T09 · Insecure Skill Coding Practices
- Location
src/fieldy-webhook.js:43- Finding
Unprotected Plaintext Storage of Sensitive Voice Transcripts
- Content
View full analysis
/fieldy/transcripts/`, including transcripts that do not contain a wake word. The stored record includes the complete transcript, supplied timestamp, and speaker metadata. The code does not explicitly assign restrictive directory or file permissions, encrypt records, redact credentials or other sensitive content, limit file growth, or delete old records. Consequently, effective permissions depend on the process umask and surrounding workspace configuration. Transcript records can also remain available indefinitely and may be copied into backups. Voice transcripts may include personal data, authentication secrets, confidential business information, or private conversati ...[truncated 1539 chars]- Remediation
View remediation
