T09 · Insecure Skill Coding Practices
- Location
src/core/LobsterOps.js:104- Finding
PII Filtering Can Be Bypassed Through Event Options and Updates
- Content
View full analysis
this.filter(item)); } if (typeof data === 'object') { const filtered = {}; for (const [key, value] of Object.entries(data)) { filtered[key] = this.filter(value); } return filtered; } return data; } ``` ### Technical Analysis `logEvent` filters only the original `event` object. It subsequently merges the caller-controlled `options` object after filtering, so values supplied through `options` are written to storage without passing through `PIIFilter`. The public `updateEvent` method also forwards the entire `updates` object directly to the selected storage backend without applying filtering. An event that was safe when initially recorded can therefore be modified to contain unredacted secrets. The ...[truncated 1850 chars]- Remediation
View remediation
