T09 · Insecure Skill Coding Practices
- Location
scripts/daily_master.sh:13- Finding
Predictable Temporary Log Files May Disclose Sensitive Command Context or Follow Malicious Symlinks
- Content
View full analysis
> /tmp/daily_reflect.log 2>&1 # 2. 自动提醒检查 echo "[$(date '+%Y-%m-%d %H:%M:%S')] 2/3 运行自动提醒检查..." $PYTHON3 "$SKILL_DIR/auto_remind.py" --check >> /tmp/auto_remind.log 2>&1 # 3. 重复模式检测 echo "[$(date '+%Y-%m-%d %H:%M:%S')] 3/3 运行重复模式检测..." $PYTHON3 "$SKILL_DIR/repeat_detect.py" >> /tmp/repeat_detect.log 2>&1 ``` From `scripts/daily_reflect.py:68-71`: ```xml StandardOutPath /tmp/daily_reflect.log StandardErrorPath /tmp/daily_reflect.err ``` ### Technical Analysis The scripts write operational output to fixed, predictable paths in the shared `/tmp` directory. They do not securely create these files, verify ownership, reject symbolic links, or explicitly enforce restrictive ...[truncated 2702 chars]- Remediation
View remediation
