T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:5- Finding
Notification Content Stored in Plaintext with Potentially Permissive Filesystem Permissions
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh:5-8, with user-controlled logging sinks atscripts/script.sh:135-142and equivalent command handlers through line 289
Vulnerability Type: Insecure storage of potentially sensitive data
Risk Level: MediumVulnerable Code
bash DATA_DIR="${HOME}/.local/share/notification" mkdir -p "$DATA_DIR" _log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }A representative command handler stores the supplied content twice:
bash local input="$*" local ts=$(date '+%Y-%m-%d %H:%M') echo "$ts|$input" >> "$DATA_DIR/run.log" local total=$(wc -l < "$DATA_DIR/run.log") echo " [Notification] run: $input" echo " Saved. Total run entries: $total" _log "run" "$input"The same storage pattern is repeated for the
check,convert,analyze,generate,preview,batch,compare,export,config,status, andreporthandlers.Technical Analysis
The script creates its data directory and log files without explicitly enforcing restrictive filesystem permissions. Their resulting modes depend on the invoking process's
umask. For example, a permissive or common022umask can create the directory as mode0755and newly redirected log files as mode0644, allowing other local users to traverse the directory and read notification records.Arbitrary command arguments are retained in plaintext in a command-specific log and duplicated in
history.log. Because notification content may include user messages, operational details, identifiers, or other private information, relying on ambientumasksettings violates least-privilege storage principles.The issue is conditional on the effective filesystem permissions and local account separation. The script does not transmit this information over a network and does not grant an attacker elevated privileges.
Attack Path
- A user runs a command conta ...[truncated 1095 chars]
- Remediation
View remediation
Remediation Suggestions
-
Set a restrictive process umask before creating any storage:
bash umask 077 -
Create and verify the data directory with owner-only permissions:
bash install -d -m 700 -- "$DATA_DIR" chmod 700 -- "$DATA_DIR" -
Create log files with mode
0600before appending data:bash touch -- "$DATA_DIR/history.log" chmod 600 -- "$DATA_DIR/history.log"Apply the same protection to every command-specific log.
-
Avoid duplicating complete user input in
history.log. Record only the event type and timestamp, or store a redacted summary. -
Add configurable retention limits and a command that securely removes stored history.
-
Warn users that supplied arguments are persisted locally, and advise against passing credentials, access tokens, or other secrets.
-
On startup, validate that the data directory is owned by the current user, is not an unexpected symbolic link, and is not accessible to group or other users. Refuse operation or repair permissions when validation fails.
-
