的重要触发/调度能力,因此描述与实际代码行为存在实质性不匹配。
The documented use of rm -rf data/cookies/* is a destructive shell operation with wildcard deletion. Even though the target path is limited, encouraging users or agents to run recursive forced deletion via shell increases the risk of accidental data loss, path confusion, or abuse if variables, working directory assumptions, or symlinks are involved.
# 清除登录缓存
rm -rf data/cookies/*
# 强制重新登录
python3 scripts/distribute.py --relogin
The code unconditionally logs and returns publication success even though no browser or app publishing logic exists. In an automation skill that claims cross-platform distribution, this creates a dangerous false-success condition that can cause operators to believe content was propagated when it was not, undermining auditability and operational trust.
The README markets automatic cross-platform synchronization, batching, scheduling, and staggered posting without a clear risk disclosure that such automation can trigger anti-abuse systems, account bans, or platform-integrity issues. Given the skill’s purpose is multi-platform posting automation, the missing warning makes unsafe or policy-violating use more likely.
The README explicitly promotes automated CAPTCHA handling and even suggests third-party CAPTCHA services, but does not warn that CAPTCHA images can contain sensitive session-linked challenges or that outsourcing them may expose account activity and violate platform controls. In a browser automation skill that logs into multiple social platforms, this materially increases privacy, account lockout, and policy-evasion risk.
The skill documents shell commands and file operations but does not declare any tool scope such as permissions or allowed-tools. In an agent environment, undeclared shell/file capabilities reduce least-privilege controls and can let the skill perform actions users or reviewers did not explicitly authorize.
The skill promotes automatic cross-platform posting without an upfront warning that it can publish user content to multiple external services and potentially affect account standing, privacy, or compliance with platform rules. In this context, the omission is more dangerous because the skill automates actions across several accounts and even discusses evasion-style measures like random delays and human-like simulation.
This manifest contains all human-readable comments and labels in Chinese, which imposes a specific language on operators without any visible opt-in or alternative locale support. Under the stated policy, a forced language choice in natural-language content is a reportable locale-policy issue unless it is explicitly documented as region-specific or optional.
This manifest contains only Chinese labels and comments, which effectively imposes a specific language on users and maintainers. The file does not indicate that the skill is region-specific or provide any opt-in or alternative language support, which matches the language/locale policy violation criteria.
The documentation describes handling SMS verification, cookies, usernames, and account configuration without any privacy or security guidance for sensitive data storage and use. This is dangerous because operators may store phone numbers, session cookies, and login artifacts insecurely, leading to account takeover, privacy breaches, or unauthorized publishing if those credentials are exposed.
The API documentation exposes automation commands that can publish content to third-party platforms, alter account state, and trigger irreversible external actions, but it does not warn operators about these side effects or require explicit confirmation patterns. In a multi-platform posting tool, missing safety guidance increases the chance of accidental mass posting, misuse of connected accounts, and unintended data propagation across services.
The changelog explicitly advertises automated CAPTCHA handling, randomized delays to simulate human behavior, and staggered posting to avoid platform risk controls, but provides no warning about account bans, legal/compliance issues, or platform Terms of Service violations. In the context of a multi-platform automation skill, this materially increases the risk that users will deploy evasion features for abusive automation or unauthorized account activity.
The entire guide is written exclusively in Chinese and all example titles, tags, and workflow guidance assume Chinese-language output and Chinese platforms, without any note that this is a locale-specific guide or that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is clearly documented and justified.
The batch tool automatically invokes a subordinate distribution script that can publish content to external platforms, but this file provides no explicit confirmation prompt, dry-run safeguard, or clear warning at execution time about those side effects. In an agent skill context, this increases the risk of unintended mass posting if the script is triggered with the wrong inputs or by a user who does not fully understand that real external actions will occur.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
cmd.append("--use-app")
try:
result = subprocess.run(
cmd,
capture_output=True,
text=True,
The module docstring presents the skill entirely in Chinese and does not indicate any language choice or locale constraint. Under the policy rule, forcing a specific language without offering user opt-in or documenting a justified regional limitation is a natural-language policy violation.
The module and manifest describe a tool that fetches published content from 小红书 and redistributes it, and this method is documented as source-content retrieval. In reality, the implementation explicitly says it is a simplified stub and returns fixed sample data instead of actually fetching source posts, which contradicts the documented intent of the function.
The script is designed to automatically perform repeated external posting actions on a schedule once launched, without any in-code confirmation, dry-run mode, rate-limit safeguard, or explicit warning before each run. In the context of a multi-platform content distribution skill, this increases the risk of unintended mass posting, policy violations, account restrictions, or accidental propagation of bad content across several services.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
cmd.append("--use-app")
try:
result = subprocess.run(
cmd,
capture_output=True,
text=True,
The natural-language instructions and examples are entirely in Chinese, and the file does not indicate that this is a region-specific skill or offer users an explicit language choice. Per the policy, forcing a specific language without opt-in can be a locale-policy issue unless the constraint is documented and justified.
The file's human-readable instructions and labels are entirely in Chinese, beginning with the title and warning comments. Under the policy rule for natural-language issues, this can be considered a locale/language constraint because no alternative language, opt-in, or justification for a Chinese-only audience is provided.
This YAML file’s human-readable comments and labels are entirely in Chinese, which indicates a fixed language choice in the skill’s natural-language surface. The file does not document that the skill is China-specific or offer any language/locale choice, so it may violate a language/locale policy requiring user opt-in or justified locale constraints.
No suspicious patterns detected.