T09 · Insecure Skill Coding Practices
- Location
scripts/context-engine.js:42- Finding
Persistent Sensitive Context Is Stored Without Explicit Restrictive File Permissions
- Content
View full analysis
Vulnerability Details
File Location:
scripts/context-engine.js, lines 9-18, 42-45, 75-77, and 158-162
Vulnerability Type: Plaintext sensitive-data storage with permissions dependent on the process umask
Risk Level: MediumVulnerable Code
js const PROJECTS_DIR = '/home/deus/.openclaw/workspace/memory/projects'; const PROJECTS_FILE = path.join(PROJECTS_DIR, 'projects.json'); const SESSION_FILE = path.join(PROJECTS_DIR, 'session.json'); // Ensure directory exists function ensureDir() { if (!fs.existsSync(PROJECTS_DIR)) { fs.mkdirSync(PROJECTS_DIR, { recursive: true }); } }js // Save projects function saveProjects(data) { data.lastUpdated = now(); fs.writeFileSync(PROJECTS_FILE, JSON.stringify(data, null, 2)); }js // Save session function saveSession(data) { fs.writeFileSync(SESSION_FILE, JSON.stringify(data, null, 2)); }js // Update context if (contextData.lastTopic) project.context.lastTopic = contextData.lastTopic; if (contextData.lastFile) project.context.lastFile = contextData.lastFile; if (contextData.lastCommand) project.context.lastCommand = contextData.lastCommand; if (contextData.pendingTasks) project.context.pendingTasks = contextData.pendingTasks; if (contextData.notes) project.context.notes = contextData.notes;Technical Analysis
The Skill persistently records conversation and project context, including command history, file paths, topics, tasks, and notes. This information is serialized as plaintext JSON in a fixed directory.
Neither
fs.mkdirSyncnorfs.writeFileSyncspecifies a restrictive permission mode. Consequently, permissions are determined by the runtime environment's umask or by the permissions of pre-existing files. Under a permissive configuration, other local users or processes may be able to read the stored context.The write operations also overwrite existing paths without expl ...[truncated 1693 chars]
- Remediation
View remediation
Remediation Suggestions
-
Create the storage directory with owner-only permissions:
js fs.mkdirSync(PROJECTS_DIR, { recursive: true, mode: 0o700 }); -
Create and write persistent state files with mode
0600:js fs.writeFileSync( PROJECTS_FILE, JSON.stringify(data, null, 2), { encoding: 'utf8', mode: 0o600 } );Apply the same protection to
SESSION_FILE, initial file creation, and backup files. -
Enforce permissions on existing paths with
fs.chmodSync, because specifyingmodedoes not necessarily correct permissions on files that already exist. -
Before writing, inspect paths with
lstatand reject symbolic links, non-regular files, or files not owned by the expected user. -
Redact likely credentials and tokens before persisting
lastCommand,notes,lastTopic, or task content. Avoid storing complete command lines when a minimal summary is sufficient. -
Document what data is retained, how long it is retained, and how users can securely clear project and session history.
-
Where stored context is expected to contain credentials or highly confidential information, use encryption at rest with keys protected separately from the JSON data.
-
