Back to skill

Security audit

Ok Core Skill

Security checks for vulnerabilities and agentic risk

Overview

This OK.com automation skill is related to its advertised purpose, but it exposes sensitive browser and account control in ways users should review carefully before installing.

Review before installing. Use a separate browser profile, prefer manual browser/OAuth login over giving the agent a password, close the bridge and debug-enabled Chrome after use, and avoid account-changing actions unless you can confirm the exact favorite or post being modified or deleted.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/bridge_server.py:31
Finding

Unauthenticated Local WebSocket Bridge Permits Browser Session Control and Cookie Extraction

Content
View full analysis
None: try: raw = await asyncio.wait_for(ws.recv(), timeout=10) except (asyncio.TimeoutError, Exception) as e: logger.warning("Handshake timed out or failed: %s", e) return try: msg = json.loads(raw) except json.JSONDecodeError: return role = msg.get("role") if role == "extension": await self._handle_extension(ws) elif role == "cli": await self._handle_cli(ws, msg) else: logger.warning("Unknown role: %s", role) ``` ```python # scripts/bridge_server.py:71-101 async def _handle_cli(self, ws: ServerConnection, msg: dict) -> None: if msg.get("method") == "ping_server": await ws.send(json.dumps({ "result": {"extension_connected": self._extension_ws is not None} })) return if not self._extension_ws: await ws.send(json.dumps({ "error": "Extension is not connected" })) return msg_id = str(uuid.uuid4()) msg["id"] = msg_id loop = asyncio.get_event_loop() future: asyncio.Future[Any] = loop.create_future() self._pending[msg_id] = future await self._extension_ws.send(json.dumps(msg)) try: result = await asyncio.wait_for(future, timeout=90.0) await ws.send(json.dumps(result)) ``` ```javascript // extension/background.js:23-45 function connect() { if (ws && (ws.readyState === WebSocket.CONNECTING || ws.readyState === WebSocket.OPEN)) return; ws = new WebSocket(BRIDGE_URL); ws.onopen = ( ...[truncated 4999 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ok/cli.py:493
Finding

Password Supplied as a Command-Line Argument Is Exposed to Process and Execution Logs

Content
View full analysis
ok-cli login \ --subdomain \ --email "user@example.com" \ --password "Pass1234" ``` ```bash # skills/ok-account/SKILL.md:33-38 uv run --project ok-cli login \ --subdomain \ --email "" \ --password "" ``` ### Technical Analysis The CLI requires the account password through the `--password` argument. Command-line arguments are not an appropria ...[truncated 2370 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/ok/client/factory.py:66
Finding

Automatic CDP Discovery Can Attach to and Modify an Unrelated Browser Session

Content
View full analysis
str | None: """Probe common ports for an existing Chrome debug endpoint.""" for port in _CDP_PROBE_PORTS: url = f"http://127.0.0.1:{port}" if _cdp_endpoint_alive(url): logger.info("Auto-detected CDP on port %d", port) return url return None ``` ```python # scripts/ok/client/factory.py:319-327 cdp_url = os.environ.get(_ENV_CDP_URL, "").strip() if not cdp_url: cdp_url = _discover_cdp_url() or "" if cdp_url: client = _try_cdp_connect(cdp_url) if client: return client ``` ```python # scripts/ok/client/cdp_client.py:123-152 def _url_is_ok_com(url: str) -> bool: if not url: return False u = url.lower() return "ok.com" in u def _pick_context_and_page(browser: Browser) -> tuple[BrowserContext, Page]: """Prefer an open tab with ok.com; else first tab; else new tab to ok.com.""" for ctx in browser.contexts: for page in ctx.pages: if _url_is_ok_com(page.url or ""): return ctx, page for ctx in browser.contexts: if ctx.pages: return ctx, ctx.pages[0] if browser.contexts: ctx = browser.contexts[0] page = ctx.new_page() page.goto(_DEFAULT_OK_ENTRY, wait_until="commit") return ctx, page page = browser.new_page() page.goto(_DEFAULT_OK_ENTRY, wait_until="commit") ctx = page.context return ctx, page ``` ### Technical Analysis The factory probes the conventional debugging ports 9222 through 9224 and attaches to the first endpoint that responds. It does not verify that the browser was la ...[truncated 2925 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/ok/client/factory.py:184
Finding

