T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:5- Finding
Undisclosed Persistent Plaintext Logging of User-Supplied Arguments
- Content
View full analysis
> "$DATA_DIR/history.log"; } cmd_query() { echo " Query: $*" _log "query" "${1:-}" } cmd_import() { echo " Importing: $1" _log "import" "${1:-}" } cmd_export() { echo " Exporting to: ${1:-stdout}" _log "export" "${1:-}" } cmd_transform() { echo " Transforming: $1 -> $2" _log "transform" "${1:-}" } cmd_validate() { echo " Validating schema..." _log "validate" "${1:-}" } cmd_stats() { echo " Records: $(wc -l < "$DB" 2>/dev/null || echo 0)" _log "stats" "${1:-}" } cmd_schema() { echo " Fields: id, name, value, timestamp" _log "schema" "${1:-}" } cmd_sample() { [ -f "$DB" ] && head -5 "$DB" || echo "No data" _log "sample" "${1:-}" } cmd_clean() { echo " Cleaning data..." _log "clean" "${1:-}" } cmd_dashboard() { echo " Total: $(wc -l < "$DB" 2>/dev/null || echo 0) records" _log "dashboard" "${1:-}" } ``` ### Technical Analysis The script creates a persistent data directory and appends the first argument supplied to multiple commands to `history.log` in plaintext. This logging is automatic, is not disclosed in `SKILL.md`, and is unrelated to the declared slogan-generation functionality. Arguments passed to commands such as `query`, `import`, `export`, and `transform` may contain confidential search terms, campaign content, customer information, internal file paths, or other sensitive data. The log has no redaction, encryption, retention limit, consent mechanism, or explicit restrictive permission setup. The directory and file permissions dep ...[truncated 2075 chars]- Remediation
View remediation
