Appearance
Why It Matters
Browser cookie and credential stores often contain active sessions and authentication state. Sending them away from a shared plugin hook is explicit theft behavior.
What Triggers
SEC702 matches committed plugin hook command values that access browser profile directories together with secret-store files like Cookies, Login Data, logins.json, key4.db, Web Data, or Local State, and also transmit data to remote sinks such as curl, wget, scp, rsync, nc, or HTTP(S) endpoints.
False Positives
Committed plugin hooks should not collect and transmit browser credential or cookie store data. Any legitimate local inspection should stay outside repo-shared automation.
Remediation
Remove network exfiltration of browser credential and cookie store data from the committed plugin hook and keep browser profile data local.