T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:30- Finding
Persistent Plaintext Logging of User-Supplied Arguments
- Content
View full analysis
> "$DATA_DIR/history.log"; } ``` Representative command handlers pass user-controlled arguments directly to the logging function: ```bash cmd_run() { echo " Running: $1" _log "run" "${1:-}" } ``` ```bash cmd_add() { echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo " Added: $*" _log "add" "${1:-}" } ``` ```bash cmd_search() { grep -i "$1" "$DB" 2>/dev/null || echo " Not found: $1" _log "search" "${1:-}" } ``` ### Technical Analysis The `_log` function writes the first argument supplied to command handlers into the persistent file `$DATA_DIR/history.log`. The log is created using the process's current `umask`; the script does not explicitly enforce restrictive permissions on either the data directory or its files. Arguments supplied to `run`, `add`, `search`, and other commands may contain private test data, internal identifiers, URLs, search terms, or accidentally pasted secrets. Those values are retained in plaintext after command completion. The `add` command additionally writes the complete argument list to `data.log`. This is a local data-exposure weakness rather than remote code execution. No shell evaluation or command-substitution sink was found in the affected logging operation. ### Attack Path 1. A user invokes the utility with sensitive content, for example: ```bash test-generator add "API test token: sensitive-value" ``` 2. The complete entry is appended to `data.log`. 3. The first user-supplied argument is also appended to `history.log`. 4. The values remain stored after the command terminates. 5. ...[truncated 630 chars]- Remediation
View remediation
