T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:5- Finding
Undocumented Persistent Plaintext Logging of Command Arguments
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh, lines 5–7, 35, and 78–89
Vulnerability Type: Undocumented persistent storage of potentially sensitive command arguments
Risk Level: LowVulnerable Code
bash DATA_DIR="${OFFICIAL_DOC_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/official-doc}" DB="$DATA_DIR/data.log" mkdir -p "$DATA_DIR"bash _log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }bash case "${1:-help}" in init) shift; cmd_init "$@" ;; check) shift; cmd_check "$@" ;; build) shift; cmd_build "$@" ;; test) shift; cmd_test "$@" ;; deploy) shift; cmd_deploy "$@" ;; config) shift; cmd_config "$@" ;; status) shift; cmd_status "$@" ;; template) shift; cmd_template "$@" ;; docs) shift; cmd_docs "$@" ;; clean) shift; cmd_clean "$@" ;;Technical Analysis
The script creates a persistent directory under the invoking user's data directory as soon as it runs. Most supported commands then call
_log, which appends the command name and its first argument tohistory.login plaintext.This behavior is not documented in
SKILL.mdand is unrelated to the advertised official-document generation functionality. If a user supplies confidential project names, document subjects, internal identifiers, tokens, or other sensitive values as the first command argument, that value can remain on disk after execution.The directory and log file are created using permissions determined by the process umask. The script does not explicitly enforce restrictive permissions. On a system with a permissive umask or shared access to the selected
OFFICIAL_DOC_DIR, another local account or process could read the retained arguments.No evidence indicates that the log is transmitted over a network, executed as code, or used to obtain elevated privileges.
Attack Path
- A user or automated agent invokes t ...[truncated 1312 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove
scripts/script.shif it is unrelated to the skill's documented official-document functionality. -
If the script is intentionally distributed, document its purpose, filesystem modifications, retention behavior, and log location in
SKILL.md. -
Disable command-history logging by default and require explicit user opt-in.
-
Do not log raw command arguments. Record only fixed command identifiers, or redact values that may contain confidential data.
-
Create the storage directory and log with restrictive permissions:
bash umask 077 mkdir -p -- "$DATA_DIR" touch -- "$DATA_DIR/history.log" chmod 700 -- "$DATA_DIR" chmod 600 -- "$DATA_DIR/history.log" -
Validate
OFFICIAL_DOC_DIRbefore use and reject unsafe or unintended shared locations. -
Add configurable retention limits and a documented command for securely deleting stored history.
-
Remove the unused
DBvariable to reduce ambiguity about the script's persistent storage behavior.
-
