T09 · Insecure Skill Coding Practices
- Location
scripts/clipboard.py:53- Finding
Sensitive Clipboard Content Exposed in Standard Output
- Content
View full analysis
Vulnerability Details
File Location:
scripts/clipboard.py, line 53
Vulnerability Type: Sensitive data exposure through application output
Risk Level: MediumVulnerable Code
python print(f"Copied to clipboard: {text[:50]}{'...' if len(text) > 50 else ''}")Technical Analysis
Every successful copy operation prints the first 50 characters of the copied value to standard output. The value may originate from the
--copyargument or from a file supplied through--file.Clipboard data commonly contains passwords, access tokens, private keys, personal information, and other secrets. Although the disclosure is limited to 50 characters, that may expose an entire credential or enough sensitive material to compromise it. Standard output may be retained in terminal scrollback, shell-session recordings, CI logs, automation logs, or AI-agent transcripts. This can preserve sensitive content after the clipboard itself has been overwritten or cleared.
Attack Path
- A user invokes the tool with sensitive content, for example through
--copyor--file. - The tool successfully sends that content to the platform clipboard utility.
- Line 53 prints up to the first 50 characters of the content to standard output.
- A local observer, log collector, CI operator, session-recording system, or party with access to an agent transcript obtains the disclosed content.
- If the preview contains a complete password, token, or other credential, it can be reused against the corresponding resource.
Impact Assessment
The issue does not directly grant additional operating-system privileges. Its scope is the first 50 characters of each value copied with the tool. Depending on the exposed data, the secondary impact could include unauthorized access to accounts, APIs, repositories, or other resources available to the disclosed credential. Exposure persists wherever standard output is logged or recorded.
- A user invokes the tool with sensitive content, for example through
- Remediation
View remediation
Remediation Suggestions
Replace the content-bearing message with a content-free confirmation:
python print("Copied to clipboard")If previews are considered necessary, require an explicit opt-in flag, disable previews by default, clearly warn users that content may be logged, and direct diagnostic output only to an appropriately protected destination. Avoid logging clipboard data or file contents at any verbosity level intended for routine use. Add tests verifying that copied values—including representative secrets—never appear in standard output or standard error.
