T09 · Insecure Skill Coding Practices
- Location
execution/logger.py:118- Finding
Plaintext Persistence of Sensitive Monitoring Metadata
- Content
View full analysis
Vulnerability Details
File Location:
execution/logger.py:118-129, with related URL collection atexecution/logger.py:148-165and alert persistence atexecution/detector.py:251-267, 353-370
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: MediumVulnerable Code
python def log(self, category: LogCategory, action: str, details: Dict) -> LogEntry: """Log an event.""" # Sanitize if needed sanitized_details = details if self.hash_sensitive: sanitized_details = SensitiveDataSanitizer.sanitize_dict(details) # Create entry entry = LogEntry( timestamp=datetime.now().isoformat(), category=category.value, action=action, details=sanitized_details, sanitized=self.hash_sensitive, hash=hashlib.sha256(json.dumps(details, sort_keys=True).encode()).hexdigest()[:16] ) # Write to file log_file = self._get_log_file(category) with open(log_file, "a") as f: f.write(json.dumps(asdict(entry)) + "\n")URL metadata is retained as follows:
python def log_api_call(self, method: str, url: str, status_code: Optional[int] = None, request_size: Optional[int] = None, response_size: Optional[int] = None) -> LogEntry: """Log an API call.""" from urllib.parse import urlparse parsed = urlparse(url) return self.log( LogCategory.API_CALL, method.upper(), { "url": SensitiveDataSanitizer.sanitize(url), "domain": parsed.netloc, "path": parsed.path, "status_code": status_code, "request_size": request_size, "response_size": response_size } )The detector can also copy a potentially sensitive URL into an alert:
python def detect_credential_exposure(self, api_events: List[Dict]) -> Opti ...[truncated 4925 chars]- Remediation
View remediation
Remediation Suggestions
- Parse URLs structurally and discard user information, query strings, and fragments before persistence. Retain only the scheme, validated hostname, method, status, and a normalized route template where necessary.
- Replace denylist-based regular expressions with an allowlist of fields and formats that are safe to log.
- Hash or tokenize sensitive file paths. Consider retaining only a basename, category, or keyed HMAC when correlation is required.
- Never copy a raw URL into an alert. Store a redacted hostname and route together with a nonreversible correlation identifier.
- Create
~/.agentguarddirectories with mode0700and telemetry files with mode0600. Validate permissions on existing paths before using them. - Use atomic file creation with restrictive permissions, followed by an atomic rename, to reduce race and partial-write risks.
- Apply the same retention and cleanup controls to compressed logs and alert records, not only uncompressed JSONL logs.
- Implement authenticated encryption before advertising encrypted storage. Keep encryption keys outside the telemetry directory and restrict their permissions.
- Add tests covering URL encoding, signed URLs, uncommon token formats, nested data structures, mixed-case fields, and secrets embedded in paths.
- Update the documentation to state precisely which metadata is retained and which protection mechanisms are actually implemented.
