T09 · Insecure Skill Coding Practices
- Location
scripts/path_detector.py:20- Finding
Insecure Storage Permissions and Symlink Handling for Sensitive Task History
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a task logger, but it automatically persists complete task details across conversations in broadly shared local locations without enough scoping, permissions, or user control.
Install only if you intentionally want task records, including parameters and results, to persist across conversations. Avoid using it for secrets, credentials, personal data, or sensitive campaign/business details unless storage is confined to a private directory with restrictive permissions and clear retention controls.
scripts/path_detector.py:20Insecure Storage Permissions and Symlink Handling for Sensitive Task History
scripts/path_detector.py:57Unvalidated Persistent Anchor Can Redirect History Writes
scripts/query_tasks.py:89Cross-Scope History Aggregation Can Disclose or Poison Task Records
scripts/record_task.py:121Non-Atomic Unlocked History Updates Permit Record Loss and File Corruption
The skill promotes cross-conversation sharing through a globally writable /tmp location but does not clearly warn users that task parameters, execution history, and platform metadata may become accessible across sessions. In an agent environment, that can leak sensitive operational data from one conversation or tenant into another.
The skill explicitly encourages retaining and querying complete task details in a globally shared store to enable cross-conversation access. That creates a direct confidentiality risk because later sessions can access prior sessions' data without strong isolation, especially in shared /tmp locations that are commonly readable or writable by multiple processes.
The documentation explicitly says new conversations can query all previous task records from a globally readable/writable location. This is effectively an intentional cross-session data-sharing channel and can expose sensitive parameters, workflow details, and metadata between unrelated conversations or users.
The skill documents capabilities to read environment variables and read/write files, but it declares no explicit tool scope or permissions boundary. In practice this increases the chance that an agent or reviewer will approve or run the skill without understanding that it persists data to disk and inspects environment-derived paths.
The documented code example contradicts the stated storage priority by trying workspace/home/cwd paths before /tmp, while the prose says /tmp global sharing is highest priority. This inconsistency is dangerous because operators and dependent skills may assume one storage boundary while the implementation behaves differently, causing unintended data placement, exposure, or failed assumptions about isolation.
The troubleshooting guidance reinforces the expectation that all conversations should share one history file, normalizing insecure data sharing as a feature. This increases the likelihood of deployment in environments where /tmp is shared, leading to unintended disclosure or tampering of task records.
Claiming the storage is 'safe and reliable' is misleading because the skill records complete task parameters and detailed operation history, which may contain sensitive business or user data. This can cause users to underestimate confidentiality risks and enable logging where it is inappropriate.
Comments, docstrings, exception text, and console output are written entirely in Chinese, including user-visible messages emitted when the script runs. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly documented and justified.
The module probes multiple environment-derived and global locations, then persists the chosen history path in a stable anchor file under the user's home directory. In the context of a cross-dialog global logging skill, this behavior increases the risk of unintentionally collecting and retaining data across sessions and workspaces without clear disclosure or consent, which can expose sensitive task metadata and filesystem locations.
Natural-language strings in the module docstring and command-line help are fixed to Chinese, which imposes a specific language on users without any opt-in or documented locale constraint. The file does not indicate that the skill is region-specific or offer an alternative language.
The script enumerates a broad set of locations including home, cwd, /tmp, /var/tmp, and multiple environment-derived directories, then aggregates records from all matching files. This over-broad search increases the risk of reading attacker-planted or unrelated data, especially because temporary directories and environment variables are easy to influence in many execution contexts.
A query-oriented script should not mutate persistent state, but this fallback path selection logic writes an anchor file and may create directories or test files while determining where history lives. In a shared or multi-tenant environment, this expands the script from read-only inspection into filesystem modification, which can surprise callers, alter global state across sessions, and be abused to influence later reads toward attacker-controlled locations.
This code performs filesystem modifications by creating directories, writing a temporary test file, and deleting it to probe writability. Although the script later prints success or error output, there is no prior disclosure or confirmation to the user that it will modify paths such as the home directory, workspace-related directories, or temp directories.
The script stores user-supplied parameters, operations, and results to disk in a shared persistent location without any explicit consent, minimization, or sensitivity filtering. In this skill context, those fields may contain credentials, prompts, internal workflow details, or other sensitive cross-session data, so silent persistence increases the risk of unintended disclosure to other users, tools, or later sessions.
The helper returns and may print more runtime context than is necessary for path selection, including cwd, home directory, workspace environment values, anchor contents, and the full Python version. In a shared agent or multi-tenant environment, these details can leak filesystem layout and prior storage locations, which can aid later targeting or cross-session data discovery.
The output includes exact storage paths and per-file read errors, which can reveal directory layouts, usernames, workspace names, and other environmental details. While low severity by itself, this information disclosure can help an attacker map the filesystem and identify where to place or target history files in conjunction with the script's broad path scanning.
No suspicious patterns detected.