T09 · Insecure Skill Coding Practices
- Location
references/api-creator.md:24- Finding
Transmission of Login-Equivalent Session Cookies to a Third-Party API
- Content
View full analysis
Vulnerability Details
File Location:
references/api-creator.md:24-67
Vulnerability Type: Third-party disclosure of authentication credentials
Risk Level: HighVulnerable Code Snippet
markdown ## fetch_author_diagnosis `POST /api/v1/douyin/creator_v2/fetch_author_diagnosis` This endpoint requires your platform session Cookie, which is a sensitive credential equivalent to a login session. Only provide your Cookie if you fully trust the service provider. Your Cookie/session data will be transmitted to a third-party API service (`https://www.aconfig.cn`) for processing.The same behavior is documented for additional endpoints in:
references/api-user.md:458-479references/api-video.md:913-934references/api-video.md:968-989references/api-video.md:1028-1049references/api-video.md:1131-1152references/api-video.md:1235-1256references/api-video.md:1348-1369references/api-video.md:1438-1459references/api-video.md:1501-1522references/api-video.md:1609-1630references/api-video.md:1698-1719
Technical Analysis
The Skill instructs the Agent to obtain a user's full Douyin browser-session cookie and forward it to
https://www.aconfig.cn. A browser-session cookie is a bearer credential: possession may be sufficient to impersonate the authenticated user until the session expires or is revoked.This credential has substantially greater authority than the Skill-specific
MAXHUB_API_KEY. The Skill's core public-data analytics features do not require possession of a user's full authenticated browser session. Consequently, cookie forwarding exceeds the minimum privileges necessary for most declared functionality.Security warnings disclose the danger but do not provide technical controls. The Skill does not enforce:
- Explicit, endpoint-specific confirmation immediately before transmission.
- Credential scoping or least-privile ...[truncated 1437 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove endpoints that require full browser-session cookies from the default analytics Skill.
- Replace browser cookies with narrowly scoped OAuth or API tokens whenever the upstream platform supports them.
- Place credential-dependent functionality in a separate, explicitly privileged Skill.
- Require informed, endpoint-specific user confirmation immediately before each credential transfer.
- Never request credentials through conversational prompts that may be retained in history.
- Accept credentials only through a secret-management interface that prevents display and logging.
- Redact cookies from application logs, HTTP diagnostics, traces, error messages, and audit output.
- Enforce short-lived credentials and provide an immediate revocation procedure.
- Block primary-account credentials and clearly require a disposable test account where cookie use remains unavoidable.
- Obtain and link independently reviewable privacy, retention, deletion, and incident-response policies for the receiving provider.
