T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:5- Finding
Undisclosed Plaintext Persistence of User-Supplied Arguments
- Content
View full analysis
> "$DATA_DIR/history.log"; } cmd_run() { echo " Running: $1" _log "run" "${1:-}" } cmd_config() { echo " Config: $DATA_DIR/config.json" _log "config" "${1:-}" } cmd_status() { echo " Status: ready" _log "status" "${1:-}" } cmd_init() { echo " Initialized in $DATA_DIR" _log "init" "${1:-}" } cmd_list() { [ -f "$DB" ] && cat "$DB" || echo " (empty)" _log "list" "${1:-}" } cmd_add() { echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo " Added: $*" _log "add" "${1:-}" } cmd_remove() { echo " Removed: $1" _log "remove" "${1:-}" } cmd_search() { grep -i "$1" "$DB" 2>/dev/null || echo " Not found: $1" _log "search" "${1:-}" } cmd_export() { [ -f "$DB" ] && cat "$DB" || echo "No data" _log "export" "${1:-}" } cmd_info() { echo " Version: $VERSION | Data: $DATA_DIR" _log "info" "${1:-}" } ``` ### Technical Analysis The script creates persistent storage under the invoking user's data directory and records command arguments in plaintext. The `_log` function appends the first argument supplied to most commands to `history.log`. The `add` command additionally writes all supplied arguments to `data.log`. This persistence is not disclosed in `SKILL.md` and is unrelated to the skill's principal text-paraphrasing functionality. Text processed by a paraphrasing tool may contain confidential, personal, academic, or proprietary information. The implementation provides no consent mechanism, content filtering, retention limit, encryption, or explicit restrictive file-permission setu ...[truncated 2014 chars]- Remediation
View remediation
