Back to skill

Security audit

Zhihu CLI

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned but should be reviewed carefully because it asks users to run an unpinned npm CLI that extracts and stores Zhihu login cookies from Chrome.

Install only if you are comfortable letting an unpinned external npm package access your Chrome Zhihu session and store it locally. Treat `~/.zhihu-cookie` and any manually entered cookie string like a password, avoid sharing logs or shell history containing it, and prefer a pinned, reviewed package version with documented credential protections.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:14
Finding

Unpinned Third-Party npm Package Is Installed and Executed Without Integrity Verification

Content
View full analysis
``` ### Technical Analysis The Skill delegates its entire implementation to the externally distributed `zhihu-cli` npm package. The reviewed project does not include that package's source code, an exact pinned version, a lockfile, a package integrity hash, or a reference to a verified source repository. Running `npm install -g zhihu-cli` can execute npm lifecycle scripts and installs executable package content globally for the current user or installation environment. The `npx zhihu-cli ` alternative is especially sensitive because `npx` may download and immediately execute the package when it is not already available locally. Because no immutable version or integrity constraint is specified, the code executed by future users can differ from the code that existed when this Skill was reviewed. Package-account compromise, malicious version publication, dependency compromise, or package-name takeover could therefore introduce arbitrary executable code without requiring changes to this repository. The audit found no evidence that the current npm package is malicious. The vulnerability is the Skill's unsafe trust and execution model and the inability to audit the implementation from the supplied project. ### Attack Path 1. An attacker compromises the npm publisher account, takes control of the package name, or compromises a transitive dependency. 2. The attacker publishes a modified package version containing a malicious lifecycle script or runtime payload. 3. A user follows the Skill instructions and runs either `npm install -g zhihu-cli` or `npx zhihu-cli `. 4. npm retrieves the mutable package from the registry without validating it against a project-spe ...[truncated 890 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:36
Finding

Zhihu Session Cookies Are Extracted from Chrome and Stored in a Predictable File

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
89% confidence
Finding

The documented zhihu login command 'auto-extract[s] cookies from Chrome', which is behavior strongly associated with credential harvesting and can enable session hijacking if implemented unsafely or without explicit informed consent. In context, this is presented as a convenience feature for authenticating to Zhihu, so the likely intent is not overtly malicious, but the capability is inherently sensitive because it accesses browser-stored authentication data.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

(知乎). Supports hot topics, content search, article reading, user info, and Browser Relay-based voting/following.

Zhihu CLI

A CLI tool for interacting with Zhihu (知乎) content.

Installation

bash
# Install globally
npm install -g zhihu-cli

# Or use npx
npx zhihu-cli <command>

Commands

CommandDescription
zhihu loginAuto-extract cookies from Chrome
zhihu whoamiCheck login status
zhihu set-cookie <cookie>Set cookie manually
zhihu hotGet hot topics
zhihu search <keyword>Search content
zhihu topics <keyword>Search topics
zhihu read <url>Read answer/article
zhihu user <token>Get user info by url_token
zhihu vote <url>Browser Relay vote instructions
zhihu follow [url]Browser Relay follow instructions
zhihu postBrowser Relay post instructions

Features

  • 🔍 Search Zhihu content
  • 🔥 Get hot topics
  • 📖 Read answers/articles

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states that Zhihu authentication cookies are stored locally in ~/.zhihu-cookie but does not warn about the sensitivity of those cookies or the account-takeover risk if the file is exposed. Because the same skill also supports auto-extracting cookies from Chrome, the lack of a clear storage/security warning increases the chance that users handle long-lived session secrets insecurely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.