T09 · Insecure Skill Coding Practices
- Location
scripts/quick-life-assessment.sh:107- Finding
Insecure Storage and Predictable File Creation for Sensitive Assessment Data
- Content
View full analysis
"life-assessment-$timestamp.md" << EOF # 生活评估报告 **评估时间**: $(date) ## 领域评分 - 健康: $health_avg/10 - 整体满意度: $health_score/10 - 睡眠质量: $sleep_score/10 - 运动频率: $exercise_freq 次/周 - 关系: $relationship_avg/10 - 亲密关系: $relationship_score/10 - 社交频率: $social_freq/10 - 家庭联系: $family_score/10 - 工作: $work_avg/10 - 投入度: $work_engagement/10 - 成长感: $career_growth/10 - 平衡度: $work_balance/10 ## 改进重点 最需要关注的领域: $lowest_domain ($lowest_score/10) ## 建议行动 $(case $lowest_domain in "健康") echo "1. 确保7-8小时睡眠\n2. 每周运动3-5次\n3. 均衡饮食,充足饮水" ;; "关系") echo "1. 安排定期社交活动\n2. 主动联系朋友家人\n3. 参加兴趣小组或社区" ;; "工作") echo "1. 设定明确工作边界\n2. 规划职业发展路径\n3. 平衡工作与个人时间" ;; esac) ## 后续步骤 1. 使用完整的生活轮模板进行详细评估 2. 设定具体改进目标 3. 每月重新评估进展 4. 调整策略以获得更好平衡 EOF ``` ### Technical Analysis The script unconditionally writes health, relationship, and work assessment data to the current working directory. It neither obtains explicit consent immediately before storage nor ensures that the selected directory is private. The output file inherits permissions from the caller's process-wide `umask`; on systems using a permissive default, other local users may be able to read the report. The filename is derived solely from a timestamp with one-second precision: ```bash life-assessment-YYYYMMDD_HHMMSS.md ``` The file is then opened using ordinary truncating shell redirection. This operation follows symbolic links and overwrites an existing target. If the script is run in a directory writable by another user, an attacker can predict candidate filenames and pre-create symbolic links pointing to files the victim is permitted to overwrite. The documentation recognizes that the assessment can contain sensitive healt ...[truncated 1464 chars]- Remediation
View remediation
