T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:5- Finding
Undisclosed Plaintext Persistence of User-Supplied Arguments
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh:5-7, 34, 52-55
Vulnerability Type: Undisclosed plaintext data storage and activity logging
Risk Level: MediumVulnerable Code
bash DATA_DIR="${FORTUNE_TELLER_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/fortune-teller}" DB="$DATA_DIR/data.log" mkdir -p "$DATA_DIR" _log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; } cmd_add() { echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo " Added: $*" _log "add" "${1:-}" }Technical Analysis
The script persistently stores arbitrary arguments supplied to the
addcommand indata.log. It also records command activity and the first argument inhistory.log. The logging occurs automatically and is not clearly disclosed by the skill documentation.Both files are plaintext, and the script does not establish a restrictive creation mask or explicitly set file permissions. Their effective permissions therefore depend on the invoking process's environment and
umask. If users provide personal, confidential, or otherwise sensitive text, that content remains on disk after execution.This behavior is also outside the documented fortune-calculation functionality and unnecessarily increases the amount of retained user data.
Attack Path
- A user invokes the generic utility with sensitive content, for example through the
addcommand. cmd_addappends the complete argument string todata.log._logseparately appends the first argument and command metadata tohistory.log.- The content persists across sessions in the configured data directory.
- A local process or account that has permission to read those files can recover the retained content. The same content can also be exposed later through the script's
listorexportcommands when invoked by an authorized user or process.
Impact Assessment
The issue can expose user-supplied informati ...[truncated 454 chars]
- A user invokes the generic utility with sensitive content, for example through the
- Remediation
View remediation
Remediation Suggestions
-
Remove
script.shif the generic database and logging functionality is not required for the fortune-telling skill. -
Do not log command arguments by default. Record only non-sensitive operational metadata when logging is necessary.
-
Clearly document all persistent storage, including the data collected, storage path, retention period, and deletion procedure.
-
Establish restrictive permissions before creating storage:
bash umask 077 mkdir -p -- "$DATA_DIR" -
Create files with owner-only permissions and verify that the destination is an expected regular file before appending.
-
Provide an explicit opt-in mechanism for logging and a command that securely removes retained history.
-
Avoid accepting secrets, credentials, or other sensitive data through this utility.
-
