T09 · Insecure Skill Coding Practices
- Location
scripts/run-task.py:30- Finding
Android PIN May Be Exposed Through ADB Error Messages and Process Arguments
- Content
View full analysis
str: """Run an ADB command and return stdout.""" cmd = ["adb"] if serial: cmd += ["-s", serial] cmd += list(args) result = subprocess.run(cmd, capture_output=True, text=True, timeout=30) if check and result.returncode != 0: raise RuntimeError(f"adb {' '.join(args)} failed: {result.stderr.strip()}") return result.stdout.strip() ``` ```python pin = os.environ.get("ANDROID_PIN") if not pin: print("🔒 Phone is locked but ANDROID_PIN not set — skipping unlock") print(" Set ANDROID_PIN environment variable or unlock manually") return print("🔑 Unlocking phone...") # Swipe up to reveal PIN pad adb(serial, "shell", "input", "swipe", "540", "1800", "540", "800", "300") time.sleep(1) # Type the PIN — works on most devices adb(serial, "shell", "input", "text", pin) ``` ```python except Exception as e: print() print("=" * 60) print(f"❌ Task failed: {e}") print("=" * 60) if args.verbose: import traceback traceback.print_exc() sys.exit(1) ``` ### Technical Analysis The phone PIN is passed directly to ADB as a command-line argument: ```text adb -s shell input text ``` Command-line arguments may be visible to other local processes through process-inspection facilities while the command is running. More importantly, the shared `adb()` helper constructs an exception containing all ADB arguments when the command fails. Because the PIN is one of those arguments, an unlock failure can produce an exception containing the plaintext PIN. The top-level exception handler prints that exception. If output is collected ...[truncated 1799 chars]- Remediation
View remediation
str: cmd = ["adb"] if serial: cmd += ["-s", serial] cmd += list(args) result = subprocess.run(cmd, capture_output=True, text=True, timeout=30) if check and result.returncode != 0: operation = "" if sensitive else " ".join(args) raise RuntimeError( f"ADB operation failed: {operation}; " f"error={result.stderr.strip()}" ) return result.stdout.strip() ``` The PIN-entry call should then set `sensitive=True`, while the top-level handler should continue to print only sanitized exceptions. ]]>
