T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:4- Finding
Undocumented Persistent Logging of Caller-Supplied Arguments
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh:4-7, 35-84
Vulnerability Type: Undocumented plaintext logging to a caller-configurable path
Risk Level: MediumVulnerable Code
bash VERSION="2.0.0" DATA_DIR="${BABY_GUIDE_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/baby-guide}" DB="$DATA_DIR/data.log" mkdir -p "$DATA_DIR"bash _log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; } cmd_palette() { echo " Primary: #2563EB | Secondary: #7C3AED | Accent: #F59E0B" _log "palette" "${1:-}" } cmd_font() { echo " Heading: Inter/Poppins | Body: Open Sans/Lato" _log "font" "${1:-}" } cmd_layout() { echo " Grid: 12-col | Spacing: 8px base | Max-width: 1200px" _log "layout" "${1:-}" } cmd_icon() { echo " Libraries: Heroicons | Lucide | Phosphor | Tabler" _log "icon" "${1:-}" } cmd_spacing() { echo " xs:4 sm:8 md:16 lg:24 xl:32 2xl:48" _log "spacing" "${1:-}" } cmd_breakpoint() { echo " sm:640 md:768 lg:1024 xl:1280 2xl:1536" _log "breakpoint" "${1:-}" } cmd_contrast() { echo " Check: webaim.org/resources/contrastchecker" _log "contrast" "${1:-}" } cmd_shadow() { echo " sm: 0 1px 2px | md: 0 4px 6px | lg: 0 10px 15px" _log "shadow" "${1:-}" } cmd_mockup() { echo " Tool: Figma | Sketch | Adobe XD" _log "mockup" "${1:-}" } cmd_checklist() { echo " [ ] Consistent spacing | [ ] Color contrast | [ ] Mobile responsive" _log "checklist" "${1:-}" }Technical Analysis
The script creates a persistent data directory on every invocation and appends command arguments to
history.log. This behavior is not disclosed in the documented baby-care functionality, and the script itself provides unrelated UI design commands.Raw arguments are written in plaintext without filtering, retention controls, restrictive permissi ...[truncated 2452 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
scripts/script.shfrom the package because its design-reference behavior is unrelated to the documented baby-care skill. - If the script is intentional, document its purpose, filesystem effects, log destination, logged fields, and retention policy.
- Disable logging by default and require explicit user opt-in.
- Do not record raw caller-supplied arguments. Log only a fixed command identifier when operational telemetry is genuinely required.
- Validate and canonicalize
BABY_GUIDE_DIR; reject unexpected, relative, or untrusted destinations. - Create the data directory with restrictive permissions, such as mode
0700, and create logs with mode0600. - Refuse to write when the destination is a symbolic link or is not a regular file. Use safe file-opening semantics that prevent symbolic-link following where supported.
- Define a bounded retention policy and provide a command that allows users to inspect and delete stored history.
- Add tests confirming that ordinary execution does not modify the filesystem unless logging has been explicitly enabled.
- Remove
