T09 · Insecure Skill Coding Practices
- Location
db.js:5- Finding
Contact PII Stored in an Unencrypted SQLite Database
- Content
View full analysis
{ db.run(`CREATE TABLE IF NOT EXISTS contacts ( id INTEGER PRIMARY KEY AUTOINCREMENT, name TEXT NOT NULL, phone TEXT, email TEXT, notes TEXT )`); }); ``` Contact information is inserted without encryption: ```js case 'add_contact': { const { name, phone, email, notes } = args; const result = await db.run( 'INSERT INTO contacts (name, phone, email, notes) VALUES (?, ?, ?, ?)', [name, phone, email, notes] ); return { content: [{ type: 'text', text: `Added contact with ID ${result.lastID}` }] }; } ``` ### Technical Analysis The application stores names, phone numbers, email addresses, and free-form notes directly in `contacts.db` without application-level encryption. The database is created inside the project directory, and the code does not explicitly set or verify owner-only file permissions. SQLite does not encrypt database contents by default. Consequently, any process or account that obtains filesystem read access to the database can recover all stored records using standard SQLite tooling. Free-form notes may contain information more sensitive than the defined contact fields. This issue does not independently grant remote access or elevate privileges. Exploitation requires existing access to the database file, such as access through another compromised local process, permissive directory or umask settings, an exposed backup, or accidental publication of the project directory. ### Attack Path 1. A user adds contacts through the `add_contact` MCP tool. 2. The application writes the contact fields directly to `contacts.db`. 3. An attacker obtains read access to the project ...[truncated 675 chars]- Remediation
View remediation
