Back to skill

Security audit

知乎发帖-谷歌浏览器

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Zhihu auto-publishing skill, but it can post publicly from a saved logged-in browser session without a fresh confirmation step.

Install only if you are comfortable letting an agent publish real Zhihu articles from your logged-in account. Prefer preview/draft mode unless you explicitly confirm the final title and body, use a dedicated Zhihu browser profile, keep the Chrome debugging port local, avoid sudo/system-wide driver installs when possible, and review downloaded dependencies before setup.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:3
Finding

Unpinned Python Dependencies Installed Without Integrity Verification

Content
View full analysis
=4.15.0; python_version >= '3.7' selenium>=3.141.0,<4.0.0; python_version < '3.7' ``` ```bash echo "Installing Python dependencies (--user, no sudo)..." python3 -m pip install --user -r "$SKILL_DIR/requirements.txt" ``` ### Technical Analysis The dependency specification permits mutable ranges rather than selecting exact, reviewed versions. The installation command also does not use package hashes or an option such as `--require-hashes`. Consequently, separate installations of the same Skill can retrieve different Selenium releases and transitive dependencies. Installation through `pip` may execute package build or installation logic under the account running setup. Although Selenium is a legitimate dependency required by the declared browser-automation functionality, the absence of version and artifact integrity controls unnecessarily expands the supply-chain attack surface. No evidence indicates that the current dependency name is malicious or typo-squatted. The issue is the lack of reproducible, authenticated dependency resolution. ### Attack Path 1. An attacker compromises an allowed upstream package release, package index, dependency artifact, or applicable network trust path. 2. A user runs `scripts/setup.sh`. 3. `pip` resolves the broad version constraint to the compromised release. 4. The malicious package or build logic executes with the privileges of the account running setup. 5. The package remains installed in the user's Python environment and can execute again when the publishing script imports Selenium. ### Impact Assessment Successful exploitation could execute arbitrary code as the user who runs setup, allowing access to that user's files and processes. In this project, that account may also have access ...[truncated 305 chars]
Remediation
View remediation
; python_version >= '3.7' selenium==3.141.0; python_version < '3.7' ``` 2. Generate and commit a lock file containing hashes for all direct and transitive dependencies. 3. Install with hash enforcement: ```bash python3 -m pip install --user --require-hashes -r requirements.lock ``` 4. Use a dedicated virtual environment rather than modifying the general user site-packages directory. 5. Regularly review pinned versions for security advisories and update them through a controlled process. 6. Continue prohibiting root installation in the normal setup workflow. ]]>

T08 · Insecure Dependencies

Warning
Location
scripts/install_chromedriver.sh:63
Finding

Downloaded Chromedriver Executable Is Installed Without Artifact Verification

Content
View full analysis
&2 echo " sudo env CHROMEDRIVER_INSTALL_DIR=/usr/local/bin bash $0" >&2 fi echo "Downloading: $ZIP_URL" if ! curl -fL "$ZIP_URL" -o "$TMPDIR/chromedriver.zip"; then echo "Download failed for version $FULL_VERSION." >&2 echo "Pick the build that matches: $("$CHROME_BIN" --version 2>/dev/null || echo 'your chrome')" >&2 echo " https://googlechromelabs.github.io/chrome-for-testing/" >&2 exit 1 fi if ! command -v unzip >/dev/null 2>&1; then echo "unzip is required. On RHEL/Fedora: sudo dnf install -y unzip" >&2 exit 1 fi unzip -o -q "$TMPDIR/chromedriver.zip" -d "$TMPDIR" DEST="$INSTALL_DIR/chromedriver" cp -f "$TMPDIR/chromedriver-linux64/chromedriver" "$DEST" chmod 755 "$DEST" ``` ### Technical Analysis The installer downloads a native executable from Google Chrome for Testing over HTTPS and immediately installs it without validating a cryptographic checksum or signature. The source domain is appropriate for the declared functionality, and TLS provides transport protection, but it does not provide independent artifact integrity verification if the upstream repository, artifact, or local trust environment is compromised. Chromedriver is later executed as part of the Selenium attachment workflow. Therefore, a modified archive directly becomes executable code in the publishing account's environment. The default non-root destination is ` ...[truncated 1312 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/load_chromedriver_env.sh:8
Finding

Chromedriver Configuration File Is Executed as Unrestricted Shell Code

Content
View full analysis
Remediation
View remediation
`. 3. Reject shell metacharacters, command substitutions, embedded newlines, unexpected keys, and relative paths. 4. Canonicalize the selected path and verify that it points to a regular executable file. 5. Check that the configuration file is owned by the expected user and is not group- or world-writable. 6. Remove the parent-directory fallback unless there is a documented and secured requirement for it. 7. Prefer writing only the raw path to a data file, or pass the path through a controlled environment variable. 8. A safer parsing pattern would read data without evaluating it: ```bash IFS= read -r driver_path < "$env_file" [[ "$driver_path" == /* ]] || { echo "Invalid chromedriver path" >&2 return 1 } [[ -f "$driver_path" && -x "$driver_path" ]] || { echo "Chromedriver is not an executable regular file" >&2 return 1 } export CHROMEDRIVER_PATH="$driver_path" ``` ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (26)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 43)May include surrounding context.

clawhub publish

text

Ensure `scripts/*.sh` are executable in the published tarball (`chmod +x` before publish).

