T09 · Insecure Skill Coding Practices
- Location
index.js:100- Finding
Financial records are persisted in plaintext without restrictive filesystem permissions
- Content
View full analysis
Vulnerability Details
File Location:
index.js, lines 100-107
Vulnerability Type: Plaintext storage of sensitive financial data and insecure default file permissions
Risk Level: MediumVulnerable Code
javascript function saveData(data, dataPath) { const dir = path.dirname(dataPath); if (!fs.existsSync(dir)) { fs.mkdirSync(dir, { recursive: true }); } fs.writeFileSync(dataPath, JSON.stringify(data, null, 2)); }Technical Analysis
The application serializes all income records directly into an unencrypted JSON file. These records may include income amounts, currencies, customer or platform names, project notes, tags, and timestamps.
Neither
fs.mkdirSyncnorfs.writeFileSyncspecifies a restrictive filesystem mode. Consequently, permissions are inherited from the process umask. Under a common umask of0022, a newly created directory can be accessible with mode0755and a newly created file with mode0644, allowing other local users to read the financial records.The implementation also does not correct the permissions of an existing file. If the configured
DATA_PATHreferences a file with overly broad permissions, subsequent writes preserve that exposure. The project documentation advises users to encrypt sensitive information, but the implementation does not provide encryption.Attack Path
- A user runs the Skill with the default path or another path located on a multi-user system.
- The process creates the data directory and JSON file using permissions derived from a permissive umask.
- Income records, notes, and source information are written to the file in plaintext.
- Another local user or compromised process identifies the configured or default data path.
- If filesystem permissions permit access, that actor reads and exfiltrates the complete financial dataset.
- If an existing configured file is also writable by that actor, the actor can mo ...[truncated 614 chars]
- Remediation
View remediation
Remediation Suggestions
-
Create the storage directory with owner-only permissions:
javascript fs.mkdirSync(dir, { recursive: true, mode: 0o700 }); -
Create and write the data file with mode
0600:javascript fs.writeFileSync(dataPath, JSON.stringify(data, null, 2), { encoding: 'utf8', mode: 0o600, flag: 'w' }); -
Explicitly correct permissions on existing paths using
fs.chmodSync(dir, 0o700)andfs.chmodSync(dataPath, 0o600)after validating ownership. -
Provide authenticated encryption for stored records, such as AES-GCM, with keys stored in an operating-system keychain or dedicated secrets manager rather than alongside the data file.
-
Validate the configured path and reject symbolic links or unexpected file types where the deployment threat model includes local attackers. Atomic writes through a securely created temporary file should be used to prevent corruption.
-
Document the confidentiality requirements and warn users before writing sensitive financial information to shared or network-mounted locations.
-
