T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:6- Finding
Sensitive activity records are created without enforced restrictive permissions
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh:6-7and entry-writing branches such asscripts/script.sh:140-151
Vulnerability Type: Insecure storage permissions for potentially sensitive data
Risk Level: MediumVulnerable Code
bash DATA_DIR="${HOME}/.local/share/fitlog" mkdir -p "$DATA_DIR"Entry-writing branches subsequently create plaintext log files without setting their permissions:
bash add) shift if [ $# -eq 0 ]; then echo "Recent add entries:" tail -20 "$DATA_DIR/add.log" 2>/dev/null || echo " No entries yet. Use: fitlog add <input>" else local input="$*" local ts=$(date '+%Y-%m-%d %H:%M') echo "$ts|$input" >> "$DATA_DIR/add.log" local total=$(wc -l < "$DATA_DIR/add.log") echo " [Fitlog] add: $input" echo " Saved. Total add entries: $total" _log "add" "$input" fi ;;The same storage pattern is repeated for the other logging commands and for
history.log.Technical Analysis
FitLog is presented as a fitness, health, reminder, and activity-tracking tool. Its logs can therefore contain sensitive health information, schedules, habits, project details, and other personal data.
The script creates its data directory with
mkdir -pand creates log files through ordinary append redirection. It does not set a restrictiveumask, explicitly assign directory mode0700, or assign file mode0600. Effective permissions consequently depend on the invoking process's existing umask. In an environment with a permissive umask, the resulting files may be readable by other local users.The data is also stored as unencrypted plaintext. Encryption is not always required for a local command-line application, but strict access permissions are necessary because of the potentially sensitive nature of the records.
Attack Path
- A victim runs ...[truncated 1116 chars]
- Remediation
View remediation
Remediation Suggestions
Apply restrictive permissions before creating or writing any data:
bash umask 077 DATA_DIR="${HOME}/.local/share/fitlog" mkdir -p -m 700 "$DATA_DIR" chmod 700 "$DATA_DIR"Ensure every existing and newly created data file is accessible only to its owner:
bash find "$DATA_DIR" -type f -exec chmod 600 {} +Additional hardening should include:
- Rejecting a
HOMEvalue that does not resolve to a directory owned by the current user. - Checking that
DATA_DIRis not a symbolic link before writing sensitive records. - Documenting that entries and exports are stored locally in plaintext.
- Applying mode
0600to JSON, CSV, and text exports as well as log files. - Providing an optional secure deletion or retention mechanism for health-related records.
- Rejecting a
