T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:6- Finding
Survey responses may be stored with overly permissive filesystem permissions
- Content
View full analysis
> "$DATA_DIR/history.log"; } ``` A representative response-writing path is: ```bash run) shift if [ $# -eq 0 ]; then echo "Recent run entries:" tail -20 "$DATA_DIR/run.log" 2>/dev/null || echo " No entries yet. Use: survey run " else local input="$*" local ts=$(date '+%Y-%m-%d %H:%M') echo "$ts|$input" >> "$DATA_DIR/run.log" local total=$(wc -l < "$DATA_DIR/run.log") echo " [Survey] run: $input" echo " Saved. Total run entries: $total" _log "run" "$input" fi ``` The same storage pattern is repeated for other commands in lines 148-289. ### Technical Analysis The script creates its data directory and log files without establishing restrictive permissions. File and directory modes therefore depend on the invoking process's `umask`. With a common `umask` of `022`, the directory may be created as `0755` and newly created log files as `0644`. Command input is written in plaintext both to command-specific logs and to `history.log`. Because the project is presented as a survey utility, this input may include responses, reports, or other personal or confidential information. On a multi-user system, permissive modes can allow other local accounts to read that information. Exploitation is conditional on the effective filesystem permissions and the attacker already having local access. The code does not itself provide remote access or privilege escalation. ### Attack Path 1. A user runs a command containing confidential survey informa ...[truncated 805 chars]- Remediation
View remediation
