T08 · Insecure Dependencies
- Location
scripts/lib/vendor/bird-search/lib/cookies.js:1- Finding
Unpinned and Undeclared Browser-Cookie Dependency Can Be Resolved from an Untrusted Location
- Content
View full analysis
=22" }, "license": "MIT", "attribution": "Based on @steipete/bird v0.8.0 by Peter Steinberger (MIT License)" } ``` ### Technical Analysis The X search component is represented as a self-contained vendored client, but its cookie-extraction module imports `@steipete/sweet-cookie` without declaring the package in `package.json`, supplying a lockfile, or including the expected package in the audited project. Node.js resolves package imports by searching applicable `node_modules` directories, including ancestor locations. Consequently, an ambient package outside the audited Skill directory may satisfy this import. The loaded package is invoked with access to browser cookie stores and is expected to return X/Twitter authentication cookies: ```javascript const { cookies, warnings: providerWarnings } = await getCookies({ url: TWITTER_URL, origins: TWITTER_ORIGINS, names: [...TWITTER_COOKIE_NAMES], browsers: [options.source], mode: 'merge', chromeProfile: options.chromeProfile, firefoxProfile: options.firefoxProfile, timeoutMs: options.cookieTimeoutMs, }); ``` This creates a dependency-confusion and lo ...[truncated 1868 chars]- Remediation
View remediation
