T09 · Insecure Skill Coding Practices
- Location
scripts/common.py:39- Finding
Session cookies are persisted without restrictive file permissions
- Content
View full analysis
dict: """Write config/cookies.json while preserving entries that were not modified.""" os.makedirs(CONFIG_DIR, exist_ok=True) d = {} if os.path.exists(CONFIG_FILE): try: with open(CONFIG_FILE, encoding="utf-8") as f: d = json.load(f) except Exception: d = {} d.setdefault("bilibili", {"cookie": ""}) d.setdefault("tieba", {"cookie": ""}) if bili is not None: d["bilibili"]["cookie"] = bili.strip() if tieba is not None: d["tieba"]["cookie"] = tieba.strip() with open(CONFIG_FILE, "w", encoding="utf-8") as f: json.dump(d, f, ensure_ascii=False, indent=2) return d ``` The configuration utility also supports passing complete cookies through process arguments: ```python if args[i] == "--bili-cookie" and i + 1 < len(args): bili, i = args[i + 1], i + 1 elif args[i] == "--tieba-cookie" and i + 1 < len(args): tieba, i = args[i + 1], i + 1 ``` ### Technical Analysis Bilibili and Tieba cookies are account session credentials. The application writes them to `config/cookies.json` using a normal `open(..., "w")` operation without explicitly setting the file mode to owner-only access. For a newly created file, effective permissions depend on the process umask. In environments with a permissive umask, the file may be readable by other local users or processes. Existing insecure permissions are also not corrected. The documented command-line cookie options create a second exposure channel. Command-line arguments may be retained in shell history and can be visible through process-inspection ...[truncated 1268 chars]- Remediation
View remediation
