T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:6- Finding
Potentially Sensitive Content Is Stored Without Restrictive Permissions
- Content
View full analysis
/dev/null || echo " No entries yet. Use: linkedin-post draft " else local input="$*" local ts=$(date '+%Y-%m-%d %H:%M') echo "$ts|$input" >> "$DATA_DIR/draft.log" local total=$(wc -l < "$DATA_DIR/draft.log") echo " [Linkedin Post] draft: $input" echo " Saved. Total draft entries: $total" _log "draft" "$input" fi ;; ``` ### Technical Analysis The script creates its data directory and log files without setting a restrictive `umask` or explicitly enforcing permissions. Consequently, effective permissions depend on the environment from which the command is invoked. With a common `umask` of `022`, the directory can be created with mode `0755`, while newly created log and export files can receive mode `0644`. On a multi-user system, these modes can allow other local accounts to enumerate the data directory and read its contents. The stored information can include unpublished LinkedIn drafts, schedules, rewrite notes, content strategies, translations, and complete activity history. Export files are created in the same directory and inherit the same permissions issue. ### Attack Path 1. A victim runs a content command such as `linkedin-post draft "confidential campaign details"`. 2. The script creates `~/.local/share/linkedin-post` and its log files using permissions derived from the victim's current `umask`. 3. If those permissions grant access to other local users, another account locates the predictable directory. 4. ...[truncated 700 chars]- Remediation
View remediation
