T09 · Insecure Skill Coding Practices
- Location
hooks/observe.sh:95- Finding
Persistent Plaintext Storage of Unfiltered Tool Inputs and Outputs
- Content
View full analysis
> "$obs_file" } ``` ### Technical Analysis The observation hook accepts complete tool input and output values and stores them in persistent JSONL files without redaction. The documented configuration registers this hook for all `PreToolUse` and `PostToolUse` events, so captured values can include source code, command output, private URLs, API tokens, credentials printed during debugging, user-supplied confidential data, and environment details. The files are created according to the process umask rather than with explicit restrictive permissions. No field-level filtering, maximum record size, retention limit based on age, secret detection, or tool allowlist is applied. When the observation file grows, the im ...[truncated 1668 chars]- Remediation
View remediation
