T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:35- Finding
Persistent Plaintext Logging of User-Supplied Command Arguments
- Content
View full analysis
> "$DATA_DIR/history.log"; } cmd_palette() { echo " Primary: #2563EB | Secondary: #7C3AED | Accent: #F59E0B" _log "palette" "${1:-}" } cmd_font() { echo " Heading: Inter/Poppins | Body: Open Sans/Lato" _log "font" "${1:-}" } cmd_layout() { echo " Grid: 12-col | Spacing: 8px base | Max-width: 1200px" _log "layout" "${1:-}" } cmd_icon() { echo " Libraries: Heroicons | Lucide | Phosphor | Tabler" _log "icon" "${1:-}" } cmd_spacing() { echo " xs:4 sm:8 md:16 lg:24 xl:32 2xl:48" _log "spacing" "${1:-}" } cmd_breakpoint() { echo " sm:640 md:768 lg:1024 xl:1280 2xl:1536" _log "breakpoint" "${1:-}" } cmd_contrast() { echo " Check: webaim.org/resources/contrastchecker" _log "contrast" "${1:-}" } cmd_shadow() { echo " sm: 0 1px 2px | md: 0 4px 6px | lg: 0 10px 15px" _log "shadow" "${1:-}" } cmd_mockup() { echo " Tool: Figma | Sketch | Adobe XD" _log "mockup" "${1:-}" } cmd_checklist() { echo " [ ] Consistent spacing | [ ] Color contrast | [ ] Mobile responsive" _log "checklist" "${1:-}" } ``` ### Technical Analysis Each functional command passes its first user-supplied argument to `_log`, which appends that value verbatim to `$DATA_DIR/history.log`. The argument is not required to generate any of the static command output, making its retention unnecessary. The log is persistent across executions and is created using ordinary shell redirection. The script does not explicitly enforce restrictive directory or file permissions, so the resulting access controls depend on the user's environment and `umask`. If a user or calling agent accidentally includes a password, token, private project value, or other sens ...[truncated 1440 chars]- Remediation
View remediation
> "$DATA_DIR/history.log" } ``` Call it using only a fixed command name: ```bash _log "palette" ``` 2. If argument-derived telemetry is genuinely required, use an explicit allowlist and redact values that may contain credentials or private data. Do not store raw arbitrary input. 3. Enforce restrictive permissions before creating the directory and log: ```bash umask 077 mkdir -p -- "$DATA_DIR" chmod 700 -- "$DATA_DIR" touch -- "$DATA_DIR/history.log" chmod 600 -- "$DATA_DIR/history.log" ``` 4. Document what is logged, where it is stored, and how users can disable or delete logging. 5. Apply a retention policy, such as bounded rotation or deletion after a defined period, to prevent indefinite accumulation of historical input. 6. Add tests verifying that secrets and arbitrary command arguments never appear in `history.log`. ]]>
