T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:6- Finding
Undocumented Persistent Plaintext Logging of User-Supplied Arguments
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh:6-9, 32, 35-75
Vulnerability Type: Persistent plaintext storage of potentially sensitive user input
Risk Level: MediumThe secondary utility script persistently stores command arguments without notifying the user, obtaining explicit consent, applying a retention policy, or enforcing restrictive file permissions. This behavior is not documented in
SKILL.md.Vulnerable Code
bash DATA_DIR="${NAME_GENERATOR_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/name-generator}" DB="$DATA_DIR/data.log" mkdir -p "$DATA_DIR"bash _log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }bash cmd_run() { echo " Running: $1" _log "run" "${1:-}" } cmd_config() { echo " Config: $DATA_DIR/config.json" _log "config" "${1:-}" } cmd_status() { echo " Status: ready" _log "status" "${1:-}" } cmd_init() { echo " Initialized in $DATA_DIR" _log "init" "${1:-}" } cmd_list() { [ -f "$DB" ] && cat "$DB" || echo " (empty)" _log "list" "${1:-}" } cmd_add() { echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo " Added: $*" _log "add" "${1:-}" } cmd_remove() { echo " Removed: $1" _log "remove" "${1:-}" } cmd_search() { grep -i "$1" "$DB" 2>/dev/null || echo " Not found: $1" _log "search" "${1:-}" } cmd_export() { [ -f "$DB" ] && cat "$DB" || echo "No data" _log "export" "${1:-}" } cmd_info() { echo " Version: $VERSION | Data: $DATA_DIR" _log "info" "${1:-}" }Technical Analysis
The script creates a persistent directory under the user's data directory as soon as it starts. The
_logfunction appends the first argument supplied to most commands tohistory.log, whilecmd_addwrites every supplied argument todata.log.Neither the directory nor the files ...[truncated 1895 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
scripts/script.shif it is unused, because its generic persistent-storage behavior is unrelated to the documented name-generation interface. - If persistence is required, document every stored field, storage location, retention period, and deletion procedure in
SKILL.md. - Obtain explicit user consent before retaining command arguments.
- Do not log raw arguments. Record only non-sensitive operational metadata, or redact and minimize values before writing them.
- Set
umask 077before creating the data directory and files. - Create the directory with mode
0700and data files with mode0600, then verify that existing files are not more permissive. - Add commands that allow users to inspect and permanently delete stored history.
- Define a short retention period and automatically remove expired records.
- Avoid using arbitrary user-controlled storage locations without validating ownership, permissions, and symbolic-link behavior.
- Add automated tests confirming that sensitive arguments are not logged and that all persistent files receive restrictive permissions.
- Remove
