T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:34- Finding
Undocumented Plaintext Retention of User-Supplied Arguments
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh, lines 6-8, 34, 36-39, and 62-65
Vulnerability Type: Undocumented plaintext storage of potentially sensitive input
Risk Level: MediumVulnerable Code
bash DATA_DIR="${PROOFREADER_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/proofreader}" DB="$DATA_DIR/data.log" mkdir -p "$DATA_DIR"bash _log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }bash cmd_run() { echo " Running: $1" _log "run" "${1:-}" }bash cmd_add() { echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo " Added: $*" _log "add" "${1:-}" }Technical Analysis
The script creates a persistent data directory whenever it starts. Its logging function then appends command names and user-supplied arguments to
history.logwithout obtaining consent or filtering sensitive content. Theaddcommand additionally writes all supplied arguments todata.log.This behavior is not disclosed in
SKILL.md, which presents the project as a proofreading utility. Users may consequently provide confidential documents, personal information, or proprietary text without expecting command arguments to be retained.The files are created using permissions determined by the caller's current
umask; the script does not establish a restrictive mode such as owner-only access. The content is stored in plaintext and has no defined retention period. Genericlist,search, andexportcommands can subsequently expose the stored data.Attack Path
- A user invokes
scripts/script.shand supplies sensitive text torunoradd. - For
run, the first argument is passed to_logand appended tohistory.log. - For
add, all arguments are appended todata.log, and the first argument is also written tohistory.log. - The plaintext data remains under the configured
PROOFREADER_DIRor the default ...[truncated 831 chars]
- A user invokes
- Remediation
View remediation
Remediation Suggestions
- Remove
scripts/script.shif it is not required for the documented proofreading functionality. - Do not record raw document text or command arguments. Log only non-sensitive operational metadata when logging is necessary.
- Make all data retention explicit, documented, and opt-in rather than enabled by default.
- Establish restrictive permissions before creating files, for example with
umask 077, and verify that the data directory and files are accessible only to their owner. - Provide commands to inspect and securely delete retained information, together with a clearly defined retention period.
- Warn users before storing any supplied content and distinguish temporary processing from persistent storage.
- If persistent storage is genuinely required, minimize collected data and consider encryption appropriate to the threat model.
- Align the documented command set in
SKILL.mdwith the actual executable behavior so users can make an informed decision before supplying sensitive content.
- Remove