Persistent Chrome Debugging Process Leaves Authenticated Browser State Exposed on Predictable Ports

Content
View full analysis
None: """Clean up resources (does NOT kill the auto-launched Chrome; it persists for future CLI invocations).""" global _client_instance _client_instance = None ``` ### Technical Analysis The skill launches Chrome with an unauthenticated remote-debugging interface on one of three predictable ports and a persistent profile containing cookies and browser storage. The process intentionally survives the CLI invocation. Persisting a dedicated browser profile can be a legitimate convenience for maintaining login state. Persisting an active CDP endpoint is not required to preserve that profile and creates a continuing privileged control channel after the re ...[truncated 2211 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (85)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the skill can perform arbitrary browser automation, execute page-context JavaScript, retrieve cookies, navigate generically, and start a local bridge server, those are powerful capabilities that exceed normal OK.com task automation. In context, this is more dangerous because the skill is framed as a narrow classifieds helper, which may lower operator suspicion while still enabling session or data abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill can perform arbitrary browser automation, execute page-context JavaScript, retrieve cookies, navigate generically, and start a local bridge server, those are powerful capabilities that exceed normal OK.com task automation. In context, this is more dangerous because the skill is framed as a narrow classifieds helper, which may lower operator suspicion while still enabling session or data abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill can perform arbitrary browser automation, execute page-context JavaScript, retrieve cookies, navigate generically, and start a local bridge server, those are powerful capabilities that exceed normal OK.com task automation. In context, this is more dangerous because the skill is framed as a narrow classifieds helper, which may lower operator suspicion while still enabling session or data abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill can perform arbitrary browser automation, execute page-context JavaScript, retrieve cookies, navigate generically, and start a local bridge server, those are powerful capabilities that exceed normal OK.com task automation. In context, this is more dangerous because the skill is framed as a narrow classifieds helper, which may lower operator suspicion while still enabling session or data abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill can perform arbitrary browser automation, execute page-context JavaScript, retrieve cookies, navigate generically, and start a local bridge server, those are powerful capabilities that exceed normal OK.com task automation. In context, this is more dangerous because the skill is framed as a narrow classifieds helper, which may lower operator suspicion while still enabling session or data abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill can perform arbitrary browser automation, execute page-context JavaScript, retrieve cookies, navigate generically, and start a local bridge server, those are powerful capabilities that exceed normal OK.com task automation. In context, this is more dangerous because the skill is framed as a narrow classifieds helper, which may lower operator suspicion while still enabling session or data abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

If the skill can perform arbitrary browser automation, execute page-context JavaScript, retrieve cookies, navigate generically, and start a local bridge server, those are powerful capabilities that exceed normal OK.com task automation. In context, this is more dangerous because the skill is framed as a narrow classifieds helper, which may lower operator suspicion while still enabling session or data abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

If the skill can perform arbitrary browser automation, execute page-context JavaScript, retrieve cookies, navigate generically, and start a local bridge server, those are powerful capabilities that exceed normal OK.com task automation. In context, this is more dangerous because the skill is framed as a narrow classifieds helper, which may lower operator suspicion while still enabling session or data abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill can perform arbitrary browser automation, execute page-context JavaScript, retrieve cookies, navigate generically, and start a local bridge server, those are powerful capabilities that exceed normal OK.com task automation. In context, this is more dangerous because the skill is framed as a narrow classifieds helper, which may lower operator suspicion while still enabling session or data abuse.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
88% confidence
Finding

The YARA hit is supported by concrete behavior in this file: the extension can retrieve all cookies, capture screenshots, and forward results through a localhost-controlled bridge. While this is not definitive proof of malware intent, the capability set overlaps strongly with information-stealer tradecraft and is especially risky in an automation skill that should only browse and manage OK.com content.

