T09 · Insecure Skill Coding Practices
- Location
scripts/vision_wrapper.sh:2- Finding
Predictable Temporary File Used for Sensitive Desktop Screenshots
- Content
View full analysis
Vulnerability Details
File Location:
scripts/vision_wrapper.sh, lines 2–3
Vulnerability Type: Unsafe temporary-file handling
Risk Level: MediumComplete Code Snippet:
bash screencapture -x /tmp/claw_view.png echo "Screenshot captured at /tmp/claw_view.png"Technical Analysis
The script stores every desktop screenshot at the fixed, globally predictable path
/tmp/claw_view.png. Desktop images can contain credentials, private messages, personal information, or other sensitive material.The script does not create a private temporary directory, apply a restrictive
umask, verify that the destination is not a symbolic link or unexpected file type, or remove the image after consumption. Consequently, the screenshot can remain accessible after execution and may be exposed to other local users depending on the resulting file permissions. A local attacker can also prepare or monitor the known path and attempt file-replacement or symbolic-link manipulation, subject to macOS filesystem permissions and the destination-handling behavior ofscreencapture.Line 3 prints a success message without checking the exit status of
screencapture, which can also mislead callers when capture or file creation fails.Attack Path
- A local attacker learns the constant screenshot path from the publicly available script.
- The attacker monitors
/tmp/claw_view.pngor prepares the path before the skill runs. - An authorized user or agent invokes
vision_wrapper.shwhile sensitive information is visible. screencapturewrites the desktop image to the predictable location.- If local permissions allow it, the attacker reads or copies the image before it is replaced or manually deleted.
- Alternatively, the attacker attempts to manipulate the pre-existing destination, including through a symbolic link or replacement file. The success and consequences of this variant depend on filesystem permissions a ...[truncated 697 chars]
- Remediation
View remediation
Remediation Suggestions
- Set
umask 077before creating any screenshot so newly created files are accessible only to the invoking user. - Create a private temporary directory with
mktemp -dand store the screenshot under a randomized name inside it. - Register a
trapto delete the screenshot and temporary directory on normal exit, interruption, or failure. - Check the exit status of
screencaptureand print a success message only after successful capture. - Validate that the generated destination remains inside the newly created directory and is not an unexpected symbolic link or file type.
- Delete the screenshot immediately after the authorized consumer has processed it. If the wrapper cannot control consumption, return the randomized path and require the caller to perform cleanup.
- Consider avoiding persistent storage entirely by using a protected stream or other ephemeral transfer mechanism if supported.
Example hardened implementation:
bash #!/bin/bash set -euo pipefail umask 077 tmpdir="$(mktemp -d "${TMPDIR:-/tmp}/claw-view.XXXXXX")" screenshot="$tmpdir/view.png" trap 'rm -rf -- "$tmpdir"' EXIT HUP INT TERM if ! screencapture -x "$screenshot"; then echo "Screenshot capture failed" >&2 exit 1 fi echo "Screenshot captured at $screenshot" # Keep the process alive only as required for an authorized consumer, # or transfer/process the image here before the EXIT trap removes it.- Set
