T09 · Insecure Skill Coding Practices
- Location
scripts/rollback.ps1:53- Finding
Agent memory snapshots are stored in plaintext without access-control hardening
- Content
View full analysis
Vulnerability Details
File Location:
scripts/rollback.ps1, lines 53-84
Vulnerability Type: Plaintext storage of potentially sensitive agent memory
Risk Level: MediumTechnical Analysis
The snapshot root is placed in a predictable directory adjacent to the script, and protected agent files are copied there without encryption or explicit access-control restrictions.
powershell # Snapshot root: one level up from this script by default. # NOTE: Join-Path takes only TWO path segments in Windows PowerShell 5.1. $SnapRoot = Join-Path (Join-Path $PSScriptRoot "..") "snapshots" function Do-Snapshot([string]$reason) { if (-not (Test-Path $SnapRoot)) { New-Item -ItemType Directory -Path $SnapRoot | Out-Null } $stamp = New-TimeStamp $target = Join-Path $SnapRoot $stamp New-Item -ItemType Directory -Path $target | Out-Null $manifest = @() $hashes = @() foreach ($f in $CoreFiles) { $src = Get-FullCorePath $f $name = Split-Path $f.rel -Leaf if (Test-Path $src) { Copy-Item -Path $src -Destination (Join-Path $target $name) -Force $hash = (Get-FileHash -Path $src -Algorithm MD5).Hash $manifest += "$($f.rel)`t$name" $hashes += "$($f.rel)`t$hash" } else { $manifest += "$($f.rel)`t(MISSING)" $hashes += "$($f.rel)`tMISSING" } }The files identified by the project as snapshot targets include identity data, user-profile information, durable knowledge, and event journals. These can contain private or operationally sensitive information. The script inherits permissions from the parent directory and does not ensure that only the intended account can read newly created directories and files.
Hashing does not provide confidentiality. The presence of
HASHES.md5therefore does not protect the contents from disclosure.Attack Path
- A u ...[truncated 1180 chars]
- Remediation
View remediation
Remediation Suggestions
- Create the snapshot root under a dedicated, user-private data directory rather than beside the script.
- On Windows, apply an explicit ACL granting access only to the intended user and required administrative recovery principals. Disable unwanted inherited permissions.
- Encrypt sensitive snapshots at rest, preferably using DPAPI, an enterprise-managed encryption key, or an authenticated archive format.
- Do not store secrets unless they are explicitly required for recovery. Add configurable exclusions for credentials, tokens, private keys, and sensitive journals.
- Warn before snapshotting arbitrary paths supplied through
-Arg. - Implement retention limits and secure deletion policies so historical sensitive data is not kept indefinitely by default.
- Validate the effective ACL after directory creation and abort if the location is readable by unintended principals.
