T09 · Insecure Skill Coding Practices
- Location
scripts/client.py:135- Finding
Authentication Cookies Are Persisted in Plaintext Without Restrictive File Permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its Xiaohongshu collection purpose, but it should go through Review because it stores login cookies locally and includes authenticated posting/publishing paths with unsafe edge cases.
Install only if you are comfortable giving the skill access to an authenticated Xiaohongshu browser session. Use a dedicated or low-risk account, keep runs small, restrict permissions on the cookie file, do not share or commit the cookie directory, review local output before reuse, avoid untrusted Markdown with publish-md, and use publishing/comment commands only when you explicitly intend to post under your account.
scripts/client.py:135Authentication Cookies Are Persisted in Plaintext Without Restrictive File Permissions
scripts/publish.py:475Untrusted Markdown Can Cause Chromium to Make Arbitrary Network Requests
The reply API claims to reply to a specific comment/user, but reply_user_id is never used to verify or bind the action to the intended target. If locating the target comment fails, the function explicitly falls back to typing into the generic comment box, which can post a top-level comment or reply to the wrong thread, causing unintended actions under the user's authenticated account.
The docstring explicitly characterizes the module as read-only, yet the implementation persists collected data to disk by creating an output directory and writing notes, comments, summary JSON, and a markdown report. This is an active contradiction in the code documentation, not merely an omitted detail.
The default keywords are hard-coded Chinese phrases, and the collector also uses Chinese platform-specific values such as Chinese publish-time strings and sort labels elsewhere in the file. This creates a natural-language/locale constraint that is imposed by default rather than offered as a user choice or clearly documented as an opt-in regional mode.
This function collects public notes and comments and persists them to local JSONL files without any user-facing notice or confirmation at the collection entry point. In an agent skill context, silent local storage of scraped third-party content can create privacy, compliance, and data-governance risk because operators may not realize content is being retained on disk, potentially including usernames-derived identifiers, post text, and comment text.
The module docstring and method/class docstrings are entirely in Chinese, with no indication that the skill is region-specific or that users may choose another language. This is a natural-language locale constraint visible in the file and matches the policy-violation category for language/locale requirements without opt-in.
This code file contains natural-language documentation and user-facing status messages exclusively in Chinese, beginning with the module docstring. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not present here.
The stderr messages shown during execution, such as page-opening, retry, comment-loading, and failure notices, are all emitted only in Chinese. Because these are user-visible runtime messages and the file does not offer any language choice or opt-in, they violate the language/locale policy for natural-language content.
This Python file contains natural-language descriptions entirely in Chinese, starting with the module docstring, and provides no indication that the skill is limited to a Chinese-speaking or region-specific context. Under the language/locale policy, forcing a specific language without user opt-in or clear justification is a policy concern.
This code includes natural-language documentation and runtime status messages exclusively in Chinese, which can impose a language choice on users without opt-in. The policy specifically calls out language or locale constraints as violations unless the skill offers a choice or clearly documents a justified regional scope.
The code saves authenticated session cookies after detecting a successful login via self.client._save_cookies(), but this file provides no explicit disclosure, consent flow, or safeguards around persistence. In an agent skill context, silently storing reusable auth material can expose accounts if the cookie file is readable by other processes, reused unexpectedly, or left on disk longer than intended.
This code presents its purpose and operational messages entirely in Chinese, including the primary module description and later user-facing status strings, with no indication that language selection is configurable or that the skill is explicitly limited to Chinese-speaking users. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
The module docstring explicitly claims a safer manual-confirmation publishing model, but both publish_image and publish_video accept auto_publish=True and will click the final publish button with no enforced human checkpoint. This mismatch can mislead operators or downstream agents into assuming a review gate exists when the code is capable of fully automated posting, increasing the risk of unintended or unauthorized content publication.
This code navigates a browser client to a Xiaohongshu search URL using the user-supplied keyword, which sends the query to an external service. Although the module has docstrings, there is no explicit disclosure here that the action contacts a third-party site and uses the authenticated browser/session context when doing so.
The top-level search helper accepts a cookie_path and constructs a client with it, indicating that stored authentication material may be loaded and used. The file does not include an explicit warning to users that local cookie/session data will be accessed for this operation.
The skill description and usage are presented entirely in Chinese and the examples assume Chinese-language interaction patterns and Chinese Xiaohongshu keyword inputs. The file does not indicate that language choice is optional or that the skill is intentionally limited to Chinese-speaking users, which can conflict with a policy requiring user opt-in for language or locale constraints.
The dependency specification uses a lower-bound constraint (playwright>=1.40.0) instead of pinning an exact version, which makes builds non-reproducible and can pull in unexpected upstream releases. While this is not an immediately exploitable code flaw by itself, it increases supply-chain risk because a compromised or breaking future release could be installed without review.
playwright>=1.40.0
markdown>=3.5
pytest>=7.0
pytest-mock>=3.0
The markdown dependency is not pinned to a specific version, so installations may resolve to different releases over time. This weakens reproducibility and makes it harder to determine whether the environment is affected by known vulnerable versions, increasing supply-chain uncertainty.
playwright>=1.40.0
markdown>=3.5
pytest>=7.0
pytest-mock>=3.0
The manifest references markdown without pinning a specific version, and advisories exist for some markdown releases. Because the installed version is unconstrained above the minimum, it is impossible to verify from this file alone whether a vulnerable release could be selected, creating an avoidable supply-chain risk.
The pytest dependency is declared with a minimum version only, allowing newer versions to be installed automatically. This can introduce vulnerable or incompatible releases and prevents reliable auditing of the dependency set.
playwright>=1.40.0
markdown>=3.5
pytest>=7.0
pytest-mock>=3.0
The pytest entry is not pinned, and known advisories exist for some pytest versions. Without an exact version or lockfile, consumers cannot determine whether installation will pull a safe release, leaving security posture ambiguous and potentially unsafe.
pytest-mock is also unpinned, which contributes to non-deterministic builds and broader supply-chain exposure. Even for test-only packages, unreviewed upstream changes can affect CI behavior, development workflows, or transitive dependency safety.
playwright>=1.40.0
markdown>=3.5
pytest>=7.0
pytest-mock>=3.0
The module docstring and the command help text throughout the file are written only in Chinese, which establishes a fixed language for user-facing interaction. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless a locale-specific constraint is explicitly documented, which is not present here.
Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.
try:
client.start()
action = InteractAction(client)
method = getattr(action, action_name)
return method(feed_id, xsec_token)
finally:
client.close()
The module description is written in Chinese, and the file consistently uses Chinese-only user-facing strings and comments. Under the policy rule for language/locale, this is a violation because the skill does not provide any user opt-in or alternative language handling.
The print statements shown to the user/operator, such as status and error messages, are hard-coded in Chinese throughout this section. The file does not offer a language choice or indicate that a Chinese-only locale restriction is intentional and justified.
No suspicious patterns detected.