T09 · Insecure Skill Coding Practices
- Location
scripts/validate.py:128- Finding
Plaintext Exposure of Credit-Card Data Through Process Arguments and Console Output
- Content
View full analysis
None: """Try all validators.""" validators = [ ("Email", validate_email), ("Phone", validate_phone), ("URL", validate_url), ("IP", validate_ip), ("Credit Card", validate_credit_card), ("JSON", validate_json), ("UUID", validate_uuid), ("Hex", validate_hex), ] print(f"Testing '{value}' with all validators:") print("-" * 50) ``` The sensitive value is obtained directly from a command-line argument: ```python validator_type = sys.argv[1].lower() value = sys.argv[2] ``` ### Technical Analysis The tool supports credit-card validation even though this capability is not declared in `SKILL.md`. Credit-card numbers are supplied through command-line arguments and may therefore be exposed through shell history, process inspection facilities, terminal recordings, or execution telemetry. The `validate_all` function creates an additional disclosure by printing the complete supplied value without masking it: ```python print(f"Testing '{value}' with all validators:") ``` If the supplied value is a payment-card number, the full number is written to standard output. In CI systems, automation frameworks, agent transcripts, or applications that collect subprocess output, this value may be retained in logs or artifacts. The implementation does not redact, tokenize, or otherwise minimize sensitive data. ### Attack Path 1. A user or automated process invokes the tool with a card number, for example: ```bash python3 scripts/validate.py all 4532015112830366 ``` 2. The complete card number is placed in the process argument vector and may also be recorded in shell history. 3. A local user or monitoring process with sufficient process-observat ...[truncated 1205 chars]- Remediation
View remediation
str: digits = re.sub(r"[\s-]", "", value) return "*" * max(0, len(digits) - 4) + digits[-4:] ``` 5. Change `validate_all` so it identifies validators without reproducing the original input: ```python print("Testing supplied value with all validators:") ``` 6. Ensure verbose, JSON, error, and exception output paths apply the same redaction policy. 7. Configure CI and application logging to avoid retaining sensitive command arguments and subprocess output. 8. Add automated tests confirming that complete card numbers never appear in stdout, stderr, structured output, or exception messages. ]]>
