Back to skill

Security audit

Short Drama Publisher

Security checks for vulnerabilities and agentic risk

Overview

The skill’s publishing purpose is clear, but it asks users to store live account cookies and can automate Facebook posting on a schedule without enough safeguards.

Review before installing. Use only dedicated, least-privileged accounts, keep cookie files out of source control and backups, restrict file permissions, avoid enabling the cron job until every post is manually reviewed, and prefer official OAuth or platform APIs where possible. Also inspect any referenced scripts before running them, because this package only submitted SKILL.md.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Third-Party Dependencies and Browser Binary Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 31-32
Vulnerability Type: Unpinned third-party dependencies and mutable browser binaries
Risk Level: Medium

Complete Code Snippet:

bash
pip install playwright opencv-python librosa numpy pyyaml
playwright install chromium

Technical Analysis

The installation instructions retrieve several Python packages and a Chromium browser binary without fixed versions, cryptographic hashes, a lockfile, or a documented trusted package index. Consequently, the installed artifacts can vary over time and cannot be reliably matched to versions reviewed by the project author.

Unpinned installation alone does not prove that any listed package is malicious. However, it creates a supply-chain exposure: compromise of a package release, package index, dependency account, transitive dependency, or browser distribution channel could cause users to install attacker-controlled components. Python package installation can execute package build or installation logic, while a compromised browser binary would later execute when the documented Playwright workflow runs.

The artifact contains only SKILL.md; it does not include a dependency lockfile, integrity metadata, or the referenced scripts. Therefore, neither dependency integrity nor the way these packages would be invoked can be verified from the submitted project.

Attack Path

  1. An attacker compromises a listed dependency, one of its transitive dependencies, its publisher account, or an applicable package distribution channel.
  2. The attacker publishes a malicious release that remains compatible with the unpinned package name.
  3. A user follows the documented pip install or playwright install chromium command.
  4. The package manager resolves the mutable dependency or browser binary to the attacker-controlled release.
  5. Malicious code executes during installation or when the installed component is imported ...[truncated 554 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin every direct and transitive Python dependency to a reviewed version in a lockfile.
  • Require cryptographic hashes, such as through pip install --require-hashes, for reproducible dependency verification.
  • Pin Playwright and its corresponding browser revision rather than retrieving an unspecified current Chromium build.
  • Document and enforce trusted package indexes; disable unintended fallback to public or additional indexes.
  • Install dependencies inside a dedicated virtual environment or container under a nonprivileged account.
  • Add automated dependency vulnerability and provenance scanning to the release process.
  • Review and update locked dependencies through a controlled process rather than resolving mutable versions during deployment.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:35
Finding

Reusable Authentication Cookies Stored as Plaintext Project Files

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 35-44
Vulnerability Type: Insecure storage of authentication credentials
Risk Level: High

Complete Code Snippet:

markdown
### Credentials Setup

1. **MoboBoost Cookies**
   - Login to https://ckoc.cdreader.com
   - Export cookies using browser extension (e.g., "EditThisCookie")
   - Save as `config/moboboost_cookies.json`

2. **Facebook Cookies**
   - Login to Facebook
   - Export cookies using browser extension
   - Save as `config/facebook_cookies.json`

Technical Analysis

The instructions require users to export active browser cookies and save them as ordinary JSON files inside the project directory. Authentication cookies are bearer credentials: a party that obtains a still-valid session cookie may be able to impersonate the authenticated user without knowing the password, subject to the service's session-binding and risk controls.

No safeguards are documented for filesystem permissions, encryption at rest, secret-manager storage, version-control exclusion, secure deletion, logging redaction, session lifetime, or credential rotation. Keeping these files beneath the project tree also raises the likelihood of accidental inclusion in source-control commits, archives, support bundles, backups, or shared development environments.

The artifact contains no actual cookie files and no executable scripts, so no credential leak is directly present in the submitted package. The vulnerability arises from the documented credential-handling design users are instructed to adopt.

Attack Path

  1. A user signs in to MoboBoost and Facebook and exports active browser cookies as instructed.
  2. The user stores the exported cookies in config/moboboost_cookies.json and config/facebook_cookies.json.
  3. The files become accessible through weak filesystem permissions, another local process or user, malware, a shared workspace, a backup, or an a ...[truncated 980 chars]
Remediation
View remediation

Remediation Suggestions

  • Prefer officially supported OAuth or service APIs with narrowly scoped, revocable access tokens instead of exported browser sessions.
  • Store credentials in an operating-system keychain, managed secret store, or equivalent protected credential facility rather than in the project directory.
  • If file-based storage is unavoidable, encrypt credentials at rest and restrict access to the owning account using the narrowest supported filesystem permissions.
  • Add cookie and credential paths to .gitignore and provide only sanitized example files such as *.example.json.
  • Implement startup checks that reject credentials with unsafe ownership or permissions.
  • Never print cookies in command output or logs; redact all authentication headers and cookie values.
  • Use dedicated, least-privileged service accounts with only the publishing permissions required by the workflow.
  • Minimize session lifetime and scope, rotate sessions regularly, and revoke them immediately after suspected exposure.
  • Document secure deletion and incident-response procedures for accidentally committed or shared cookies.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very generic phrases such as "short drama," "video publisher," and Chinese equivalents that could match ordinary user requests and invoke this skill unexpectedly. Because the skill performs credential-dependent downloading and auto-posting workflows, overbroad activation increases the chance of unintended account-affecting actions or disclosure of sensitive operational guidance in the wrong context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to export and store MoboBoost and Facebook browser cookies, then use them for automated publishing, but it does not present a strong, explicit warning about the privacy, account security, and account-action risks of doing so. Session cookies are effectively bearer tokens; if mishandled, logged, or reused improperly, they can enable account takeover-like access and unauthorized posting from personal or business Facebook accounts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.