T09 · Insecure Skill Coding Practices
- Location
scripts/publish.py:34- Finding
Zhihu Authentication Cookies Are Persisted in Plaintext
- Content
View full analysis
list | None: """Load cookies from file, return None if not found.""" if COOKIE_FILE.exists(): try: return json.loads(COOKIE_FILE.read_text(encoding="utf-8")) except (json.JSONDecodeError, IOError): return None return None ``` ### Technical Analysis After browser login, the script serializes the complete Playwright browser cookie list into `scripts/.zhihu_cookies.json`. This list may include the reusable `z_c0` authentication cookie, the `_xsrf` token, and other cookies belonging to the Zhihu browser context. The file is stored as ordinary plaintext without: - Owner-only file permissions - Encryption or operating-system credential protection - Filtering to retain only the cookies strictly required for publishing - Automatic expiration or secure deletion - A repository ignore rule protecting generated credential files The related browser profile is also persisted under `scripts/.zhihu_browser_profile`. Persisting authentication state is necessary to support repeat publishing without logging in each time, but storing all captured cookies in the project directory exceeds the minimum credential scope needed for that function. Network use itself is consistent with the declared functionality: the inspected code transmits credentials and article content only to hard-coded HTTPS endpoints under `www.zhihu.com` and `zhuanlan.zhihu.com`. No unrelated exfiltration destination was found. ### Attack ...[truncated 1192 chars]- Remediation
View remediation
