T09 · Insecure Skill Coding Practices
- Location
config/fallback-sources.json:6- Finding
Committed Zhihu Session Credentials in Plaintext Configuration
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly fetches and stores Zhihu hot-list data, but it ships sensitive cookie material and includes under-scoped diagnostic scripts that users should review before installing.
Install only if you are comfortable reviewing and sanitizing the package first. Remove the bundled cookie values, do not commit or share your own Zhihu cookies, avoid running the anti-crawl/browser-research snippets unless you understand the console/log exposure, and treat generated HTML reports as unsafe if they include untrusted fetched content.
config/fallback-sources.json:6Committed Zhihu Session Credentials in Plaintext Configuration
snippets/cookie-manager.js:103Authentication Cookie Material Disclosed in Process Logs
scripts/generate_html.py:414Stored HTML and JavaScript Injection in Generated Reports
snippets/browser-research.js:12Browser Fetch API Hijacking and Sensitive Session Reconnaissance
A script that only loads file-based cookies while claiming broader auth fallback conceals the real trust boundary: sensitive credentials stored on disk are the primary auth mechanism. This matters because users may not realize the skill depends on local secret material and lacks a safe degraded mode if those credentials are absent or mishandled.
A script that only loads file-based cookies while claiming broader auth fallback conceals the real trust boundary: sensitive credentials stored on disk are the primary auth mechanism. This matters because users may not realize the skill depends on local secret material and lacks a safe degraded mode if those credentials are absent or mishandled.
A script that only loads file-based cookies while claiming broader auth fallback conceals the real trust boundary: sensitive credentials stored on disk are the primary auth mechanism. This matters because users may not realize the skill depends on local secret material and lacks a safe degraded mode if those credentials are absent or mishandled.
A script that only loads file-based cookies while claiming broader auth fallback conceals the real trust boundary: sensitive credentials stored on disk are the primary auth mechanism. This matters because users may not realize the skill depends on local secret material and lacks a safe degraded mode if those credentials are absent or mishandled.
A script that only loads file-based cookies while claiming broader auth fallback conceals the real trust boundary: sensitive credentials stored on disk are the primary auth mechanism. This matters because users may not realize the skill depends on local secret material and lacks a safe degraded mode if those credentials are absent or mishandled.
A script that only loads file-based cookies while claiming broader auth fallback conceals the real trust boundary: sensitive credentials stored on disk are the primary auth mechanism. This matters because users may not realize the skill depends on local secret material and lacks a safe degraded mode if those credentials are absent or mishandled.
A script that only loads file-based cookies while claiming broader auth fallback conceals the real trust boundary: sensitive credentials stored on disk are the primary auth mechanism. This matters because users may not realize the skill depends on local secret material and lacks a safe degraded mode if those credentials are absent or mishandled.
A script that only loads file-based cookies while claiming broader auth fallback conceals the real trust boundary: sensitive credentials stored on disk are the primary auth mechanism. This matters because users may not realize the skill depends on local secret material and lacks a safe degraded mode if those credentials are absent or mishandled.
A script that only loads file-based cookies while claiming broader auth fallback conceals the real trust boundary: sensitive credentials stored on disk are the primary auth mechanism. This matters because users may not realize the skill depends on local secret material and lacks a safe degraded mode if those credentials are absent or mishandled.
A script that only loads file-based cookies while claiming broader auth fallback conceals the real trust boundary: sensitive credentials stored on disk are the primary auth mechanism. This matters because users may not realize the skill depends on local secret material and lacks a safe degraded mode if those credentials are absent or mishandled.
A script that only loads file-based cookies while claiming broader auth fallback conceals the real trust boundary: sensitive credentials stored on disk are the primary auth mechanism. This matters because users may not realize the skill depends on local secret material and lacks a safe degraded mode if those credentials are absent or mishandled.
A script that only loads file-based cookies while claiming broader auth fallback conceals the real trust boundary: sensitive credentials stored on disk are the primary auth mechanism. This matters because users may not realize the skill depends on local secret material and lacks a safe degraded mode if those credentials are absent or mishandled.
A script that only loads file-based cookies while claiming broader auth fallback conceals the real trust boundary: sensitive credentials stored on disk are the primary auth mechanism. This matters because users may not realize the skill depends on local secret material and lacks a safe degraded mode if those credentials are absent or mishandled.
A script that only loads file-based cookies while claiming broader auth fallback conceals the real trust boundary: sensitive credentials stored on disk are the primary auth mechanism. This matters because users may not realize the skill depends on local secret material and lacks a safe degraded mode if those credentials are absent or mishandled.
Referenced artifact was not completely inspected
node snippets/test-simple.js
The file contains a hardcoded Zhihu authenticated cookie set, including session and anti-CSRF-related values, which are effectively secrets embedded in source-controlled configuration. If valid, these credentials can be reused by anyone with access to the skill to impersonate the account, scrape private or rate-limited data, or trigger account abuse; even if expired, embedding real-looking auth material normalizes unsafe secret handling and may indicate credential leakage from a real browser session.
The script is explicitly framed as an anti-crawl research tool and includes logic for testing request-header combinations and analyzing platform defenses, which materially exceeds the stated purpose of a minimalist Zhihu data fetcher. In the context of an agent skill, this creates dual-use capability for reconnaissance against a third-party service’s anti-abuse controls and increases the chance the skill will be used to bypass access restrictions.
The predefined header sets emulate browser-originated traffic and are designed to compare which combinations succeed against the target API, including fetch-related headers commonly used to mimic same-origin browser requests. That behavior is not necessary for ordinary data retrieval and can be used to tune requests to evade anti-bot filtering, making the skill more dangerous in context.
The rate-limit test intentionally sends repeated requests to detect throttling thresholds, which is classic reconnaissance for service-abuse tuning. In a fetcher skill, this is especially concerning because it operationalizes how to measure and adapt to platform defenses rather than simply retrieving user-requested content.
The skill documents use of browser state, local files, shell commands, network retrieval, and database/file generation, but it declares no explicit tool scope or permissions. In an agent setting, this creates an over-privileged and under-specified capability boundary, increasing the risk of unintended file access, credential handling, or network use without clear user consent.
The manifest frames the skill as minimalist data retrieval, but the documentation shows persistent storage, querying, and HTML report generation. This hidden expansion of data lifecycle and outputs is dangerous because it affects privacy, retention, and local file-write exposure in ways users may not anticipate from a simple fetcher.
The skill instructs users to manually copy live authentication cookies into a local config file, which is sensitive credential material. In an agent or shared workstation context, this is particularly dangerous because plaintext cookie storage can enable session hijacking if the file is exposed through backups, logs, repo commits, or over-broad file permissions.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
},
{
"name": "another-api",
"url": "https://api.example.com/zhihu-hot.json",
"type": "json",
"priority": 2
}
The file header and all user-facing strings indicate the tool is designed to operate exclusively in Chinese, and there is no natural-language indication that users may choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
try:
# 运行Node.js脚本获取数据
result = subprocess.run(
['node', str(fetch_script), str(limit)],
capture_output=True,
text=True,
No suspicious patterns detected.