T09 · Insecure Skill Coding Practices
- Location
tool.py:16- Finding
Unsafe Persistent Memory File Handling
- Content
View full analysis
Vulnerability Details
File Location:
tool.py, lines 16 and 22–29
Vulnerability Type: Plaintext sensitive-data storage, predictable file path, symlink following, and non-atomic writes
Risk Level: MediumVulnerable Code
python MEMORY_STORE_FILE = "memory_store.json"python def load_memory(self) -> Dict[str, Any]: if os.path.exists(self.persistence_file): with open(self.persistence_file, "r") as f: return json.load(f) return {"experiences": [], "reflections": []} def save_memory(self): with open(self.persistence_file, "w") as f: json.dump(self.memory, f, indent=2)Technical Analysis
The application stores agent contexts, actions, results, metadata, and reflections in plaintext at the predictable relative path
memory_store.json. It does not explicitly enforce restrictive file permissions, verify that the destination is a regular file owned by the expected user, reject symbolic links, or use atomic file replacement.Python's ordinary
open()follows symbolic links. Opening the file with mode"w"truncates the resolved destination before writing. Consequently, if the program runs in a directory writable by an attacker, the attacker can pre-creatememory_store.jsonas a symbolic link to another file writable by the victim process. A subsequentstoreorreflectoperation may overwrite that target with JSON content.The load path also accepts untrusted JSON without schema, ownership, or integrity validation. An attacker able to modify the storage file can inject fabricated experiences and reflections that are later returned by queries or processed by reflection logic. This is a local integrity concern; the audited implementation does not execute stored content as code or send it to a remote service.
Attack Path
- A victim runs the tool from a shared or attacker-writable working directory.
- The attacker creates
memory_store.jsonas a symbolic link to another file ...[truncated 1260 chars]
- Remediation
View remediation
Remediation Suggestions
- Store persistent data in a dedicated per-user application-data directory rather than the current working directory.
- Create the directory with restrictive permissions such as
0700, and create the memory file with mode0600. - Reject symbolic links and non-regular files. On supported platforms, open files using
os.open()withO_NOFOLLOW, then verify the descriptor withos.fstat(). - Validate the file's owner and permissions before reading or replacing it.
- Implement atomic persistence by writing to a securely created temporary file in the same directory, flushing and synchronizing it, setting restrictive permissions, and replacing the destination with
os.replace(). - Apply a strict JSON schema and type validation before accepting stored experiences or reflections.
- If memory integrity must be protected from local modification, authenticate the serialized data with a key stored separately from the memory file.
- Document that contexts, actions, results, and metadata may contain sensitive information, and provide retention, redaction, and secure-deletion controls.
