T09 · Insecure Skill Coding Practices
- Location
scripts/init_db.py:5- Finding
Financial Data Stored in a Plaintext Database Without Explicit File Permission Hardening
- Content
View full analysis
Vulnerability Details
File Location:
scripts/init_db.py, lines 5-9
Vulnerability Type: Plaintext storage of sensitive financial data with permissions dependent on the host environment
Risk Level: MediumVulnerable Code
python DB_PATH = os.path.expanduser("~/.openclaw/workspace/skills/personal-finance/finance.db") def init_db(): os.makedirs(os.path.dirname(DB_PATH), exist_ok=True) conn = sqlite3.connect(DB_PATH)Technical Analysis
The skill stores transaction, budget, category, and payment-schedule information in an unencrypted SQLite database at a predictable path. The initialization code creates the parent directory and database without assigning explicit restrictive permissions.
Consequently, the effective permissions are inherited from the existing directory and the process-wide
umask. In an environment with a permissiveumask, shared workspace permissions, insecure backup configuration, or access by other local processes, the database may be readable or copyable by unintended principals. SQLite does not provide encryption at rest by default.Exploitation requires local filesystem access or access through another process running under a principal that can read the database. No remote access mechanism or privilege-escalation primitive was identified in the audited code.
Attack Path
- The user initializes the skill, causing
finance.dbto be created at~/.openclaw/workspace/skills/personal-finance/finance.db. - The skill records sensitive financial transactions, budgets, and payment schedules in the database.
- A local user or compromised process identifies the predictable database location.
- If inherited directory or file permissions permit access, the actor copies or opens
finance.db. - The actor queries the SQLite tables to recover transaction descriptions, amounts, dates, budgets, and scheduled payment details.
Impact Assessment
Successful e ...[truncated 513 chars]
- The user initializes the skill, causing
- Remediation
View remediation
Remediation Suggestions
-
Create the database directory with owner-only permissions and verify existing directories before use:
python db_dir = os.path.dirname(DB_PATH) os.makedirs(db_dir, mode=0o700, exist_ok=True) os.chmod(db_dir, 0o700) -
Restrict the database file to the owning user immediately after creation:
python conn = sqlite3.connect(DB_PATH) os.chmod(DB_PATH, 0o600) -
Set a restrictive
umask, such as0o077, during initialization so that database-related files are not initially created with broad permissions. -
Apply equivalent restrictions to SQLite journal, WAL, shared-memory, backup, and exported files. Ensure the containing directory prevents access to these auxiliary files.
-
Before writing sensitive data, reject unsafe database paths, symbolic links, and files not owned by the expected user.
-
If the threat model includes privileged local processes, shared accounts, untrusted backups, or offline disk access, use an encrypted database implementation or application-level encryption with keys stored separately from the database.
-
Document the database location, sensitivity, retention policy, backup behavior, and secure deletion procedure for users.
-
