T09 · Insecure Skill Coding Practices
- Location
SKILL.md:83- Finding
Predictable Temporary File Exposes Sensitive Search Results
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 83-89, 102-106, 559-572
Vulnerability Type: Predictable temporary file with insecure handling of sensitive personal data
Risk Level: MediumVulnerable Code
bash # Submit search request curl -s -X POST "https://api.nyne.ai/person/search" \ -H "Content-Type: application/json" \ -H "X-API-Key: $NYNE_API_KEY" \ -H "X-API-Secret: $NYNE_API_SECRET" \ -d '{"query": "Software engineers at Google in San Francisco", "limit": 10, "type": "premium", "show_emails": true}' | nyne_parse > /tmp/nyne_search.jsonThe same predictable file is overwritten during polling:
bash curl -s "https://api.nyne.ai/person/search?request_id=$REQUEST_ID" \ -H "X-API-Key: $NYNE_API_KEY" \ -H "X-API-Secret: $NYNE_API_SECRET" | nyne_parse > /tmp/nyne_search.jsonThe documented commands subsequently extract sensitive data from that file:
bash # All emails jq '.data.results[] | {displayname, best_business_email, best_personal_email, altemails}' /tmp/nyne_search.json # Phone numbers jq '.data.results[] | {displayname, fullphone}' /tmp/nyne_search.jsonTechnical Analysis
The skill repeatedly stores complete API responses in the fixed path
/tmp/nyne_search.json. These responses can contain business and personal email addresses, alternate email addresses, phone numbers, biographies, locations, employment histories, and other profile information.The instructions do not:
- Create the file atomically with a unique name.
- Set a restrictive process umask or explicit file permissions.
- Verify that the destination is a regular file owned by the current user.
- Defend against pre-existing symbolic links.
- Delete the file when processing finishes.
A shell redirection to a predictable path follows a pre-existing symbolic link. On a shared host, another local user may therefore be able to anticipate the path and cr ...[truncated 1842 chars]
- Remediation
View remediation
Remediation Suggestions
- Create a unique temporary file with
mktemprather than using a fixed filename. - Set
umask 077before creating files that may contain personal information. - Store the generated filename in a quoted variable and use it consistently.
- Register a cleanup trap so the file is removed on normal completion, interruption, or failure.
- Avoid writing the complete response to disk when in-memory processing or a protected pipe is sufficient.
- If persistent storage is required, use an application-specific private directory with restrictive permissions and a documented retention period.
Example hardened pattern:
bash umask 077 NYNE_RESULT_FILE=$(mktemp "${TMPDIR:-/tmp}/nyne_search.XXXXXX") || exit 1 trap 'rm -f "$NYNE_RESULT_FILE"' EXIT HUP INT TERM curl -sS --fail-with-body -X POST "https://api.nyne.ai/person/search" \ -H "Content-Type: application/json" \ -H "X-API-Key: $NYNE_API_KEY" \ -H "X-API-Secret: $NYNE_API_SECRET" \ -d "$REQUEST_BODY" | nyne_parse > "$NYNE_RESULT_FILE"The implementation should additionally validate API failures before treating the stored response as successful output.
- Create a unique temporary file with
