T09 · Insecure Skill Coding Practices
- Location
scripts/start_chrome.sh:15- Finding
Excessive Copying of Sensitive Browser Data into an Unsafe Temporary Profile
- Content
View full analysis
/dev/null for f in Cookies Cookies-journal "Login Data" "Login Data-journal" \ "Web Data" "Web Data-journal" Preferences "Secure Preferences" \ Favicons "Favicons-journal" "Session Storage" "Session Storage-journal" \ "Local Storage" "Local Storage-journal" IndexedDB Network \ "Origin Bound Certs" "Origin Bound Certs-journal" \ "Extension State" "Extension State-journal" \ "Media Device Salts" "Trust Database" "Trust Database-journal" \ Sessions; do cp -R "$SRC/Default/$f" "$DST/Default/" 2>/dev/null done ``` ### Technical Analysis The script duplicates a broad portion of the user's primary Chrome profile into `/tmp/chrome-debug-profile`. The copied information includes: - Cookies and active authenticated sessions - Saved-login databases - Local storage, session storage, and IndexedDB data for unrelated origins - Browser sessions and history-related state - Extension state - Trust databases and origin-bound certificate information - Chrome's `Local State`, which can be involved in protecting locally stored browser secrets The declared task only requires an authenticated Weibo session. Copying browser data belonging to every website violates least-data and least-privilege principles. The destination is also a predictable path under the shared temporary directory. The script creates the directory without explicitly enforcing restrictive permissions. Although some copied credentials may remain protected by operating-system encryption, active sessions loaded into Chrome can still be exercised through browser automation without decrypting the underlying cred ...[truncated 1463 chars]- Remediation
View remediation
