T09 · Insecure Skill Coding Practices
- Location
scripts/reminder_guard.py:8- Finding
Predictable Shared Temporary Storage Enables Reminder Disclosure and Symbolic-Link Attacks
- Content
View full analysis
list[dict]: LOG_PATH.parent.mkdir(parents=True, exist_ok=True) if not LOG_PATH.exists(): LOG_PATH.write_text("[]", encoding="utf-8") try: return json.loads(LOG_PATH.read_text(encoding="utf-8")) except json.JSONDecodeError as exc: raise RuntimeError(f"Corrupted reminder log: {exc}") def save_log(entries: list[dict]) -> None: LOG_PATH.write_text(json.dumps(entries, indent=2, ensure_ascii=False), encoding="utf-8") ``` ### Technical Analysis In the supplied project layout, `Path(__file__).resolve().parents[3]` resolves to `/tmp`. Consequently, the reminder log is written to the predictable shared path: ```text /tmp/memory/reminder-log.json ``` The code creates and accesses this path using `mkdir`, `Path.exists`, `read_text`, and `write_text` without validating ownership, rejecting symbolic links, enforcing private permissions, or using race-resistant file operations. On systems with a typical umask of `022`, a newly created directory and file may receive permissions equivalent to `0755` and `0644`. Reminder messages, labels, notes, and timestamps may therefore be readable by other local users. The check followed by write also creates a time-of-check/time-of-use condition. Python's ordinary path-based reads and writes follow symbolic links. A local attacker who can prepare or modify the predictable path can redirect log operations to another file writable by the victim process. The attacker can also supply malformed or manipulated JSON to co ...[truncated 2252 chars]- Remediation
View remediation
