Back to skill

Security audit

Weibo Operations

Security checks for vulnerabilities and agentic risk

Overview

The skill performs the advertised Weibo automation, but it copies broad Chrome session data into a debug profile and enables powerful browser control with weak containment.

Review this before installing. Use only with a dedicated Chrome profile for Weibo, not your primary browser profile. Avoid running delete_all unless the agent asks for explicit confirmation and you have verified the target account. Treat the CDP browser as sensitive while it is open, and prefer pinned dependencies in an isolated Python environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/start_chrome.sh:15
Finding

Excessive Copying of Sensitive Browser Data into an Unsafe Temporary Profile

Content
View full analysis
/dev/null for f in Cookies Cookies-journal "Login Data" "Login Data-journal" \ "Web Data" "Web Data-journal" Preferences "Secure Preferences" \ Favicons "Favicons-journal" "Session Storage" "Session Storage-journal" \ "Local Storage" "Local Storage-journal" IndexedDB Network \ "Origin Bound Certs" "Origin Bound Certs-journal" \ "Extension State" "Extension State-journal" \ "Media Device Salts" "Trust Database" "Trust Database-journal" \ Sessions; do cp -R "$SRC/Default/$f" "$DST/Default/" 2>/dev/null done ``` ### Technical Analysis The script duplicates a broad portion of the user's primary Chrome profile into `/tmp/chrome-debug-profile`. The copied information includes: - Cookies and active authenticated sessions - Saved-login databases - Local storage, session storage, and IndexedDB data for unrelated origins - Browser sessions and history-related state - Extension state - Trust databases and origin-bound certificate information - Chrome's `Local State`, which can be involved in protecting locally stored browser secrets The declared task only requires an authenticated Weibo session. Copying browser data belonging to every website violates least-data and least-privilege principles. The destination is also a predictable path under the shared temporary directory. The script creates the directory without explicitly enforcing restrictive permissions. Although some copied credentials may remain protected by operating-system encryption, active sessions loaded into Chrome can still be exercised through browser automation without decrypting the underlying cred ...[truncated 1463 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/start_chrome.sh:33
Finding

Authenticated Chrome Exposed with an Overly Permissive CDP Origin Policy

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Unpinned Third-Party Automation Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes shell commands and operational scripts but does not declare any tool scope or allowed-tools boundary. In a write-operation skill that can post and mass-delete content, missing explicit permission constraints increases the chance the agent can execute unintended shell actions or invoke this capability without clear sandboxing expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation language is broad enough that ordinary discussion of Weibo actions could trigger a skill that performs real account-changing operations. Because this skill posts, comments, likes, reposts, and deletes using an authenticated browser profile, accidental activation can translate directly into unauthorized actions on a live account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation exposes destructive operations like delete_all without any explicit confirmation, dry-run, or warning requirement. In the context of an authenticated social-media automation skill, this creates a significant risk of irreversible mass deletion from ambiguous prompts, mistaken invocations, or agent error.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The rm -rf on the destination path is a destructive file operation, and the script does not provide any user-facing notice or confirmation before removing that directory. The current comments describe building a clean profile but do not clearly warn that prior contents of /tmp/chrome-debug-profile will be deleted.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script clones a large set of Chrome profile artifacts, including cookies, login databases, local/session storage, IndexedDB, and trust-related files, into a separate debug profile. For a skill whose purpose is limited to Weibo write operations, this grants the automation environment access to far more sensitive browser state than necessary, increasing the blast radius to unrelated accounts, session tokens, and browsing secrets if the profile is accessed, exfiltrated, or reused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Copying cookies, login data, and other persistent browser artifacts into /tmp creates a second accessible copy of sensitive credentials and session material without any notice or consent boundary. In the context of a browser automation skill, this is especially dangerous because it can silently inherit authenticated sessions not only for Weibo but potentially for many other services present in the original profile.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script enables Chrome remote debugging and sets --remote-allow-origins="*", exposing a powerful browser control interface. In combination with a profile seeded from the user's real browser data, any local process—or in some environments a broader origin/client set—could abuse CDP to read cookies, inspect pages, issue authenticated actions, or extract sensitive data from active sessions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The automation relies on Chinese UI labels such as "删除", and similar hard-coded strings appear throughout the file for posting and interaction flows. This effectively forces a Chinese-language Weibo interface without offering the user a language choice or documenting the locale dependency, which matches the policy concern for language/locale constraints without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script exposes a read capability (count) that is outside the declared write-operation scope of the skill. Scope drift matters for agent skills because callers, reviewers, and policy layers may rely on the manifest to understand what data the skill can access; an undeclared read action weakens trust boundaries and can enable unintended data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

delete_all performs repeated destructive actions with no additional confirmation, dry-run, bounds check, or explicit safety interlock beyond the action name. In an agentic setting, ambiguous prompts, invocation mistakes, or prompt injection elsewhere in the chain could cause irreversible mass deletion of a user's posts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI parser and dispatcher make the undocumented count action reachable in practice, confirming that the skill's executable surface exceeds its stated contract. In an agent environment, undocumented reachable actions are dangerous because they bypass user and platform expectations about what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Most operational instructions and notes are written only in Chinese, which effectively imposes a specific language for using the skill. There is no indication that the user can choose another language or that the locale restriction is required for a documented regional-compliance reason.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.