T09 · Insecure Skill Coding Practices
- Location
scripts/auto-sync-icloud.sh:31- Finding
Blanket Git Staging Can Synchronize Undeclared Sensitive Files
- Content
View full analysis
/dev/null 2>&1 # 2. Commit local changes (skip if nothing staged) git add -A if ! git diff --cached --quiet 2>/dev/null; then git commit -m "auto-sync ${TS} from $(hostname)" >/dev/null 2>&1 fi # 3. Push git push "$REMOTE" "$BRANCH" >/dev/null 2>&1 ``` ### Technical Analysis The recurring synchronization process uses `git add -A`, which stages every unignored file under `~/.workbuddy`. The provided `.gitignore` excludes several known credential and runtime locations, but it is a denylist and does not protect arbitrary sensitive files, newly introduced WorkBuddy paths, private keys, environment files, token exports, or backups that do not match an existing rule. This behavior is broader than the Skill's documented synchronization scope, which identifies a limited set of identity, memory, configuration, and skill files. Any unignored content is automatically committed and copied to the iCloud bare repository. ### Attack Path 1. A user, plugin, tool, or future WorkBuddy version creates a sensitive file under `~/.workbuddy`. 2. The path is not covered by `references/gitignore-template`. 3. The background daemon invokes `auto-sync-icloud.sh`. 4. `git add -A` stages the sensitive file. 5. The script commits it without user review. 6. `git push` copies it into the iCloud Drive bare repository. 7. iCloud and Git propagate the file to other Macs connected to the repository. ### Impact Assessment The issue does not grant elevated system privileges, but it can disclose data accessible to the current user. Exposure is scoped to the user's iCloud account, the bare repository, and every Mac configured to consume that repository. Depending on the ...[truncated 132 chars]- Remediation
View remediation
