T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:5- Finding
Undocumented Plaintext Persistence of Potentially Sensitive Personnel Data
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh:5-7,scripts/script.sh:35, andscripts/script.sh:57-59
Vulnerability Type: Plaintext storage and logging of potentially sensitive data
Risk Level: MediumVulnerable Code
bash DATA_DIR="${PERFORMANCE_REVIEW_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/performance-review}" DB="$DATA_DIR/data.log" mkdir -p "$DATA_DIR"bash _log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }bash cmd_add() { echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo " Added: $*" _log "add" "${1:-}" }Technical Analysis
The secondary utility creates a persistent data directory and writes user-controlled command arguments to
data.logandhistory.logwithout explicitly establishing restrictive permissions. The resulting permissions depend on the invoking user's umask and any pre-existing filesystem objects.Because this project handles performance reviews, promotion assessments, KPIs, and employee feedback, supplied arguments may contain confidential personnel information. Storing that content in plaintext creates an unnecessary local disclosure risk. Storage, retention, and history logging are also not disclosed by the documented
SKILL.mdinterface, which describes a report generator that prints output locally.The history log duplicates part of the submitted content, increasing the number of locations from which sensitive information must be removed. Retention is unbounded, and the implementation provides no verified data-lifecycle controls.
The related removal implementation at
scripts/script.sh:61-64also does not delete stored data:bash cmd_remove() { echo " Removed: $1" _log "remove" "${1:-}" }It reports that an item was removed while only adding another history entry. Users may therefore incorrectly believe that sensitive information has been erased.
Attack Path
- A user or automated agent invokes `scripts/script.sh a ...[truncated 1193 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
scripts/script.shif it is unused or unrelated to the documented performance-review functionality. - Clearly document all persistent storage, history logging, retention, export, and deletion behavior.
- Require explicit user consent before storing performance-review or personnel information.
- Create the storage directory and files with restrictive permissions:
bash umask 077 install -d -m 0700 -- "$DATA_DIR" touch "$DB" "$DATA_DIR/history.log" chmod 0600 "$DB" "$DATA_DIR/history.log"- Avoid recording command arguments or review content in
history.log. Log only non-sensitive operational events where necessary. - Implement actual, verified record deletion in
cmd_remove; only print a success message after confirming that the intended record was removed. - Add configurable retention limits and a command that securely clears both the primary database and associated history records.
- Validate the configured storage location and reject unsafe paths or unexpected pre-existing filesystem objects where appropriate.
- Consider encryption at rest if retaining confidential personnel data is a required feature, while protecting encryption keys separately from the stored records.
- Remove
