T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:5- Finding
Potentially Sensitive Task Data Stored in Plaintext with Umask-Dependent Permissions
- Content
View full analysis
> "$DATA_DIR/history.log"; } ``` ```bash cmd_add() { echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo " Added: $*" _log "add" "${1:-}" } ``` ### Technical Analysis The script persistently writes user-provided task content to `data.log` and command-related content to `history.log`. These records are stored as plaintext. The script does not set a restrictive `umask` or explicitly apply access modes to the data directory and files. Consequently, the resulting permissions depend on the invoking process's umask and any pre-existing filesystem permissions. Under a commonly permissive umask such as `022`, the directory may be created with mode `0755` and files with mode `0644`, potentially allowing other local accounts to read their contents. Task and OKR descriptions may contain confidential business plans, personnel information, deadlines, or other sensitive user-provided data. The persistent storage behavior is also not clearly documented in `SKILL.md`, making users less likely to anticipate local retention. ### Attack Path 1. A user runs the task-management script with sensitive content, for example through the `add` command. 2. `cmd_add` appends the complete task text to `data.log`. 3. `_log` also writes command metadata and the first supplied argument to `history.log`. 4. The files are created using permissions derived from the caller's current umask because the script establishes no restrictive permission policy. 5. If those permissions permit access by other local users, another account or process on the same host can re ...[truncated 724 chars]- Remediation
View remediation