## Maintainer sync from dev repo

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is end-user content publishing to Zhihu, but the supplied code does not create, edit, or submit any article content, nor does it interact with Zhihu at all. Its sole function is to verify that local Chrome and chromedriver installations are present and version-compatible. While this could be a supporting prerequisite for a browser automation stack, the chunk itself has a materially different primary purpose from the declared skill behavior. Therefore this code chunk does not accurately represent the declared publishing functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly tells the agent to default to '--submit' and skip a non-destructive check for ordinary requests, meaning a normal invocation can immediately publish content to a live user account. This is dangerous because a misunderstood prompt, hallucinated article content, or accidental trigger can cause irreversible external actions without an explicit last-mile user confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file instructs users to run sudo dnf install, move a binary into /usr/local/bin, and change its permissions, which affects system integrity and requires elevated privileges. The surrounding text does not warn users that these commands modify the host system or require trust in downloaded binaries.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs the agent to use shell execution, file writes, environment inspection, and network-capable setup steps, but it does not declare any tool scope or allowed-tools restrictions. That omission weakens governance and increases the chance the skill is invoked with broader capabilities than necessary, making misuse or accidental side effects harder to contain.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad natural-language phrases such as '帮我发帖' that may match ambiguous user requests and invoke a high-impact publishing workflow unintentionally. Because this skill can perform real external posting, overbroad triggers materially raise the risk of accidental activation and unintended account actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill relies on a persistent Chrome profile and stored login session to automate posting on behalf of the user, and it also writes article content to a predictable temporary path. Persistent sessions and reusable local artifacts increase the risk that another local process, user, or later invocation can reuse authentication state or access sensitive unpublished content.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
1. Clarify topic, tone, length only if truly ambiguous (one short question max).
2. **Compose** title + article text yourself.
3. **Write file** e.g. `/tmp/zhihu_post_body.txt` (use your file/write tool — not inline in bash).
4. **Exec** `zhihu_publish.sh` with `--title`, `--body-file`, `--publish`, **`--submit`**, `--json`.

Do **not** ask the user to run bash commands. Do **not** put the article body in exec args.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 58)May include surrounding context.

Version must match the chromedriver you install. Example 148.0.7778.215:

bash
sudo dnf install -y \
  https://dl.google.com/linux/chrome/rpm/stable/x86_64/google-chrome-stable-148.0.7778.215-1.x86_64.rpm

google-chrome-stable --version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 64)May include surrounding context.

Version must match the chromedriver you install. Example 148.0.7778.215:

bash
sudo dnf install -y \
  https://dl.google.com/linux/chrome/rpm/stable/x86_64/google-chrome-stable-148.0.7778.215-1.x86_64.rpm

google-chrome-stable --version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 65)May include surrounding context.

Version must match the chromedriver you install. Example 148.0.7778.215:

bash
sudo dnf install -y \
  https://dl.google.com/linux/chrome/rpm/stable/x86_64/google-chrome-stable-148.0.7778.215-1.x86_64.rpm

google-chrome-stable --version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

Version must match the chromedriver you install. Example 148.0.7778.215:

bash
sudo dnf install -y \
  https://dl.google.com/linux/chrome/rpm/stable/x86_64/google-chrome-stable-148.0.7778.215-1.x86_64.rpm

google-chrome-stable --version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/linux-vnc-setup.md (reported line 10)May include surrounding context.

Version must match the chromedriver you install. Example 148.0.7778.215:

bash
sudo dnf install -y \
  https://dl.google.com/linux/chrome/rpm/stable/x86_64/google-chrome-stable-148.0.7778.215-1.x86_64.rpm

google-chrome-stable --version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/linux-vnc-setup.md (reported line 29)May include surrounding context.

Version must match the chromedriver you install. Example 148.0.7778.215:

bash
sudo dnf install -y \
  https://dl.google.com/linux/chrome/rpm/stable/x86_64/google-chrome-stable-148.0.7778.215-1.x86_64.rpm

google-chrome-stable --version

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/linux-vnc-setup.md (reported line 35)May include surrounding context.

