T09 · Insecure Skill Coding Practices
- Location
SKILL.md:404- Finding
Plaintext Authentication Cookies Exported to a Predictable Temporary File
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:404-406
Vulnerability Type: Unsafe temporary-file handling of sensitive authentication data
Risk Level: Mediumbash # Export cookies to file, manually edit, then import browser-use --browser real --profile "Default" cookies export /tmp/cookies.json browser-use --browser remote --profile <id> cookies import /tmp/cookies.jsonTechnical Analysis
The documented workflow exports browser cookies to the fixed path
/tmp/cookies.json. Browser cookies can contain reusable session tokens that provide authenticated access without requiring a password or multi-factor authentication challenge.The instructions do not require exclusive file creation, restrictive permissions, symlink protection, ownership validation, or deletion after import. Because
/tmpis commonly shared and the filename is predictable, another local process or user may monitor, pre-create, replace, or read the file depending on operating-system protections and the CLI's file-creation behavior.Exploitability therefore depends on the local threat model, filesystem permissions, and whether
browser-usesafely handles existing files and symbolic links. The documented pattern nevertheless fails to provide appropriate safeguards for highly sensitive authentication material.Attack Path
- A user follows the advanced cookie synchronization workflow for an authenticated browser profile.
- The CLI exports cookies, potentially including active session tokens, to
/tmp/cookies.json. - A malicious local process or user monitors the predictable path, accesses a weakly protected file, or prepares the path as a symbolic link before export.
- The attacker copies the exported cookies or causes an unintended file write if symlink handling is unsafe.
- The attacker imports or injects captured session cookies into a browser and attempts to impersonate the user on affected domains.
- If the temp ...[truncated 805 chars]
- Remediation
View remediation
Remediation Suggestions
- Avoid intermediate plaintext files by supporting direct, domain-scoped cookie transfer between profiles.
- If a file is unavoidable, create a unique private directory using a secure temporary-file API rather than a fixed
/tmp/cookies.jsonpath. - Set the temporary directory to mode
0700and the cookie file to mode0600. - Use exclusive creation and reject symbolic links and non-regular files.
- Validate file ownership and permissions before importing cookie data.
- Export only cookies for explicitly approved domains; do not default to a full-profile export.
- Delete the temporary file in a guaranteed cleanup operation immediately after import, including failure and interruption paths.
- Warn users that exported cookies are authentication credentials and should never be logged, committed, shared, or retained.
- Where available, use encrypted operating-system credential storage or an authenticated encrypted transfer mechanism.
