T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:29- Finding
Undisclosed Persistent Logging of User-Controlled Input
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh, lines 4-6 and 29-81
Vulnerability Type: Plaintext storage of potentially sensitive user input
Risk Level: MediumVulnerable Code
bash DATA_DIR="${LIVE_STREAM_SCRIPT_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/live-stream-script}" DB="$DATA_DIR/data.log" mkdir -p "$DATA_DIR"bash _log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; } cmd_draft() { echo " Draft: $1 Target: ${2:-800} words" _log "draft" "${1:-}" } cmd_headline() { echo " 1. How to $1 2. $1: Complete Guide 3. Why $1 Matters" _log "headline" "${1:-}" } cmd_outline() { echo " 1. Intro | 2. Problem | 3. Solution | 4. Examples | 5. CTA" _log "outline" "${1:-}" } cmd_seo() { echo " Keywords: $1 | Title tag | Meta desc | H1-H3 | Internal links" _log "seo" "${1:-}" } cmd_schedule() { echo " Mon: Research | Tue: Write | Wed: Edit | Thu: Publish | Fri: Promote" _log "schedule" "${1:-}" } cmd_hooks() { echo " Question | Statistic | Story | Bold claim | Controversy" _log "hooks" "${1:-}" } cmd_cta() { echo " Subscribe | Share | Comment | Try it | Learn more" _log "cta" "${1:-}" } cmd_repurpose() { echo " Blog -> Thread -> Video -> Carousel -> Newsletter" _log "repurpose" "${1:-}" } cmd_metrics() { echo " Views | Clicks | Shares | Time on page | Conversions" _log "metrics" "${1:-}" } cmd_ideas() { echo " How-to | Listicle | Case study | Interview | Comparison" _log "ideas" "${1:-}" }Technical Analysis
The script persistently appends command names and raw user-controlled arguments to
history.log. The documented skill behavior describes generation of textual livestream content but does not disclose persistent logging, a retention period, or a deletion mechanism....[truncated 1407 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove argument logging unless it is necessary for the declared functionality.
- If logging is required, make it explicitly opt-in and document what is recorded, where it is stored, and how long it is retained.
- Avoid recording raw user content. Log only non-sensitive event metadata, such as the command name and success status.
- Apply restrictive permissions before creating data:
bash umask 077 mkdir -p -- "$DATA_DIR" - Create log files with an explicit owner-only mode and verify that the configured data directory is not shared.
- Add log rotation, retention limits, and a command that securely removes stored history.
- Validate
LIVE_STREAM_SCRIPT_DIRbefore use if it can be supplied by an untrusted launcher or environment.