Manual (user dir, example 147.0.7727.55):

bash
mkdir -p ~/.local/bin
wget https://storage.googleapis.com/chrome-for-testing-public/147.0.7727.55/linux64/chromedriver-linux64.zip
unzip -o chromedriver-linux64.zip
mv -f chromedriver-linux64/chromedriver ~/.local/bin/

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install_chromedriver.sh (reported line 10)May include surrounding context.

sh
#
# Override:
#   CHROME_VERSION=148.0.7778.215 bash install_chromedriver.sh
#   CHROMEDRIVER_INSTALL_DIR=/usr/local/bin   # use: sudo env CHROMEDRIVER_INSTALL_DIR=... bash ...

set -euo pipefail

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install_chromedriver.sh (reported line 53)May include surrounding context.

sh
#
# Override:
#   CHROME_VERSION=148.0.7778.215 bash install_chromedriver.sh
#   CHROMEDRIVER_INSTALL_DIR=/usr/local/bin   # use: sudo env CHROMEDRIVER_INSTALL_DIR=... bash ...

set -euo pipefail

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install_chromedriver.sh (reported line 70)May include surrounding context.

sh
#
# Override:
#   CHROME_VERSION=148.0.7778.215 bash install_chromedriver.sh
#   CHROMEDRIVER_INSTALL_DIR=/usr/local/bin   # use: sudo env CHROMEDRIVER_INSTALL_DIR=... bash ...

set -euo pipefail

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install_chromedriver.sh (reported line 71)May include surrounding context.

sh
#
# Override:
#   CHROME_VERSION=148.0.7778.215 bash install_chromedriver.sh
#   CHROMEDRIVER_INSTALL_DIR=/usr/local/bin   # use: sudo env CHROMEDRIVER_INSTALL_DIR=... bash ...

set -euo pipefail

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install_chromedriver.sh (reported line 83)May include surrounding context.

sh
#
# Override:
#   CHROME_VERSION=148.0.7778.215 bash install_chromedriver.sh
#   CHROMEDRIVER_INSTALL_DIR=/usr/local/bin   # use: sudo env CHROMEDRIVER_INSTALL_DIR=... bash ...

set -euo pipefail

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install_chromedriver.sh (reported line 90)May include surrounding context.

sh
unzip -o -q "$TMPDIR/chromedriver.zip" -d "$TMPDIR"
DEST="$INSTALL_DIR/chromedriver"
cp -f "$TMPDIR/chromedriver-linux64/chromedriver" "$DEST"
chmod 755 "$DEST"

ENV_FILE="$SCRIPTS_DIR/chromedriver.env"
cat >"$ENV_FILE" <<EOF

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install_chromedriver.sh (reported line 97)May include surrounding context.

sh
# Auto-generated by install_chromedriver.sh — sourced by zhihu_publish.sh
export CHROMEDRIVER_PATH=$DEST
EOF
chmod 644 "$ENV_FILE"

echo ""
echo "Installed: $DEST"

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The script deliberately starts Chrome in the background with a persistent user-data directory and explicitly relies on retained login cookies. In this skill’s context, that creates a long-lived authenticated Zhihu browser profile exposed through a local remote-debugging port, which increases the risk of session theft or unauthorized posting if the host, VNC session, or local user account is compromised.

Content

Scanner excerpt · scripts/start_chrome_debug.sh (reported line 93)May include surrounding context.

sh
if [[ "$DETACH" -eq 1 ]]; then
  echo "Starting Chrome in background (profile keeps login cookies)..."
  nohup "${CHROME_CMD[@]}" >/tmp/chrome-zhihu-automation.log 2>&1 &
  echo "PID: $!"
  sleep 2
  if curl -sf "http://127.0.0.1:${DEBUG_PORT}/json/version" >/dev/null 2>&1; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

This script attaches to an already-running Chrome instance via the remote debugging port and then relies on the existing authenticated Zhihu session to verify login and publish content. That is a real session-persistence risk because any process able to use this script or access the debugging port can act as the logged-in user without re-authentication, including creating drafts and publishing posts.

Content

Scanner excerpt · scripts/zhihu_attach_standalone.py (reported line 16)May include surrounding context.

python
Usage:
  python3 zhihu_attach_standalone.py --check
  python3 zhihu_attach_standalone.py --open-write
  python3 zhihu_attach_standalone.py --publish-test          # fill draft + screenshot, no submit
  python3 zhihu_attach_standalone.py --publish-test --submit # actually click Publish (careful)
"""

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The README presents the skill as specifically for publishing Zhihu column articles, a Chinese-language platform, but does not explain the locale/language constraint or offer any user choice. This can be a natural-language policy issue when a skill implicitly forces a specific locale context without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: selenium has 2 known advisory(ies) (CVE-2022-28108 (Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content ); CVE-2023-5590 (NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.