T09 · Insecure Skill Coding Practices
- Location
lib/auth-web.js:15- Finding
TLS Certificate Verification Is Disabled During Web Authentication
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its 115 cloud-drive purpose, but it needs review because it saves reusable account cookies and can change cloud files without the confirmations its documentation promises.
Install only if you are comfortable giving this skill access to your 115 account and cloud-file structure. Review the cookie storage behavior, avoid the alternate web-auth flow until TLS validation is fixed, and use smart organization only after manually confirming the files and destination because the current implementation can move files immediately.
lib/auth-web.js:15TLS Certificate Verification Is Disabled During Web Authentication
lib/client/http-client.js:147115 Session Cookies Can Be Sent to Arbitrary Absolute URLs
lib/storage/cookie-store.js:43Cookie Encryption Key Is Derived from Predictable Machine Metadata
index.js:260Bulk Cloud-File Reorganization Executes Without a Preview or Explicit Confirmation
This code persists active authentication cookies to storage with no visible safeguards such as encryption, scope restriction, secure lifecycle controls, or user consent handling. Stored session cookies can be replayed to hijack the user's 115 account, and this skill's purpose—automated QR login and cookie harvesting—makes the risk more acute than in ordinary web automation.
The HTTPS client is explicitly configured with rejectUnauthorized: false, which disables TLS certificate validation for requests in the web login flow. This allows man-in-the-middle attackers to intercept or alter QR-login responses and potentially steal session cookies or inject attacker-controlled authentication data.
The clearRecycleBin method directly calls /files/clear_recycle and returns success, but there is no confirmation prompt, user-facing notice, or warning comment describing the destructive nature of emptying the recycle bin. This is a safety-critical operation that can permanently affect user data.
The offline download feature accepts magnet/HTTP inputs and initiates remote network activity, but the documentation does not clearly warn users about privacy implications, third-party fetching, or account/network traces created by such tasks. In a cloud-drive context, that omission increases the chance users trigger behavior without understanding that it causes persistent external retrieval operations.
The trigger phrase '下载 xxx' is broad enough to match ordinary conversational requests or unrelated download intents, which can cause the skill to invoke offline download behavior unexpectedly. In this skill, that behavior creates network-side tasks and may consume account resources, so accidental activation has real side effects beyond a harmless misunderstanding.
The smart organization feature can automatically classify and move files, which changes file structure and may disrupt user organization or workflows, yet the description does not clearly warn about those side effects. In this skill, file-management actions operate on cloud storage state, so insufficient warning can lead to unintended bulk modifications that are difficult to review or reverse.
The phrase '整理文件' is vague and maps to an operation that can reorganize user data, potentially moving many files at once. Because this skill manages cloud storage contents, an imprecise trigger raises the risk of unintended bulk modification to folder structure and user workflows.
The skill performs a state-changing cloud storage operation (autoOrganizeByType) immediately when the message contains words like '自动' or '智能', without presenting a preview, warning, or explicit confirmation. Because this action moves user files in remote storage, ambiguous natural-language input or accidental triggering could cause unintended reorganization and operational disruption.
The code reads authenticated browser cookies after QR login and converts them into reusable credential fields, then later saves them via the cookie store. Although comments describe the mechanics, there is no user-facing prompt, log message, or warning that sensitive authentication material will be collected and stored.
On successful login, the code saves authentication cookies via this.cookieStore.save(status.cookie), which is a sensitive write of credential material. While the file has internal comments about login flow, it does not provide any user-facing prompt, warning, or disclosure that session cookies will be stored.
The module persists long-lived login cookies locally for up to 90 days, but the code provides no built-in disclosure, consent, or safeguards around storing authentication material. In a chat/agent context, silently retaining reusable session tokens increases the risk of account compromise if local storage is exposed, misconfigured, or accessed by other components.
This code attaches a Cookie header containing UID/CID/SE values to outbound axios requests, which is a network operation transmitting sensitive authentication data. While the code has technical comments about request handling, it does not include any user-facing warning, confirmation, or disclosure that credentials will be sent over the network.
The module stores potentially sensitive fields such as userInput, assistantOutput, details, and context in memory and later exposes records through getHistory() and export() with no redaction, consent check, or sensitivity warning. In an agent context, history often contains secrets, prompts, tokens, personal data, or tool outputs, so exporting or displaying it wholesale can cause unintended data disclosure.
The module returns user-visible strings such as 暂无历史记录, 历史记录, and 历史统计 only in Chinese, and relative time formatting is also fixed to Chinese phrases. This forces a specific language/locale without any opt-in or configuration path, which matches the policy category for language or locale violations.
This JavaScript file includes natural-language recovery guidance such as 回复"登录 115"重新扫码 and 使用 /115 登录 命令 that assumes Chinese as the required interaction language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.
The code exposes a batchDelete method that performs irreversible remote deletion against '/rb/delete' for arbitrary file IDs without any built-in confirmation, safeguard, dry-run mode, or policy check in this module. In an agent or automation context, this raises the risk of accidental or prompt-induced mass deletion because a single mistaken call can remove many files at once.
The deleteFiles method issues a deletion request to /files/delete for one or more file IDs, but the code provides no confirmation prompt, warning log, or cautionary comment beyond the basic function description. Because deletion affects user data and may be safety-critical, this lacks visible disclosure within the file.
This method reads a local file and sends its contents to a remote upload endpoint, which is a safety-relevant network transmission of user data. While the code has developer comments describing upload behavior, it provides no confirmation prompt, user-facing log/print, or explicit warning to the user before transmitting the file.
The large-file path reads local file data in chunks and posts base64-encoded content to upload endpoints, which is a direct transmission of user file contents. The function contains internal comments for developers, but no confirmation, print/log message, or other user-facing notice that local data is being uploaded.
The download routine writes remote content directly to an arbitrary caller-supplied savePath without validating or constraining the destination. If untrusted input can influence savePath, this can overwrite sensitive local files or place attacker-controlled content in dangerous locations, making the file-writing behavior security-relevant beyond mere lack of disclosure.
The skill implements both single-task deletion and bulk cleanup of completed tasks through remote API calls, which are destructive operations affecting user-managed download tasks. Although methods are commented, there is no confirmation prompt, visible logging/print, or explicit warning to the user before deletion occurs.
This module makes multiple API calls to enumerate file metadata, storage usage, recycle-bin contents, large files, duplicates, and temporary files, but the file itself contains no user-consent, disclosure, or permission-gating mechanism before inspecting potentially sensitive file information. Even if intended for cleanup assistance, this creates a privacy risk because a caller can trigger broad metadata collection and formatted reporting of filenames, locations, and identifiers without any visible notice or explicit opt-in at this layer.
The skill returns user-facing status messages, suggestions, and formatted reports exclusively in Chinese. This enforces a specific language/locale without offering the user a choice or documenting a justified locale restriction.
The autoOrganizeByType method creates folders and moves files, which changes user data layout and can be disruptive if triggered unexpectedly. Although a dryRun option exists, there is no confirmation prompt, user-facing log/output, or explicit warning comment/docstring that this operation will reorganize files in place.
The autoOrganizeByTime method automatically creates folders and moves files into them, which is a safety-relevant file modification operation. The code does not show any prompt, print/log statement, or explicit warning in the surrounding comments indicating that user files will be reorganized when dryRun is false.
Detected: suspicious.exposed_secret_literal, suspicious.insecure_tls_verification