T09 · Insecure Skill Coding Practices
- Location
scripts/prepare-session.jxa:10- Finding
Local Session Artifacts Are Created Without Restrictive Permissions
- Content
View full analysis
Vulnerability Details
File Location:
scripts/prepare-session.jxa:10-20
Related Locations:scripts/collect-system.sh:6-7,scripts/helpers/safe-command.sh:12-15, 22-24,scripts/build-session.jxa:51-56
Vulnerability Type: Insecure permissions on locally retained sensitive data
Risk Level: MediumVulnerable Code
scripts/prepare-session.jxa:10-20:javascript var fm = $.NSFileManager.defaultManager; var root = $(argv[0]).stringByStandardizingPath.js; var locale = argv[1] || 'zh-CN'; if (locale !== 'zh-CN' && locale !== 'en-US') fail('unsupported locale: ' + locale); fm.createDirectoryAtPathWithIntermediateDirectoriesAttributesError(root, true, $(), null); var now = new Date(); function pad(n) { return String(n).padStart(2, '0'); } var stamp = now.getFullYear() + pad(now.getMonth() + 1) + pad(now.getDate()) + '-' + pad(now.getHours()) + pad(now.getMinutes()) + pad(now.getSeconds()); var suffix = Math.random().toString(16).slice(2, 6).toUpperCase().padEnd(4, '0'); var id = stamp + '-' + suffix; var dir = root + '/' + id; fm.createDirectoryAtPathWithIntermediateDirectoriesAttributesError(dir + '/raw', true, $(), null);scripts/helpers/safe-command.sh:12-15, 22-24:sh /bin/mkdir -p "$output_dir" stdout_file="$output_dir/${probe_id}.out" stderr_file="$output_dir/${probe_id}.err" meta_file="$output_dir/${probe_id}.meta.json"sh "$@" > "$stdout_file" 2> "$stderr_file" &scripts/build-session.jxa:51-56:javascript write(dir+'/session.json',JSON.stringify(session,null,2)+'\n'); var strings=json(root+'/assets/i18n/'+session.locale+'.json'),layoutName=caps.keyboardLayout&&layouts[caps.keyboardLayout]?caps.keyboardLayout:'ANSI'; var payload={session:session,facts:{device:facts.device,battery:facts.battery,security:facts.security,storage:facts.storage,network:facts.network,peripherals:facts.peripherals},system:results,capabilities:caps,checks ...[truncated 3139 chars]- Remediation
View remediation
Remediation Suggestions
-
Set a restrictive
umaskbefore any output is created:sh umask 077Place this near the beginning of
scripts/run-full-check.shand defense-in-depth wrappers that can be invoked independently. -
Explicitly create the output root, session directory, and raw-data directory with owner-only access equivalent to
0700. -
Create all raw output, metadata, JSON, HTML, and report files with owner-only permissions equivalent to
0600. Do not rely exclusively on the caller's environment. -
Verify after creation that the output path is owned by the current user, is not a symbolic link, and is not unexpectedly group- or world-writable.
-
Reject unsafe shared output roots unless the user explicitly acknowledges the risk. Where practical, use a private per-user application-support directory by default.
-
Document which artifacts contain the full serial number, how long they remain on disk, and how users can securely remove them.
-
Provide an explicit cleanup command or option that safely removes only the generated session directory after the user has exported any desired report.
-
Consider masking the serial number by default in HTML and exported reports, with an explicit opt-in for including the complete value.
-
