T09 · Insecure Skill Coding Practices
- Location
SKILL.md:13- Finding
Raw Tool Parameters and Results Are Logged Without Effective Redaction
- Content
View full analysis
{ const entry = { ts: new Date().toISOString(), event: "before_tool_call", tool: event.tool.name, params: JSON.stringify(event.tool.params).slice(0, 500), session: ctx.sessionKey, user: ctx.session?.senderId || 'unknown' }; console.log("[AUDIT]", JSON.stringify(entry)); return {}; }); api.registerHook("after_tool_call", async ({ event, ctx }) => { const entry = { ts: new Date().toISOString(), event: "after_tool_call", tool: event.tool.name, result: String(event.result).slice(0, 200), error: event.error?.message || null, duration: event.durationMs, session: ctx.sessionKey }; console.log("[AUDIT]", JSON.stringify(entry)); return {}; }); ``` The documented redaction function is: ```javascript function redactSensitive(obj) { const sensitive = ['apiKey', 'token', 'password', 'secret']; for (const key of Object.keys(obj)) { if (sensitive.some(s => key.toLowerCase().includes(s))) { obj[key] = '[REDACTED]'; } } return obj; } ``` ### Technical Analysis The hooks serialize raw tool parameters and results directly into console output. Tool calls can contain API tokens, passwords, authorization headers, private messages, command-line credentials, file contents, personal identifiers, or other sensitive data. The use of `.slice(0, 500)` and `.slice(0, 200)` only truncates the recorded values; it does not sanitize them. Any secret appearing within those prefixes remains exposed. Although a redaction function is documented, it is never invoked before the audit entries are logged. The fun ...[truncated 2495 chars]- Remediation
View remediation
