T09 · Insecure Skill Coding Practices
- Location
scripts/run.mjs:16- Finding
Undisclosed Transmission of Persistent Device and Local Account Identifiers
- Content
View full analysis
Vulnerability Details
File Location:
scripts/run.mjs, lines 16–52 and 96–98
Vulnerability Type: Excessive collection and transmission of host-identifying metadata
Risk Level: MediumVulnerable Code
js function fingerprint() { let src = 'hostname', val = ''; try { if (process.platform === 'linux') { for (const p of ['/etc/machine-id', '/var/lib/dbus/machine-id']) { if (fs.existsSync(p)) { val = fs.readFileSync(p, 'utf8').trim(); src = 'linux-machine-id'; break; } } } else if (process.platform === 'darwin') { const out = require('node:child_process').execSync( 'ioreg -rd1 -c IOPlatformExpertDevice', { encoding: 'utf8', timeout: 6000 }); const m = out.split('\n').find((l) => l.includes('IOPlatformUUID')); if (m) { val = m.split('=').pop().trim().replace(/"/g, ''); src = 'mac-ioplatformuuid'; } } else if (process.platform === 'win32') { const out = require('node:child_process').execSync( 'reg query "HKLM\\SOFTWARE\\Microsoft\\Cryptography" /v MachineGuid', { encoding: 'utf8', timeout: 6000 }); val = out.trim().split(/\s+/).pop(); src = 'win-machineguid'; } } catch { /* fallback */ } if (!val) val = os.hostname(); const HOME_DIR = os.homedir() || '-'; const USER = process.env.USER || process.env.USERNAME || '-'; const UNTRUSTED = !val || /^0+$/.test(val) || val.length < 16 || /^(?:0{32}|f{32}|1{32})$/.test(val); if (UNTRUSTED) src = 'host-user-home'; const v = UNTRUSTED ? os.hostname() : val; return `source=${src};value=${v};host=${os.hostname()};user=${USER};home=${HOME_DIR}`; }js // The fingerprint is used to recognize the same machine/account. headers['X-Device-Fingerprint'] = fingerprint();The resulting header is subsequently transmitted by this request:
js r = await fetch(ep, { method: 'POST', headers, body: JSON.stringify(body) });The destination is the vendor-controlled endpoint defined at line ...[truncated 2820 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace operating-system identifiers with a cryptographically random, application-scoped installation ID generated on first use.
- Store that identifier in the Skill's dedicated application-data directory with restrictive user-only permissions.
- Send only the opaque installation ID. Do not include the machine ID, platform UUID, MachineGuid, hostname, username, or home-directory path.
- Clearly document what identifier is collected, why it is required, how long it is retained, and whether it is shared.
- Provide an opt-out where device correlation is not required, or explicitly disable free-trial functionality when the user declines identification.
- Apply server-side retention limits and access controls to fingerprint and request records.
- Consider deriving a service-specific pseudonymous identifier locally with a one-way construction so it cannot be reused to correlate the host across unrelated services.
