T09 · Insecure Skill Coding Practices
- Location
scripts/spx_tracking.py:575- Finding
Sensitive browser session cookie exposed through command-line arguments
- Content
View full analysis
Vulnerability Details
File Location:
scripts/spx_tracking.py:115-130, 575;SKILL.md:19, 27
Vulnerability Type: Sensitive data exposure through process arguments and shell history
Risk Level: MediumVulnerable Code
python def fetch_tracking(tracking_number: str, cookie: str | None, timeout: int) -> dict[str, Any]: headers = HEADERS.copy() headers["referer"] = f"https://spx.com.my/track?{tracking_number}" if cookie: headers["cookie"] = cookie response = requests.get( API_URL, params={"spx_tn": tracking_number}, headers=headers, timeout=timeout, ) response.raise_for_status()python parser.add_argument("--cookie", help="Optional browser cookie for authenticated requests")The documented invocation explicitly instructs users to place the cookie on the command line:
bash python skills/spx-tracking/scripts/spx_tracking.py <tracking_number> [--format json|text|summary] [--cookie "..."] [--timeout 15]Technical Analysis
Browser cookies are authentication secrets and should not be passed as ordinary command-line arguments. Depending on the operating system and execution environment, command-line arguments may be visible through process inspection facilities, execution telemetry, job logs, diagnostic tooling, or shell history.
Although the request is transmitted to a fixed HTTPS endpoint and the script does not print the cookie directly, transport security does not protect the secret before it is placed into the HTTP request. The primary exposure occurs locally through the command invocation.
The documentation identifies the cookie as sensitive but still recommends the unsafe
--cookiemechanism. No protected alternative, such as standard input, a restricted file, or a secret manager, is provided.Attack Path
- A user follows the documented invocation and supplies an active brow ...[truncated 1127 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove or deprecate the
--cookiecommand-line option. - Read the cookie from protected standard input, preferably without terminal echo.
- Alternatively, accept a path to a permission-restricted file and verify that its permissions do not allow access by other users.
- Where available, integrate with an operating-system credential store or dedicated secret manager.
- Prefer anonymous API access and avoid requesting a browser cookie unless authentication is strictly necessary.
- Ensure that exceptions, debug output, request tracing, and telemetry never include the
Cookieheader. - Document cookie revocation and advise affected users to clear command history and rotate sessions if the legacy option has been used.
- Remove or deprecate the