Content

Scanner excerpt · extension/background.js (reported line 9)May include surrounding context.

js
/**
 * OK Bridge - Background Service Worker
 *
 * 连接 Python bridge server(ws://localhost:9334),接收命令并执行:
 * - navigate / wait_for_load: chrome.tabs.update + onUpdated
 * - evaluate / has_element 等: chrome.scripting.executeScript (MAIN world)
 * - click / input 等 DOM 操作: chrome.tabs.sendMessage → content.js
 * - screenshot: chrome.tabs.captureVisibleTab
 * - get_cookies: chrome.cookies.getAll
 */

const BRIDGE_URL = "ws://localhost:9334";
let ws = null;

// 保持 service worker 存活
chrome.alarms.create("keepAlive", { periodInMinutes: 0.4 });
chrome.alarms.onAlarm.addListener(() => {
  if (!ws || ws.readyState !== WebSocket.OPEN) connect();
});

// ───────────────────────── WebSocket ─────────────────────────

function connect() {
  if (ws && (ws.readyState === WebSocket.CONNECTING || ws.readyState === WebSocket.OPEN)) return;

  ws = new WebSocket(B

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The background worker exposes direct cookie extraction through chrome.cookies.getAll and returns the results over the bridge. Cookies can contain session tokens or other authentication material, so this enables account/session theft if the localhost bridge or controlling process is compromised.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The extension exposes an 'evaluate' pathway that executes attacker-controlled JavaScript in the page's MAIN world using Function(...). Any process able to send commands over the localhost WebSocket can run arbitrary code on OK.com pages, manipulate user actions, scrape sensitive page data, or trigger authenticated requests far beyond the advertised marketplace automation scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code attaches the Chrome debugger and can set arbitrary file inputs on the page. This gives the bridge power to cause local files to be uploaded from user-controlled paths, which can expose sensitive local data and exceeds normal browsing or marketplace-search functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Automating file inputs through the Chrome debugger affects local user data but is performed with no warning or confirmation. A compromised or abusive bridge could silently cause uploads of sensitive files to remote websites under the user's authenticated browser context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest requests the powerful Chrome "debugger" permission even though the stated functionality is browsing OK.com listings, managing favorites, and interacting with a local CLI. The debugger API can inspect network traffic, execute protocol commands, and access sensitive page/session context far beyond normal site automation, creating substantial abuse potential if the extension is compromised or misused.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/ok/cookies.py (reported line 18)May include surrounding context.

python
"""OK.com Cookie 持久化与管理"""

from __future__ import annotations

import json
import logging
from pathlib import Path

logger = logging.getLogger("ok-cookies")

COOKIE_DIR = Path(__file__).parent.parent.parent / ".cookies"


def save_cookies(cookies: list[dict], country: str = "default") -> Path:
    """保存 cookies 到本地文件

    Args:
        cookies: Chrome cookie 列表
        country: 国家标识(用于文件命名)

    Returns:
        保存的文件路径
    """
    COOKIE_DIR.mkdir(parents=True, exist_ok=True)
    path = COOKIE_DIR / f"{country}_cookies.json"
    path.write_text(json.dumps(cookies, ensure_ascii=False, indent=2), encoding="utf-8")
    logger.info("Cookies 已保存: %s (%d 条)", path, len(cookies))
    return path


def load_cookies(country: str = "default") -> list[dict] | None:
    """加载本地保存的 cookies

    Args:
        country: 国家标识

    Returns:
        Cookie 列表,文件

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares executable behavior involving shell commands, dependency installation, browser automation, and likely network/file access, but does not define any explicit tool scope or permission boundaries. In an agent setting, missing scope declarations increase the chance that the skill runs with broader-than-necessary capabilities and makes review and containment harder.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The heading and core instruction state the assistant role entirely in Chinese and direct behavior in that language, while the skill is described as multi-country and multilingual. There is no indication that the user can choose their preferred language, which creates a locale/language policy concern.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
按优先级判断用户意图,路由到对应处理:

