T09 · Insecure Skill Coding Practices
- Location
weiyun_skills/login.py:32- Finding
Authentication Cookies Are Persisted in Plaintext Without Enforced Access Controls
- Content
View full analysis
None: """Save cookies data to a JSON file. Args: cookies_data: Cookies data to save. save_path: File path to save cookies. """ cookies_data["update_time"] = get_timestamp() with open(save_path, "w", encoding="utf-8") as f: json.dump(cookies_data, f, ensure_ascii=False, indent=2) ``` The CLI also accepts the complete cookie string as a command-line argument: ```python parser.add_argument( "--cookies", type=str, default="", help="Cookie string from browser (required for cookies method)" ) ``` A similar option exists in `weiyun_skills/main.py`: ```python parser.add_argument( "--cookies", type=str, default=None, help="Cookies string (overrides cookies.json)" ) ``` ### Technical Analysis The `_save_cookies` function writes the complete Tencent authentication state to a plaintext JSON file. The saved data includes both `cookies_str` and `cookies_dict`, which can contain reusable session credentials such as `p_skey`, `skey`, `pt4_token`, and related account cookies. The file is created with the process's default permissions, subject only to the current umask. The implementation does not: - Explicitly restrict the file to owner-only access, such as mode `0600`. - Check whether the destination is a symbolic link. - Use atomic and exclusive file creation. - Encrypt the credential material or use an operating-system credential store. - Warn the user if the destination is accessible by other users. On a system with a permissive umask, the resulting file may be readable by other local accounts or processes. A user-controlled `save_path ...[truncated 1834 chars]- Remediation
View remediation
