T09 · Insecure Skill Coding Practices
- Location
scripts/tavily_search_fast.py:15- Finding
Search Queries and Results Persisted in an Unprotected Plaintext Cache
- Content
View full analysis
Vulnerability Details
File Location:
scripts/tavily_search_fast.py, lines 15-50
Vulnerability Type: Plaintext storage of potentially sensitive search data
Risk Level: MediumVulnerable Code
python # Cache configuration CACHE_DIR = Path.home() / ".cache" / "tavily_search" CACHE_DURATION = 300 # 5 minutes cache def get_cache_key(query: str, **kwargs) -> str: """Generate cache key from query and parameters.""" cache_data = f"{query}:{json.dumps(kwargs, sort_keys=True)}" return hashlib.md5(cache_data.encode()).hexdigest() def get_cached_result(cache_key: str) -> Optional[Dict]: """Get cached result if valid.""" cache_file = CACHE_DIR / f"{cache_key}.json" if not cache_file.exists(): return None try: with open(cache_file, 'r') as f: cached = json.load(f) # Check if cache is still valid if time.time() - cached.get('timestamp', 0) < CACHE_DURATION: return cached['data'] except Exception: pass return None def cache_result(cache_key: str, data: Dict) -> None: """Cache search result.""" try: CACHE_DIR.mkdir(parents=True, exist_ok=True) cache_file = CACHE_DIR / f"{cache_key}.json" with open(cache_file, 'w') as f: json.dump({ 'timestamp': time.time(), 'data': data }, f) except Exception: pass # Cache failures shouldn't break searchTechnical Analysis
The optimized search script writes Tavily responses to JSON files beneath
~/.cache/tavily_search. These responses can contain the original search query, result titles, URLs, and retrieved content.The implementation does not explicitly restrict the cache directory to mode
0700or individual cache files to mode0600. Effective permissions therefore depend on the runtime environment and process umask. In permissively configured or shared environments, ano ...[truncated 1726 chars]- Remediation
View remediation
Remediation Suggestions
- Disable persistent caching by default and require an explicit
--cacheoption to enable it. - Clearly document that enabling the cache stores search queries and responses locally.
- Create the cache directory with owner-only permissions:
python CACHE_DIR.mkdir(parents=True, exist_ok=True, mode=0o700) os.chmod(CACHE_DIR, 0o700) - Create cache files atomically with mode
0600, rather than relying on the process umask. - Delete expired entries when they are encountered and add a startup cleanup routine for stale files.
- Provide a
--clear-cacheoption and an option to set a shorter retention period. - Avoid caching queries or responses identified as sensitive. If persistent storage is necessary, consider authenticated encryption backed by an operating-system credential facility.
- Do not silently suppress every cache exception; report permission and cleanup failures without exposing cached content.
- Disable persistent caching by default and require an explicit
