T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:5- Finding
Undocumented Persistent Storage of Command Arguments Without Restrictive Permissions
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh, lines 5-7 and 33-73
Vulnerability Type: Plaintext sensitive-data retention and insecure file handling
Risk Level: MediumVulnerable Code
bash DATA_DIR="${SHOPIFY_HELPER_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/shopify-helper}" DB="$DATA_DIR/data.log" mkdir -p "$DATA_DIR"bash _log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; } cmd_run() { echo " Running: $1" _log "run" "${1:-}" } cmd_config() { echo " Config: $DATA_DIR/config.json" _log "config" "${1:-}" } cmd_status() { echo " Status: ready" _log "status" "${1:-}" } cmd_init() { echo " Initialized in $DATA_DIR" _log "init" "${1:-}" } cmd_list() { [ -f "$DB" ] && cat "$DB" || echo " (empty)" _log "list" "${1:-}" } cmd_add() { echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo " Added: $*" _log "add" "${1:-}" } cmd_remove() { echo " Removed: $1" _log "remove" "${1:-}" } cmd_search() { grep -i "$1" "$DB" 2>/dev/null || echo " Not found: $1" _log "search" "${1:-}" } cmd_export() { [ -f "$DB" ] && cat "$DB" || echo "No data" _log "export" "${1:-}" } cmd_info() { echo " Version: $VERSION | Data: $DATA_DIR" _log "info" "${1:-}" }Technical Analysis
The script persistently records raw command arguments in
history.log, while theaddcommand stores all supplied arguments indata.log. This behavior is not disclosed in the skill documentation and is unrelated to the documented Shopify advisory commands.No restrictive
umaskis established, and the directory and log files are not explicitly assigned owner-only permissions. Their effective permissions therefore depend on the invoking environment's existingumask. On systems with permissive defaults, other local users or processes may be able to read business information, search terms, product details, or secrets accidentally supplied a ...[truncated 1889 chars]- Remediation
View remediation
Remediation Suggestions
- Remove
scripts/script.shif the generic storage utility is not required for the documented Shopify skill. - Explicitly disclose any persistent logging, including the stored fields, storage location, retention period, and deletion procedure.
- Avoid logging raw user arguments. Store only the minimum operational metadata required, and redact credentials, access tokens, email addresses, and other sensitive values.
- Establish restrictive permissions before creating data:
bash umask 077 install -d -m 0700 -- "$DATA_DIR" touch -- "$DB" "$DATA_DIR/history.log" chmod 0600 -- "$DB" "$DATA_DIR/history.log"- Validate and constrain
SHOPIFY_HELPER_DIR. Reject empty, unexpected, relative, or untrusted locations where appropriate. - Refuse symbolic-link log targets before writing, and open files using a mechanism that provides no-follow and exclusive-creation protections where available.
- Avoid executing the utility with elevated privileges. If elevated operation is unavoidable, use a fixed, administrator-owned data directory that unprivileged users cannot modify.
- Add explicit data-retention and secure-deletion commands, and test permissions under different host
umaskconfigurations.
- Remove
