T09 · Insecure Skill Coding Practices
- Location
scripts/log_event.sh:25- Finding
Plaintext Sensitive-Data Logging and JSONL Log Injection
- Content
View full analysis
/dev/null || date +"%Y-%m-%dT%H:%M:%S+00:00") # Build JSON (portable, no jq required) ENTRY=$(printf '{"ts":"%s","level":"%s","category":"%s","summary":"%s","detail":"%s","action":"%s"}\n' \ "$TS" "$LEVEL" "$CATEGORY" \ "$(echo "$SUMMARY" | sed 's/"/\\"/g')" \ "$(echo "$DETAIL" | sed 's/"/\\"/g')" \ "$ACTION") echo "$ENTRY" >> "$LOG_FILE" echo "[security-audit] Logged: $LEVEL $CATEGORY — $SUMMARY" ``` ### Technical Analysis The logger accepts a full command, file path, or payload in the `DETAIL` argument and writes it verbatim to a persistent log. Commands commonly contain credentials in authorization headers, URL query parameters, environment-variable assignments, API arguments, or embedded request bodies. The implementation has no secret-redaction or data-minimization step. The script also creates the log directory and file without explicitly applying restrictive permissions. Their resulting modes therefore depend on the process environment and inherited `umask`. In an environment with permissive defaults, other local users or processes may be able to read sensitive event details. The handwritten JSON encoding only escapes double quotes in `SUMMARY` and `DETAIL`. It does not correctly encode backslashes, carriage returns, newlines, tabs, or other control characters. In addition, `LEVEL`, `CATEGORY`, and `ACTION` are not escaped or validated at all. A caller able to influence these arguments can p ...[truncated 1766 chars]- Remediation
View remediation
