T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:35- Finding
Undisclosed Plaintext Persistence of User-Provided Content
- Content
View full analysis
> "$DATA_DIR/history.log"; } ``` The destination is initialized as follows: ```bash DATA_DIR="${WECHAT_MINI_APP_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/wechat-mini-app}" DB="$DATA_DIR/data.log" mkdir -p "$DATA_DIR" ``` The `_log` function is called by commands that process user-provided content, including `write`, `title`, `outline`, `polish`, `hashtag`, `platform`, `hot`, `template`, `translate`, and `proofread`. ### Technical Analysis The script silently appends command names and user-provided arguments to the persistent file `$DATA_DIR/history.log`. The project documentation does not disclose this behavior, offer an opt-in mechanism, or provide retention and deletion controls. The script also relies on the process umask instead of explicitly applying restrictive permissions to the data directory and history file. Under a permissive umask or unusual preexisting directory configuration, other local users or processes could read the stored content. Inputs supplied to writing, translation, polishing, or proofreading commands may contain confidential drafts, business information, personal data, or other sensitive material. Persisting raw input in plaintext creates unnecessary local data exposure. This does not grant elevated privileges and does not transmit data to a remote service. The affected scope is the confidentiality and retention of content supplied by users who execute the script. ### Attack Path 1. A user invokes a supported command and supplies potentially sensitive content as an argument. 2. The selected command passes part of that content to `_log`. 3. `_log` appends the command name and co ...[truncated 937 chars]- Remediation
View remediation
