T09 · Insecure Skill Coding Practices
- Location
scripts/password_manager.py:78- Finding
Credentials and backups are stored in plaintext
- Content
View full analysis
bool: """保存数据文件""" try: self.data["last_updated"] = datetime.now().isoformat() # 自动备份 if self.data.get("settings", {}).get("auto_backup", True): self._create_backup() with open(self.data_path, 'w', encoding='utf-8') as f: json.dump(self.data, f, indent=2, ensure_ascii=False) return True except Exception as e: print(f"保存数据文件失败: {e}") return False def _create_backup(self) -> bool: """创建备份文件""" try: timestamp = datetime.now().strftime("%Y%m%d_%H%M%S") backup_path = self.backup_dir / f"passwords_backup_{timestamp}.json" with open(backup_path, 'w', encoding='utf-8') as f: json.dump(self.data, f, indent=2, ensure_ascii=False) return True ``` The password is inserted directly into the persisted record: ```python password_entry = { "id": str(uuid.uuid4()), "name": name, "username": username, "password": password, "category": category, "notes": notes, "created_at": datetime.now().isoformat(), "updated_at": datetime.now().isoformat(), "strength": strength } ``` ### Technical Analysis The manager places the original password directly into an in-memory dictionary and serializes the entire dictionary to JSON without encryption. Every modification can also create another plaintext copy in the backup directory. No authenticated encryption, master-password-based key derivation, operating-system keyring integration, or explicit restrictive file permissions are applied. Consequently, confidentiality depends entirely on external filesystem protections. The documentation is also inconsistent: `SKILL.md:379` describes the pa ...[truncated 1420 chars]- Remediation
View remediation
