T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:14- Finding
Sensitive Nutrition Records Created Without Restrictive Permissions
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh, lines 14-21
Vulnerability Type: Sensitive local data stored with permissions controlled only by the caller's umask
Risk Level: MediumVulnerable Code
bash DATA_DIR="${HOME}/.diet" MEALS_FILE="${DATA_DIR}/meals.json" WATER_FILE="${DATA_DIR}/water.json" ensure_data_dir() { mkdir -p "${DATA_DIR}" [[ -f "${MEALS_FILE}" ]] || echo '[]' > "${MEALS_FILE}" [[ -f "${WATER_FILE}" ]] || echo '[]' > "${WATER_FILE}" }The files are subsequently rewritten without enforcing their permissions:
python with open(meals_file, 'w') as f: json.dump(data, f, ensure_ascii=False, indent=2)python with open(water_file, 'w') as f: json.dump(data, f, ensure_ascii=False, indent=2)Technical Analysis
The Skill stores meal history, food descriptions, calorie and macronutrient measurements, and water intake under
~/.diet/. This information may constitute sensitive health-related data.The storage directory and JSON files are created without a restrictive
umaskor explicit permission modes. Their permissions therefore depend entirely on the invoking process's environment. With a common022umask, the directory can be created as mode0755and the JSON files as mode0644. Where the user's home-directory permissions permit traversal, other local users could read these records.Reopening the files with Python's
open(..., 'w')does not correct permissions that were assigned when the files were created. The implementation also does not repair preexisting files or directories that have overly broad permissions.Attack Path
- A user invokes
log,water, or another command that callsensure_data_dir. - The script creates
~/.diet,meals.json, andwater.jsonusing permissions derived from the user's current umask. - Under a permissive umask, the files become readable by users outside the o ...[truncated 793 chars]
- A user invokes
- Remediation
View remediation
Remediation Suggestions
-
Set a restrictive umask before creating or updating the data:
bash umask 077 -
Explicitly protect the storage directory:
bash mkdir -p -m 700 "${DATA_DIR}" chmod 700 "${DATA_DIR}" -
Create and repair the data files with owner-only permissions:
bash [[ -f "${MEALS_FILE}" ]] || printf '%s\n' '[]' > "${MEALS_FILE}" [[ -f "${WATER_FILE}" ]] || printf '%s\n' '[]' > "${WATER_FILE}" chmod 600 "${MEALS_FILE}" "${WATER_FILE}" -
Validate that the data paths are regular files owned by the current user before reading or overwriting them.
-
Use atomic writes through temporary files created inside the protected directory, set each temporary file to mode
0600, and rename it into place. This will also reduce the risk of data corruption during interrupted writes.
-
