T09 · Insecure Skill Coding Practices
- Location
assets/templates/sign-and-notarize.sh:16- Finding
App Store Connect Private Key Written to a Predictable Shared Temporary File
- Content
View full analysis
/tmp/app-store-connect-key.p8 trap 'rm -f /tmp/app-store-connect-key.p8 /tmp/${APP_NAME}Notarize.zip' EXIT ``` The resulting file is subsequently used here: ```bash xcrun notarytool submit "/tmp/${APP_NAME}Notarize.zip" \ --key /tmp/app-store-connect-key.p8 \ --key-id "$APP_STORE_CONNECT_KEY_ID" \ --issuer "$APP_STORE_CONNECT_ISSUER_ID" \ --wait ``` ### Technical Analysis The script writes an App Store Connect API private key to the fixed path `/tmp/app-store-connect-key.p8`. Because ordinary shell redirection creates or truncates the destination while following symbolic links, an existing attacker-controlled path can redirect the secret into another user-writable file. A process able to observe the shared temporary directory may also attempt to read the key while it exists. The file permissions depend on the invoking process's `umask`; the script does not explicitly enforce owner-only permissions. Deleting the file through an EXIT trap limits how long it remains present but does not protect it during script execution or prevent symlink attacks before creation. ### Attack Path 1. An attacker with local access predicts the fixed `/tmp/app-store-connect-key.p8` pathname. 2. The attacker monitors the path or prepares it as a symbolic link to an attacker-readable or victim-owned destination. 3. A release operator runs `sign-and-notarize.sh` with a valid App Store Connect private key in the environment. 4. Shell redirection writes the private key through the predictable path. 5. The attacker reads the exposed credential or causes an unintended file to be overwritten. 6. Cleanup occurs only after the credential has already been exposed or the ...[truncated 528 chars]- Remediation
View remediation
