T09 · Insecure Skill Coding Practices
- Location
scripts/kosmi-connect.sh:35- Finding
Credentials Can Be Submitted to an Untrusted Browser Origin
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly aligned with Kosmi browser automation, but it handles credentials and long-running automation in ways users should review before installing.
Review before installing. Use only a trusted Kosmi room URL, avoid putting reusable passwords in the plugin .env, prefer an already-authenticated encrypted session, and do not run the loop under cron or unattended until the .env loading, URL validation, and /tmp PID/FIFO handling are fixed.
scripts/kosmi-connect.sh:35Credentials Can Be Submitted to an Untrusted Browser Origin
scripts/kosmi-connect.sh:27Configuration Files Are Executed as Arbitrary Shell Code
scripts/kosmi-loop.sh:46Predictable Shared Temporary Files Permit PID, FIFO, and Symlink Abuse
SKILL.md:107Documentation Encourages Unmanaged Cross-Session Scheduling
SKILL.md:10Unpinned Package Is Installed Globally from the npm Registry
Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.
| Role | Name Pattern(s) | Purpose |
|---|---|---|
| textbox | `message`, `chat`, `type a message` | Chat input box |
| button | `send` | Send chat message |
| button | `apps`, `add`, `+`, `media` | Open the apps/media modal |
| link | `app`, `add media` | Alternative apps trigger |
| button | `settings`, `gear` | Room settings |
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# =============================================================================
# kosmi-connect.sh — Connect to a Kosmi room via agent-browser
#
# Reads .env from plugin root, opens the room URL, handles nickname/login
# prompts, and verifies the agent is in the room.
#
# Usage:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# =============================================================================
# kosmi-connect.sh — Connect to a Kosmi room via agent-browser
#
# Reads .env from plugin root, opens the room URL, handles nickname/login
# prompts, and verifies the agent is in the room.
#
# Usage:
The script automatically loads and sources a .env file from the plugin root, which may contain credentials such as KOSMI_EMAIL and KOSMI_PASSWORD. Sourcing a file executes shell syntax, so if an attacker can modify .env they can achieve arbitrary code execution in the script's context, and the script also broadens exposure of secrets by auto-importing them into the environment for browser automation.
PLUGIN_ROOT="$(cd "$SCRIPT_DIR/../../.." && pwd)"
# ---------------------------------------------------------------------------
# Load .env
# ---------------------------------------------------------------------------
ENV_FILE="${PLUGIN_ROOT}/.env"
if [[ -f "$ENV_FILE" ]]; then
The combination of checking for ${PLUGIN_ROOT}/.env and then sourcing it means the script trusts a local file as executable shell input. In this skill context, that is more dangerous because the script handles authentication credentials and drives a browser session, so a poisoned .env could both steal secrets and alter automation behavior.
# ---------------------------------------------------------------------------
# Load .env
# ---------------------------------------------------------------------------
ENV_FILE="${PLUGIN_ROOT}/.env"
if [[ -f "$ENV_FILE" ]]; then
set -a
# shellcheck disable=SC1090
Referencing the plugin root specifically to load a top-level .env file creates a path to broad secret access that is not necessary for basic Kosmi DJ automation. In this skill context, the loop script is intended to control browser playback, so reaching into shared plugin configuration increases the chance that unrelated API keys or tokens are exposed to this process and any subprocesses it launches.
PLUGIN_ROOT="$(cd "$SCRIPT_DIR/../../.." && pwd)"
# ---------------------------------------------------------------------------
# Load .env
# ---------------------------------------------------------------------------
ENV_FILE="${PLUGIN_ROOT}/.env"
if [[ -f "$ENV_FILE" ]]; then
The code conditionally loads .env from disk and then sources it, which can expose credentials and execute attacker-controlled shell content if that file is altered. Because the script subsequently invokes other programs and helper scripts, any exported secrets from .env may propagate beyond the immediate process boundary, amplifying the blast radius.
# ---------------------------------------------------------------------------
# Load .env
# ---------------------------------------------------------------------------
ENV_FILE="${PLUGIN_ROOT}/.env"
if [[ -f "$ENV_FILE" ]]; then
set -a
# shellcheck disable=SC1090
Referencing and loading the repository-level .env gives this script access to credentials and sensitive configuration unrelated to playing a video in Kosmi. In this skill context, that capability is unjustified and increases risk because browser automation scripts often invoke external tools and may leak environment data through child processes, debugging, or future modifications.
PLUGIN_ROOT="$(cd "$SCRIPT_DIR/../../.." && pwd)"
# ---------------------------------------------------------------------------
# Load .env
# ---------------------------------------------------------------------------
ENV_FILE="${PLUGIN_ROOT}/.env"
if [[ -f "$ENV_FILE" ]]; then
The conditional block around .env existence is part of a flow that sources and exports all values from that file, effectively granting this simple playback script credential access. Because the skill's purpose is narrow UI automation, loading shared secrets is disproportionate and creates unnecessary exposure if the script or its dependencies mis-handle environment variables.
# ---------------------------------------------------------------------------
# Load .env
# ---------------------------------------------------------------------------
ENV_FILE="${PLUGIN_ROOT}/.env"
if [[ -f "$ENV_FILE" ]]; then
set -a
# shellcheck disable=SC1090
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
PLUGIN_ROOT="$(cd "$SCRIPT_DIR/../../.." && pwd)"
# Load .env for session name
ENV_FILE="${PLUGIN_ROOT}/.env"
if [[ -f "$ENV_FILE" ]]; then
set -a
# shellcheck disable=SC1090
The skill explicitly instructs operators to store Kosmi room URLs, login credentials, and persistent browser session settings in a .env file and to rely on reusable session state, but it does not warn users that these values are sensitive or that persistent sessions may retain authenticated access. In a browser-automation skill, this increases the chance of accidental credential exposure, misuse of stored sessions, or unintended access to a private room if the environment or session store is shared.
The documentation explicitly recommends persistent browser sessions that store cookies, localStorage, and sessionStorage on disk. In the context of a browser-automation skill for joining and controlling Kosmi rooms, this can retain authentication tokens and room access state across runs, increasing the risk of credential theft, unintended account reuse, or privacy leakage if the host system is shared or compromised.
The example shows a password being passed directly on the command line to agent-browser fill, which can expose secrets via shell history, process listings, logs, or terminal recording. In an automation skill, users may copy this pattern into scripts or operational environments, causing accidental credential disclosure beyond the immediate browser interaction.
The script sources a repository-root .env file and exports all variables into its environment even though this loop only appears to need a narrowly scoped session name. Sourcing .env as shell code is dangerous because it executes arbitrary shell syntax if the file is modified, and exporting every variable also broadens credential exposure to child processes such as agent-browser and helper scripts.
The script sources a plugin-wide .env file and exports all variables into its environment even though its stated purpose is only to automate Kosmi video playback. Sourcing .env executes shell syntax from that file and unnecessarily exposes unrelated secrets or configuration to this process and any subprocesses, expanding the blast radius if the script, logs, or called tools are compromised.
The skill describes an auto-loop/background mode that continues until interrupted and writes a PID file, but it does not prominently warn users that the process may keep running autonomously after the initiating interaction. In this context, that can lead to unintended ongoing browser activity, repeated room interaction, resource consumption, and confusion about how to stop the automation.