T09 · Insecure Skill Coding Practices
- Location
references/implementation.md:258- Finding
Local Cache Stores Potentially Sensitive Data Without Enforced Restrictive Permissions
- Content
View full analysis
Vulnerability Details
File Location:
references/implementation.md, lines 258–259 and 301–302
Vulnerability Type: Insecure local storage and filesystem permissions
Risk Level: MediumVulnerable code:
python CACHE_DIR = Path.home() / ".claude_cache" CACHE_DIR.mkdir(exist_ok=True)python with open(cache_file, "w") as f: json.dump(result, f)Technical Analysis
The implementation creates a cache directory and writes API responses without explicitly enforcing restrictive permissions. The resulting permissions depend on the process umask. Under common defaults, the directory may be created as
0755and files as0644, potentially permitting other local users to traverse the directory and read cached content.This is security-sensitive because the Skill explicitly warns that its cache can contain source code, prompts, API responses, credentials, personally identifiable information, or other confidential material. Although the documentation advises users to run
chmod 600 ~/.claude_cache/, the implementation does not enforce that protection.Moreover, mode
0600is inappropriate for a directory because directories require the execute bit for traversal. The correct baseline is0700for the cache directory and0600for cache files.Attack Path
- A user adopts the documented local-caching implementation on a shared or multi-user system.
- The process creates
~/.claude_cacheusing permissions derived from a permissive umask. - Claude API responses influenced by confidential prompts or source code are written to cache files without an explicit
0600mode. - Another local account enumerates or directly accesses the cache directory.
- The local attacker reads cached responses and recovers confidential information contained in them.
Exploitation requires local filesystem access through another account or process and permissions that allow traversal or reading; t ...[truncated 482 chars]
- Remediation
View remediation
Remediation Suggestions
Enforce secure permissions in code rather than relying on documentation or the caller's umask:
python CACHE_DIR.mkdir(mode=0o700, exist_ok=True) os.chmod(CACHE_DIR, 0o700) fd = os.open( cache_file, os.O_WRONLY | os.O_CREAT | os.O_TRUNC, 0o600, ) with os.fdopen(fd, "w") as f: json.dump(result, f)Additional hardening measures:
- Use
0700for cache directories and0600for files. - Correct the documentation so it does not recommend
chmod 600for a directory. - Reject symbolic links and verify that the cache path remains under the expected directory.
- Write through a securely created temporary file and atomically rename it to avoid partial files and race conditions.
- Apply restrictive permissions to existing directories and files, not only newly created ones.
- Do not cache credentials, secrets, personal data, or regulated information.
- Use a short retention period and securely remove expired cache entries.
- Prefer encrypted or ephemeral storage in shared, CI, and hosted environments.
- Use
