T09 · Insecure Skill Coding Practices
- Location
scripts/agent-loop-runner.ps1:144- Finding
Unsanitized Command and Process Output Persisted in Project State
- Content
View full analysis
Vulnerability Details
File Location:
scripts/agent-loop-runner.ps1:144-147, 178-191, 199-209
Vulnerability Type: Plaintext persistence of potentially sensitive command data
Risk Level: MediumVulnerable Code
powershell $runnerLog = if ([string]::IsNullOrWhiteSpace($RunnerLogPath)) { Join-Path $workspace "Docs\RUNNER_LOG.jsonl" } else { $RunnerLogPath }powershell $checkEvent = @{ timestamp = (Get-Date).ToString("o") event = "runner_check" loop = $loopIndex workspace = $workspace checker_status = $status checker_exit_code = $checkerResult.ExitCode strict_mode = $strictMode checker_warnings = $checkerWarnings checker_issues = $checkerIssues checker_raw = $checkerResult.Raw } Write-RunnerLog -RunnerLogPath $runnerLog -Record $checkEventpowershell $loopEvent = @{ timestamp = (Get-Date).ToString("o") event = "runner_loop_command" loop = $loopIndex workspace = $workspace command = $loopRun.Command exit_code = [int]$loopRun.ExitCode started_at = $loopRun.StartedAt finished_at = $loopRun.FinishedAt duration_ms = [int]$loopRun.DurationMs output = if ([string]::IsNullOrWhiteSpace($loopRun.Raw)) { "<empty>" } else { $loopRun.Raw.Substring(0, [Math]::Min(1000, $loopRun.Raw.Length)) } } Write-RunnerLog -RunnerLogPath $runnerLog -Record $loopEventTechnical Analysis
The runner records the complete caller-provided loop command, raw checker output, the absolute workspace path, and up to 1,000 characters of combined process standard output and standard error. No redaction or sensitivity filtering is performed before these fields are serialized as JSONL.
By default, the log is written to
Docs/RUNNER_LOG.jsonl. BecauseDocs/is the Skill's durable project-state directory, its contents may be committed, archived, included in handoffs, or uploaded by CI. This behavior contradicts the repository's stated requirements to retain only sanitized command summaries and to reda ...[truncated 1731 chars]- Remediation
View remediation
Remediation Suggestions
- Change the default log destination from
Docs/RUNNER_LOG.jsonlto a non-versioned location such as.agent/logs/RUNNER_LOG.jsonl. - Add
.agent/logs/and any runner log file to the recommended.gitignoreconfiguration. - Do not persist the complete loop command. Record only an allowlisted executable name or a stable command identifier, and omit arguments by default.
- Redact output before serialization. Cover common token formats, authorization headers, passwords, cookies, private URLs, connection strings, email addresses, customer identifiers, and machine-specific paths.
- Make raw command and output logging explicitly opt-in, with a warning that the data may be sensitive.
- Prefer structured summaries containing the exit code, duration, verification category, and sanitized error classification rather than arbitrary process output.
- Apply restrictive filesystem permissions when creating the log.
- Add automated tests that inject representative secrets into commands, stdout, stderr, and checker output and verify that none appear in persisted logs.
- Document a retention policy and provide a safe mechanism for deleting or rotating old runner logs after explicit user approval.
- Change the default log destination from
