T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:5- Finding
Environment-Controlled Persistent File Writes Follow Symbolic Links
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh, lines 5–7, 35, and 62–64
Vulnerability Type: Unrestricted storage path and unsafe symbolic-link-following file writes
Risk Level: MediumVulnerable Code
bash DATA_DIR="${PITCH_DECK_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/pitch-deck}" DB="$DATA_DIR/data.log" mkdir -p "$DATA_DIR"bash _log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }bash cmd_add() { echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo " Added: $*" _log "add" "${1:-}" }Technical Analysis
The
PITCH_DECK_DIRenvironment variable completely controls the directory in which the script creates or appends to persistent files. The path is not canonicalized, restricted to an expected user-data directory, or checked for ownership and safe permissions.The shell redirections used for
history.loganddata.logfollow symbolic links. The script does not verify that either destination is a regular file, reject pre-existing symbolic links, or use a file-opening mechanism that prevents link traversal. It also does not set a restrictiveumask, so the confidentiality of newly created files depends on the caller's environment.Most commands invoke
_log, including commands that appear read-only, causing command arguments to be retained persistently. Theaddcommand stores all supplied arguments in plaintext indata.log. If users provide confidential business information, that information may consequently be exposed to other accounts where default file permissions are permissive.Exploitation requires the attacker to control
PITCH_DECK_DIRor be able to prepare files in the selected data directory. File-system permissions still apply: the script cannot append to a destination that the invoking account is not permitted to write.Attack Path
- An attacker influences the process environment and sets `PITCH_DECK_DI ...[truncated 1444 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not permit an unrestricted environment variable to select arbitrary write destinations. If configurability is necessary, canonicalize the requested path and verify that it remains beneath an approved per-user data root.
- Create the data directory with restrictive permissions:
bash umask 077 install -d -m 700 -- "$DATA_DIR" - Verify that the directory is owned by the invoking user and is not writable by untrusted users.
- Reject symbolic links and non-regular destination files before writing. Prefer a small helper implemented with secure file-opening flags such as
O_NOFOLLOW,O_APPEND, andO_CREAT, followed by ownership and file-type validation. - Create data and history files with mode
0600, and validate existing files before every append. - Avoid logging command arguments unless they are operationally required. Redact potentially sensitive values and document the retention behavior.
- Do not perform persistent writes for read-only commands unless explicit audit logging is a documented feature.
- Remove
scripts/script.shif this generic persistence utility is unrelated to the pitch-deck generator's intended functionality. - Ensure the script is never run with elevated privileges unless strictly required.
