T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:5- Finding
Plaintext Persistent Storage of Potentially Confidential User Input
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh:5-7,scripts/script.sh:32,scripts/script.sh:55-57, andscripts/script.sh:77-80
Vulnerability Type: Plaintext storage and logging of potentially sensitive data
Risk Level: MediumVulnerable Code
bash DATA_DIR="${NDA_GENERATOR_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/nda-generator}" DB="$DATA_DIR/data.log" mkdir -p "$DATA_DIR"bash _log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }bash cmd_add() { echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo " Added: $*" _log "add" "${1:-}" }bash case "${1:-help}" in run) shift; cmd_run "$@" ;; config) shift; cmd_config "$@" ;; status) shift; cmd_status "$@" ;; init) shift; cmd_init "$@" ;; list) shift; cmd_list "$@" ;; add) shift; cmd_add "$@" ;; remove) shift; cmd_remove "$@" ;; search) shift; cmd_search "$@" ;; export) shift; cmd_export "$@" ;; info) shift; cmd_info "$@" ;; help|-h) show_help ;; version|-v) echo "nda-generator v$VERSION" ;; *) echo "Unknown: $1"; show_help; exit 1 ;; esacTechnical Analysis
The generic
addcommand appends all supplied arguments todata.log. It then passes the first argument to_log, which appends that value tohistory.log. Both files are persistent and stored beneath a user-controlled or default data directory.The code does not apply data classification, sensitive-value redaction, retention limits, encryption, or explicit restrictive file permissions. Consequently, resulting permissions depend on the invoking process's umask and pre-existing directory state. The directory can also be redirected through
NDA_GENERATOR_DIR.This storage functionality is not necessary for generating NDA text and is especially risky in the context of an NDA utility, where supplied arguments may includ ...[truncated 1807 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove
scripts/script.shif its generic persistent data-store functionality is not required for NDA generation. -
If persistence is necessary, make it explicit and opt-in. Inform users exactly which values will be retained before writing them.
-
Do not log NDA content, party identities, secrets, credentials, or unrestricted command arguments. Use an allowlist of non-sensitive metadata and redact sensitive values.
-
Create private storage with restrictive permissions:
bash umask 077 install -d -m 700 -- "$DATA_DIR" touch -- "$DB" "$DATA_DIR/history.log" chmod 600 -- "$DB" "$DATA_DIR/history.log" -
Validate
NDA_GENERATOR_DIRbefore use and reject unsafe or unexpected destinations where appropriate. -
Add configurable retention limits and a command that reliably deletes retained records. Clearly document that backups may preserve deleted data.
-
Avoid exposing sensitive records through unrestricted
list,search, orexportoperations. Require explicit confirmation or access controls when the execution environment supports them. -
Add automated tests verifying restrictive permissions, redaction behavior, opt-in persistence, and safe handling of sensitive arguments.
-
