T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:5- Finding
Configuration and Command Data May Be Stored with Overly Permissive Permissions
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh:5-7,scripts/script.sh:34, andscripts/script.sh:53-55
Vulnerability Type: Insecure local storage and plaintext argument logging
Risk Level: MediumVulnerable Code
bash DATA_DIR="${CONFIG_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/config}" DB="$DATA_DIR/data.log" mkdir -p "$DATA_DIR"bash _log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }bash cmd_add() { echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo " Added: $*" _log "add" "${1:-}" }Technical Analysis
The script creates its data directory and log files without establishing a restrictive
umaskor explicitly assigning secure permissions. Their effective permissions therefore depend on the invoking process's environment. Under a commonumaskof022, the directory may be created as mode0755and files as mode0644, making stored content readable by other local users.The
addoperation writes the complete supplied text todata.log. It also copies the first argument intohistory.log. The documented use cases encourage users to record configuration changes, endpoints, environment information, and deployment notes. Such values may include confidential infrastructure details or accidentally supplied credentials.The
CONFIG_DIRoverride can also point storage at a shared or otherwise insufficiently protected location. The script does not validate the ownership or permissions of that directory before writing data.Attack Path
- A user invokes the utility with confidential configuration information, for example through
config add. - The script creates
data.logandhistory.logusing permissions inherited from the currentumask. - With a permissive
umaskor sharedCONFIG_DIR, another local account can traverse the data directory and read one or both files. - The attacker obtains the recorded ...[truncated 669 chars]
- A user invokes the utility with confidential configuration information, for example through
- Remediation
View remediation
Remediation Suggestions
-
Set a restrictive process mask before creating any storage:
bash umask 077 -
Create the data directory with mode
0700and log files with mode0600. -
Validate that
DATA_DIRis owned by the current user and is not group- or world-writable before using it. -
Avoid recording raw command arguments in
history.log. Log only the command name or redact values likely to contain secrets. -
Document explicitly that credentials, tokens, private keys, and passwords must not be supplied as entries.
-
Where practical, accept sensitive input through protected files or standard input rather than command-line arguments, which may also be visible in process listings and shell history.
-
Review and correct permissions on existing installations during initialization.
-
