T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:5- Finding
Persistent Plaintext Storage of Potentially Sensitive Command Arguments
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh, lines 5–7 and 32–78
Vulnerability Type: Persistent plaintext logging of user-supplied arguments
Risk Level: MediumVulnerable Code
bash DATA_DIR="${ENV_CONFIG_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/env-config}" DB="$DATA_DIR/data.log" mkdir -p "$DATA_DIR"bash _log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; } cmd_run() { echo " Running: $1" _log "run" "${1:-}" } cmd_config() { echo " Config: $DATA_DIR/config.json" _log "config" "${1:-}" } cmd_status() { echo " Status: ready" _log "status" "${1:-}" } cmd_init() { echo " Initialized in $DATA_DIR" _log "init" "${1:-}" } cmd_list() { [ -f "$DB" ] && cat "$DB" || echo " (empty)" _log "list" "${1:-}" } cmd_add() { echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo " Added: $*" _log "add" "${1:-}" } cmd_remove() { echo " Removed: $1" _log "remove" "${1:-}" } cmd_search() { grep -i "$1" "$DB" 2>/dev/null || echo " Not found: $1" _log "search" "${1:-}" } cmd_export() { [ -f "$DB" ] && cat "$DB" || echo "No data" _log "export" "${1:-}" } cmd_info() { echo " Version: $VERSION | Data: $DATA_DIR" _log "info" "${1:-}" }Technical Analysis
The script creates a persistent data directory before command dispatch and records command arguments in predictable plaintext files. Most commands append their first argument to
history.log, whilecmd_addalso appends the complete argument list todata.log.The project is presented as an environment-configuration manager, where arguments may reasonably contain environment values, tokens, credentials, configuration strings, or sensitive filesystem paths. The logging implementation performs no secret redaction, input classification, consent check, ...[truncated 2104 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove persistent argument logging unless it is necessary for the documented functionality.
-
Make telemetry or command-history storage explicitly opt-in and document its location, contents, retention period, and security implications.
-
Never record raw secret-bearing arguments. Redact values matching sensitive names such as
PASSWORD,SECRET,TOKEN,KEY, and credential-bearing URLs. -
Establish private permissions before creating storage:
bash umask 077 mkdir -p -- "$DATA_DIR" chmod 700 -- "$DATA_DIR" touch -- "$DATA_DIR/history.log" "$DB" chmod 600 -- "$DATA_DIR/history.log" "$DB" -
Reject or normalize carriage returns and newline characters before writing user-controlled data to logs.
-
Use
printfinstead ofechofor predictable data handling:bash safe_value=${2//$'\n'/ } safe_value=${safe_value//$'\r'/ } printf '%s %s: %s\n' "$(date '+%m-%d %H:%M')" "$1" "$safe_value" >> "$DATA_DIR/history.log" -
Avoid creating persistent state for read-only operations such as
help,version,status, andinfo. -
Add automated tests verifying that sensitive arguments are not persisted, generated files are private, and multiline input cannot forge additional log entries.
-
