T09 · Insecure Skill Coding Practices
- Location
src/auth.py:88- Finding
Bilibili Session Credentials Are Stored with Unenforced Permissions and Partially Logged
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent and not malicious, but it handles live Bilibili session cookies, persistent local indexes, and optional outbound PDF delivery in ways users should review carefully.
Install only if you are comfortable giving this skill reusable Bilibili session cookies. Keep the .env file private, set restrictive permissions such as chmod 600 where applicable, avoid sharing logs that may contain cookie prefixes, leave delivery set to none unless you intentionally want PDFs sent to a chat platform, and review or upgrade the pinned dependencies before regular use. Remember that summaries, history, topic data, and vector search data persist locally under the skill data directory, and cron setup can make the skill run in the background.
src/auth.py:88Bilibili Session Credentials Are Stored with Unenforced Permissions and Partially Logged
chromadb==0.5.23 is flagged with multiple severe advisories including authorization bypass and code injection. If the skill exposes ChromaDB locally or uses it to store/query untrusted embeddings or metadata, these issues can lead to unauthorized data access, tampering, or potentially arbitrary code execution.
This finding is valid because the documentation directs users to place live Bilibili session cookies into a plaintext .env file. While credential collection is necessary for the skill's functionality, storing reusable session material in a local flat file increases the chance of theft through accidental disclosure, backups, misconfigured permissions, or repository commits.
首次使用 Skill 时,Hermes 会自动提示输入 Cookie 值。
方式 B:手动创建 .env 文件
cd ~/.hermes/skills/bilibili-reader
The explicit step to create and populate a .env file with authentication cookies creates a concrete credential exposure path. In this skill's context, the tokens are not harmless examples; they are real account-linked session artifacts that could be abused for authenticated requests if leaked.
cd ~/.hermes/skills/bilibili-reader
cp .env.example .env
编辑 .env 文件:
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
echo '{"processed":[],"stats":{"total_processed":0,"last_processed_at":null}}' > ~/.hermes/skills/bilibili-reader/data/processed.json
# 清除 Topic 图谱
rm ~/.hermes/skills/bilibili-reader/data/topic_graph.json
# 清除向量库
rm -rf ~/.hermes/skills/bilibili-reader/data/chroma_db/
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm ~/.hermes/skills/bilibili-reader/data/topic_graph.json
rm -rf ~/.hermes/skills/bilibili-reader/data/chroma_db/
**Q: PDF 中的中文显示为方块?**
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm ~/.hermes/skills/bilibili-reader/data/topic_graph.json
rm -rf ~/.hermes/skills/bilibili-reader/data/chroma_db/
**Q: PDF 中的中文显示为方块?**
Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.
Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.
Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.
Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.
Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.
Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.
Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.
Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.
Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.
Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.
Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.
Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.
Semantic/vector indexing into ChromaDB materially changes the data handling model from transient summarization to persistent searchable storage. If users are not told that summaries and related metadata will be embedded and stored locally, they cannot make an informed decision about retention and privacy risk.
The skill relies on writing sensitive configuration and authentication material to a .env file, which is plain-text local storage and commonly mishandled, committed, or exposed through logs and tooling. Session cookies and delivery settings stored this way can be reused to access the user's Bilibili account or route outputs externally.
python -m src --config
DELIVERY_PLATFORM=wechat
The workflow explicitly creates a .env containing extracted cookies after browser-based login. Because these are bearer credentials, compromise of the file can enable unauthorized account access without needing the user's password or MFA challenge.
- **验证**:`cd ${HERMES_SKILL_DIR} && .venv/bin/python -c "from src.bilibili_api import BilibiliAPI; ..."` 如果走 curl 路径会正常返回
### WSL 环境下 Playwright 登录
- **症状**:`python -m src --login` 运行后无输出,无浏览器弹出,.env 未创建
- **原因**:WSL 默认无 GUI,Playwright `headless=False` 无法显示浏览器窗口
- **解决**:检查 WSLg 是否可用(`echo $DISPLAY`,`ls /mnt/wslg/`)
- WSLg 可用时,Playwright GUI 正常工作。但直接 `python -m src --login` 可能因 stdout 缓冲看不到输出
Troubleshooting guidance instructs users to manually copy browser cookies into .env, encouraging direct handling of highly sensitive session secrets. Manual extraction increases the chance of accidental disclosure, phishing-style misuse, clipboard leakage, or insecure storage in shell history and files.
cookies = login_via_browser(save_to_env=True)
print('Result:', cookies)
```
- WSLg 不可用时,需手动从浏览器获取 Cookie 写入 .env
### 交互式配置脚本 EOFError
- **症状**:`python -m src --config` 或 `run_setup()` 报 `EOFError: EOF when reading a line`
protobuf==4.25.5 is reported with denial-of-service and recursion-related advisories. If the skill processes attacker-controlled protobuf or JSON-encoded protobuf-like data from external services, this can lead to resource exhaustion or parser instability.
weasyprint==62.3 is associated with multiple SSRF-related advisories and content-handling issues. This skill generates PDFs from externally sourced subtitles, comments, or other web content, which makes an unsafe HTML/CSS-to-PDF engine materially more dangerous because rendering may trigger network fetches or unsafe resource resolution.
The function is explicitly designed to capture authentication cookies from a logged-in browser session and return them to the caller. Returning session cookies as plain strings increases the chance they are logged, reused by unrelated code, or exfiltrated, enabling unauthorized account access.
"""通过 Playwright 打开浏览器,用户扫码后自动提取 Cookie
Args:
save_to_env: 是否自动保存到 .env 文件
Returns:
成功返回 {"SESSDATA": "...", "bili_jct": "...", "buvid3": "..."}, 失败返回 None
No suspicious patterns detected.