T09 · Insecure Skill Coding Practices
- Location
scripts/proxy.py:398- Finding
Persistent Plaintext Logging of Sensitive Conversation and Tool Data
- Content
View full analysis
Vulnerability Details
File Location:
scripts/proxy.py:54-72, 398-424
Vulnerability Type: Sensitive data stored in plaintext diagnostic files
Risk Level: MediumTechnical Analysis
The proxy enables diagnostic logging unconditionally. It appends the first 8,000 characters of every inbound request body to
proxy-requests.logand overwritesproxy-last-upstream.jsonwith the complete translated upstream payload.python LOG_PATH = os.path.join(os.path.dirname(os.path.abspath(__file__)), "proxy-requests.log") FULL_REQ_PATH = os.path.join(os.path.dirname(os.path.abspath(__file__)), "proxy-last-request.json") FULL_UP_PATH = os.path.join(os.path.dirname(os.path.abspath(__file__)), "proxy-last-upstream.json") FULL_ERR_PATH = os.path.join(os.path.dirname(os.path.abspath(__file__)), "proxy-last-error.txt") def _log(msg): """Append a line to proxy-requests.log (best-effort, never raises).""" try: with open(LOG_PATH, "a", encoding="utf-8") as f: f.write(f"[{time.strftime('%Y-%m-%d %H:%M:%S')}] {msg}\n") except Exception: pass def _dump(path, text): """Overwrite a debug dump file (best-effort, never raises).""" try: with open(path, "w", encoding="utf-8") as f: f.write(text) except Exception: passpython # --- debug logging (auth redacted) --- _log(f">>> {self.command} {self.path}") _log( "headers: " + json.dumps( { k: (v if k.lower() != "authorization" else "Bearer ***") for k, v in self.headers.items() } ) ) _log("body(first 8000): " + body.decode("utf-8", "replace")[:8000]) try: req = json.loads(body.decode("utf-8") or "{}") except json.JSONDecodeError: _log("<<< 400 bad json") self.send_error(400, "bad json") return model = req.get("model", "gpt-5.6-luna") auth = self.headers.get("Author ...[truncated 1993 chars]- Remediation
View remediation
Remediation Suggestions
- Disable body and payload logging by default.
- Require an explicit environment variable such as
PROXY_DEBUG=1before creating diagnostic files. - Log only non-sensitive metadata such as timestamp, route, status, duration, model, and body size.
- If debug payload capture is necessary, recursively redact message content, instructions, tool arguments, tool outputs, image data, and fields whose names indicate credentials or secrets.
- Create files with owner-only permissions, such as mode
0600on supported platforms. - Add rotation, maximum file size, and short retention periods.
- Provide a documented cleanup procedure and warn users that diagnostic data can contain complete conversations.
- Correct the documentation so it accurately states what is stored.
- Remove the unused
FULL_REQ_PATHdeclaration or implement only a safe, explicitly enabled version of that diagnostic feature.
