T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:16- Finding
Unrestricted Browser Cookie Import Exposes Sensitive Authentication Material
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 16
Vulnerability Type: Browser credential access without documented scope restrictions
Risk Level: MediumComplete Code Snippet:
markdown spogo setup - Import cookies: `spogo auth import --browser chrome`Technical Analysis
The skill instructs the agent to execute a third-party program that imports authentication cookies directly from Chrome. Browser cookie stores contain sensitive session material, and access to them crosses a significant security boundary.
The instruction does not specify a Chrome profile, limit extraction to Spotify domains, identify which cookies are accessed, or require the user to review and explicitly approve the operation immediately before execution. Although cookie import may be an intended authentication mechanism for
spogo, the unrestricted instruction delegates access to sensitive browser data without documenting least-privilege controls.The project contains no executable implementation of
spogo, so the audit cannot establish that the program actually extracts unrelated cookies or exfiltrates credentials. The identified risk is the excessive trust granted to an external binary and the absence of safeguards around credential-store access.Attack Path
- An agent loads the skill and determines that Spotify authentication is required.
- Following
SKILL.md, the agent executesspogo auth import --browser chrome. - The installed
spogobinary is granted or obtains access to Chrome's cookie storage. - If that binary or its distribution channel has been compromised, it can attempt to read authentication material available through that access.
- Exposed session material could then be retained or transmitted by the compromised binary and potentially used to impersonate affected browser sessions.
This attack path requires a malicious or compromised external executable; the reviewed file does not i ...[truncated 647 chars]
- Remediation
View remediation
Remediation Suggestions
- Prefer Spotify's documented OAuth authorization flow with the minimum required scopes instead of importing browser cookies.
- Require explicit, contemporaneous user confirmation before accessing browser credential storage.
- Document the exact cookie domains and data fields the client needs.
- Restrict import to Spotify-owned domains and a user-selected Chrome profile.
- Explain where imported credentials are stored, how they are protected, and how users can revoke or delete them.
- Avoid logging cookie values, authorization headers, or derived tokens.
- Verify the installed client before permitting credential access, using a trusted release source, immutable version, and integrity verification.
- If domain-restricted import cannot be guaranteed, remove the automated cookie-import instruction and direct users to a safer authorization workflow.
