Security checks for vulnerabilities and agentic risk
Overview
This skill is coherent with its Toutiao auto-publishing purpose, but it can post through an existing logged-in browser session with broad triggers, scheduled automation, and limited confirmation guidance.
Review this carefully before installing. Use a dedicated browser profile and a limited Toutiao account, keep uploads in a narrow folder, pin and verify browser-cdp, and require manual review of the destination, content, images, and final publish click for every post or scheduled run.
Related installation instructions appear in README.md, lines 16–22:
markdown
### 1. Install Dependencies
Ensure that the browser-cdp skill is installed:
```bash
skillhub_install install_skill browser-cdp
text
### Technical Analysis
The project accepts any current or future `browser-cdp` release with a version greater than or equal to `1.0.0`. The installation instructions also omit an exact version, trusted source, publisher identity, signature, or checksum. No dependency lockfile is included in the audited project.
This creates a supply-chain risk because installations performed at different times may resolve to different, unreviewed dependency versions. The dependency is particularly sensitive because its advertised role is to control a browser through the Chrome DevTools Protocol and reuse an authenticated browser profile. Consequently, a compromised, malicious, or improperly substituted compatible release could execute browser operations with access to the user's active authenticated sessions.
The audit found no evidence that the currently referenced dependency is malicious. The vulnerability is the absence of immutable dependency resolution and provenance verification.
### Attack Path
1. An attacker compromises the distribution account or package source used for `browser-cdp`, or publishes a malicious release that the installer resolves as the expected package.
2. The attacker assigns a version satisfying the broad `>=1.0.0` constraint.
3. A user follows the documented unversioned installation command or installs project dependencies without integrity verification.
4. The malicious dependency is loaded with CDP access to the browser profile used by this Skill.
...[truncated 863 chars]
Remediation
View remediation
Remediation Suggestions
Replace the range with an exact, reviewed dependency version, for example:
json
"browser-cdp": "1.0.0"
The exact version should be selected only after reviewing and testing that release.
Add and commit the ecosystem's supported lockfile or immutable dependency-resolution metadata.
Document the authoritative registry, source repository, maintainer identity, and expected package identifier.
Verify package signatures or published cryptographic checksums where supported.
Configure installation to reject unexpected registries, redirects, and unverifiable packages.
Perform dependency vulnerability, provenance, and source-code reviews before upgrades.
Run CDP automation in a dedicated browser profile containing only the accounts required for this task.
Restrict filesystem exposure and browser permissions to the minimum necessary directories and capabilities.
Require explicit user confirmation immediately before publishing or performing other irreversible account actions.
Resolve the packaging inconsistency in which package.json and README.md reference scripts/toutiao_cdp_publisher.py, although that file is absent from the audited package. This inconsistency is not itself the confirmed vulnerability but can make dependency behavior and testing harder to verify.
The README explicitly promotes reusing the user's existing browser profile and login state, but it does not clearly warn that a CDP-connected skill can inherit access to already authenticated sessions, cookies, and other profile data. In this skill's context, that means automated actions could be performed as the user on Toutiao without fresh authentication, increasing the risk of unintended posting, account misuse, or exposure of session-linked data.
Content
No source excerpt is available for this finding.
Vague Triggers
Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding
The trigger keywords are broad enough to match ordinary writing or publishing-related requests, which can cause the skill to activate in situations where the user did not intend automated browser-based account actions. Because this skill can operate on an existing logged-in session and publish content, accidental invocation materially increases the risk of unintended posts or uploads.
Content
No source excerpt is available for this finding.
Missing User Warnings
Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding
The skill is designed to publish through a reused logged-in browser session and perform uploads, but it does not present a strong, explicit warning that it will act on the user's account and transmit content/files to a third-party service. This is especially dangerous because the skill includes end-to-end automation, including image upload and final publish actions, so a user may underestimate that real account-affecting operations will occur.
Content
No source excerpt is available for this finding.
Context-Inappropriate Capability
Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding
The skill expands from publishing user-provided content into autonomously sourcing topics from third-party news sites, which increases scope and creates opportunities for unsolicited browsing, content ingestion, and derivative content generation without an explicit user request each time. In the context of a logged-in publishing workflow, this makes the agent more capable of acting independently and posting externally based on scraped trends, raising misuse and policy-compliance risks.
Content
No source excerpt is available for this finding.
Vague Triggers
Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding
The trigger phrase "发布文章" is broad enough to match many generic writing or publishing requests, which can cause this automation skill to activate outside the user's intended platform-specific context. Because the skill performs end-to-end automated publishing, accidental invocation could lead to unintended content creation or posting actions on Toutiao.
Content
No source excerpt is available for this finding.
Vague Triggers
Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding
The trigger phrase "微头条" names only a content type and does not specify an action, making it prone to activation on casual discussion, drafting, analysis, or editing requests that merely mention the term. In a skill that can automate browser-based posting, this ambiguity increases the risk of unintended execution and downstream account actions.
Content
No source excerpt is available for this finding.
Vague Triggers
Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding
The phrase "文章配图" is highly generic and could match ordinary requests about illustrating or editing an article, even when the user does not want Toutiao automation. Given this skill's full publishing workflow and browser control capability, overly generic activation can cause the agent to enter a sensitive automated posting flow without sufficiently clear user intent.