T09 · Insecure Skill Coding Practices
- Location
scripts/wechat_send.sh:19- Finding
Predictable Temporary Files Expose Sensitive Message and Contact Data
- Content
View full analysis
&2; exit 1; } command -v cliclick >/dev/null || fail "cliclick not found. Install: brew install cliclick" clip_write() { # Write text to clipboard via temp file (safe for CJK + multiline) local text="$1" printf '%s' "$text" > /tmp/wechat_send_clip.txt osascript -e 'set the clipboard to (read POSIX file "/tmp/wechat_send_clip.txt" as "utf8")' } ``` The same predictable screenshot paths are later written directly: ```bash screencapture -x -R "50,50,1200,150" "$SCREENSHOT_TITLE" || fail "Cannot capture title screenshot" ``` ```bash screencapture -x -R "50,50,500,600" "$SCREENSHOT_DROPDOWN" || fail "Cannot capture dropdown screenshot" ``` ### Technical Analysis The script stores message text and WeChat screenshots under fixed, globally predictable `/tmp` paths. It does not: - Create the files atomically. - Use a private temporary directory. - Set a restrictive `umask`. - verify file ownership or reject symbolic links. - Remove the files after use. The shell redirection to `/tmp/wechat_send_clip.txt` follows a pre-existing symbolic link. Consequently, a local user who can create this path before the Skill runs may redirect the write to another file writable by the victim. The predictable files also retain plaintext message content, contact names, and captured portions of the WeChat interface after execution. The actual ability to read files may depend on the operating system's temporary-directory and default permissi ...[truncated 1430 chars]- Remediation
View remediation
"$CLIP_FILE" || fail "Cannot create clipboard file" osascript -e \ "set the clipboard to (read POSIX file \"$CLIP_FILE\" as \"utf8\")" rm -f -- "$CLIP_FILE" } ``` 3. Maintain file permissions of `0600` and directory permissions of `0700`. 4. Do not reuse stable filenames across executions. 5. Remove clipboard data immediately after it is read. 6. Retain screenshots only when fallback analysis is required and remove them as soon as fallback processing completes. 7. If artifacts must be retained, verify that each file is a regular file owned by the current user and is not a symbolic link. ]]>
