T09 · Insecure Skill Coding Practices
- Location
references/best-practices.md:163- Finding
Sensitive User Data and Diagnostic Information May Be Transmitted Without Adequate Safeguards
- Content
View full analysis
{ // Send to monitoring service fetch('/api/errors', { method: 'POST', body: JSON.stringify({ message: event.message, stack: event.error?.stack, timestamp: new Date() }) }); }); } ``` From `references/error-handling.md:369-390`: ```typescript class ErrorLogger { private logs: any[] = []; log(error: Error, context?: Record) { this.logs.push({ message: error.message, code: error.code, stack: error.stack, context, timestamp: new Date() }); // Send to server this.flushIfNeeded(); } private async flushIfNeeded() { if (this.logs.length > 10) { const logs = this.logs.splice(0, 10); await fetch('/api/logs', { method: 'POST', body: JSON.stringify(logs) }).catch(console.error); } } } ``` ### Technical Analysis These examples serialize and transmit arbitrary user data, exception messages, stack traces, and unrestricted context objects to backend endpoints. They do not demonstrate: - A strict allowlist for transmitted fields. - Redaction of access tokens, email add ...[truncated 2563 chars]- Remediation
View remediation