0. **搜索/浏览**("找夏威夷房源 / 搜索东京的工作 / 温哥华二手车 / 夏威夷50万以下的房子")→ **先读取 `skills/ok-search/SKILL.md`**,按其中步骤执行(禁止跳过)
1. **地区切换**("切换到新加坡 / 切换城市 / 列出国家 / 列出城市")→ 执行 `ok-locale` 技能
2. **推荐/详情**("首页推荐 / 查看帖子详情")→ 执行 `ok-explore` 技能
3. **登录检测**("检查登录 / 登录状态")→ 执行 `ok-auth` 技能

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
按优先级判断用户意图,路由到对应处理:

0. **搜索/浏览**("找夏威夷房源 / 搜索东京的工作 / 温哥华二手车 / 夏威夷50万以下的房子")→ **先读取 `skills/ok-search/SKILL.md`**,按其中步骤执行(禁止跳过)
1. **地区切换**("切换到新加坡 / 切换城市 / 列出国家 / 列出城市")→ 执行 `ok-locale` 技能
2. **推荐/详情**("首页推荐 / 查看帖子详情")→ 执行 `ok-explore` 技能
3. **登录检测**("检查登录 / 登录状态")→ 执行 `ok-auth` 技能

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
1. **地区切换**("切换到新加坡 / 切换城市 / 列出国家 / 列出城市")→ 执行 `ok-locale` 技能
2. **推荐/详情**("首页推荐 / 查看帖子详情")→ 执行 `ok-explore` 技能
3. **登录检测**("检查登录 / 登录状态")→ 执行 `ok-auth` 技能
4. **收藏管理**("查看收藏 / 收藏帖子 / 取消收藏")→ **先读取 `skills/ok-account/SKILL.md`**,按其步骤执行(需登录)
5. **我的帖子**("查看我的帖子 / 删除帖子 / 编辑帖子")→ **先读取 `skills/ok-account/SKILL.md`**,按其步骤执行(需登录)

---

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
1. **地区切换**("切换到新加坡 / 切换城市 / 列出国家 / 列出城市")→ 执行 `ok-locale` 技能
2. **推荐/详情**("首页推荐 / 查看帖子详情")→ 执行 `ok-explore` 技能
3. **登录检测**("检查登录 / 登录状态")→ 执行 `ok-auth` 技能
4. **收藏管理**("查看收藏 / 收藏帖子 / 取消收藏")→ **先读取 `skills/ok-account/SKILL.md`**,按其步骤执行(需登录)
5. **我的帖子**("查看我的帖子 / 删除帖子 / 编辑帖子")→ **先读取 `skills/ok-account/SKILL.md`**,按其步骤执行(需登录)

---

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
1. **地区切换**("切换到新加坡 / 切换城市 / 列出国家 / 列出城市")→ 执行 `ok-locale` 技能
2. **推荐/详情**("首页推荐 / 查看帖子详情")→ 执行 `ok-explore` 技能
3. **登录检测**("检查登录 / 登录状态")→ 执行 `ok-auth` 技能
4. **收藏管理**("查看收藏 / 收藏帖子 / 取消收藏")→ **先读取 `skills/ok-account/SKILL.md`**,按其步骤执行(需登录)
5. **我的帖子**("查看我的帖子 / 删除帖子 / 编辑帖子")→ **先读取 `skills/ok-account/SKILL.md`**,按其步骤执行(需登录)

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill supports account actions such as managing favorites and posted ads, including potentially destructive edits or deletions, but provides no explicit warning, confirmation, or safety checkpoint. In an agent environment, this raises the risk of accidental data loss or unauthorized account changes from ambiguous prompts or misrouting.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The extension automatically connects to an unauthenticated localhost WebSocket server and accepts commands from it. That creates a broad command-and-control surface: any local process binding or hijacking that port can drive browsing, script execution, screenshots, cookie access, and file-input actions without meaningful trust verification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.