T09 · Insecure Skill Coding Practices
- Location
publish_tencent.py:73- Finding
Authentication Cookie Exposed Through Process Arguments and Shell History
- Content
View full analysis
<正文> [cookie]") sys.exit(1) title = sys.argv[1] content = sys.argv[2] cookie = sys.argv[3] if len(sys.argv) > 3 else None ``` `README.md:26-36`: ```bash python3 publish_tencent.py "文章标题" "文章正文(支持Markdown)" "你的Cookie" ``` ```bash python3 publish_tencent.py \ "OpenClaw + Qwen3-TTS 自动化简报系统实战" \ "本文介绍如何用 **OpenClaw** 和 Qwen3-TTS 构建每日自动化简报系统..." \ "skey=xxx; qcloud_uid=xxx; qcommunity_session=xxx; ..." ``` `install.sh:15`: ```bash echo ' python3 ~/.openclaw/workspace/publish_tencent.py "标题" "正文" "Cookie"' ``` ### Technical Analysis The script accepts the complete Tencent Cloud authentication Cookie through `sys.argv`. Command-line arguments are not an appropriate transport for session credentials because they may be exposed through: - Process inspection facilities while the command is running. - Shell command history after execution. - Terminal session recording. - Automation, monitoring, or endpoint telemetry that captures process command lines. - Diagnostic logs that record invoked commands. The Cookie includes authenticated session fields such as `skey` and `qcommunity_session`. Consequently, disclosure may permit session reuse until the Cookie expires or is revoked. This behavior also conflicts with the statement in `SKILL.md` that the Cookie is retained only in memory and discarded after use. Although the script does not explicitly write the Cookie to a file, the documented command-line workflow can cause it to be persisted by the shell or surrounding system. ### Attack Path 1. A user follows the documented c ...[truncated 1357 chars]- Remediation
View remediation
