T09 · Insecure Skill Coding Practices
- Location
native-host/host.js:21- Finding
Unauthenticated and Unbounded Local Unix Socket Interface
- Content
View full analysis
{ let buf = ''; socket.on('data', (data) => { buf += data.toString('utf8'); // Newline-delimited framing const nl = buf.indexOf('\n'); if (nl === -1) return; const line = buf.slice(0, nl).trim(); buf = buf.slice(nl + 1); let request; try { request = JSON.parse(line); } catch (_) { socket.write( JSON.stringify({ ok: false, error: { code: 'INVALID_REQUEST', message: 'Invalid JSON' } }) + '\n' ); socket.end(); return; } const id = ++requestIdCounter; pendingRequests.set(id, socket); // Forward to the Chrome extension sendToExtension({ ...request, _id: id }); }); // Disconnect after 60 seconds without a response socket.setTimeout(60000, () => socket.destroy()); socket.on('error', () => {}); }); socketServer.listen(SOCKET_PATH, () => { // Unix socket is ready for CLI connections }); socketServer.on('error', (err) => { process.stderr.write(`Socket server error: ${err.message}\n`); process.exit(1); }); } ``` ### Technical Analysis The Native Messaging host exposes a Unix socket at the fixed, predictable path `/tmp/today-earnings.sock`. The server does not explicitly create the socket inside a user-private runtime directory, set a restrictive socket mode, authenticate clients, or verify peer identity. Any local process that can access the socket may submit messages directly, bypa ...[truncated 2982 chars]- Remediation
View remediation
