Back to skill

Security audit

Douban CLI

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for using a Douban CLI, but it installs an unpinned third-party executable that can handle browser/session cookies and account-changing actions.

Install only if you trust the @marvae24/douban-cli package and publisher. Prefer a pinned, reviewed version before using login, browser-profile extraction, cookie import, export, follow/unfollow, rating, comment, or review commands. Do not paste Douban cookies into chat, and use logout or a restricted profile/account if you no longer need the cached session.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:8
Finding

Unpinned Third-Party CLI Executes Unreviewed Supply-Chain Code

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:123
Finding

Third-Party CLI Is Entrusted with Browser and Imported Session Cookies Without Auditable Credential Handling

Content
View full analysis
] [--profile ] [--cookie-timeout ] [--cookie-stdin | --cookie-file ] ``` ```bash pbpaste | douban login --cookie-stdin Get-Clipboard | douban login --cookie-stdin douban login --cookie-file /path/to/douban-cookies.txt ``` The documentation states that the login process imports and caches the `dbcl2` and `ck` cookie values after account validation. It also supports extracting the login state from a local browser profile. ### Technical Analysis Authentication cookies are bearer credentials: possession of a valid token may allow actions to be performed as the authenticated user. The documented login workflow grants the third-party `douban` executable access to credentials through one of the following channels: - Direct extraction from a supported browser profile. - A cookie header supplied over standard input. - A Netscape-format cookie file. - Clipboard content piped into standard input by the user. The project does not include the CLI implementation, so the audit cannot verify: - Whether browser access is restricted to the minimum required Douban cookies. - Whether cached credentials are encrypted or protected with restrictive permissions. - Whether tokens are ever written to logs or diagnostic output. - Whether credentials are transmitted only to expected Douban endpoints. - Whether imported cookie files and in-memory values are securely handled. The skill includes meaningful safeguards: login requires user confirmation, automatic clipboard or environment fallback is prohibited, users are told not to paste cookies into chat, and cookie disclosure or upload is forbidden. These controls reduce accidental exposure but cannot establish that the unaudited executable safely implements cred ...[truncated 1661 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file forces a specific language for activation, usage, warnings, and operational steps, and nowhere indicates that the user can choose another language. That creates a natural-language policy issue because the skill effectively imposes a locale/language constraint without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.