T09 · Insecure Skill Coding Practices
- Location
__init__.py:156- Finding
Sensitive typed and clipboard content is written to logs
- Content
View full analysis
50 else ''}' " f"(interval={interval:.3f}s)" ) ``` ```python try: import pyperclip pyperclip.copy(text) logger.info(f"Copied to clipboard: '{text[:50]}...'") except ImportError: logger.error("pyperclip not installed. Run: pip install pyperclip") except Exception as e: logger.error(f"Error copying to clipboard: {e}") ``` ```python try: import pyperclip text = pyperclip.paste() logger.debug(f"Got from clipboard: '{text[:50]}...'") return text except ImportError: logger.error("pyperclip not installed. Run: pip install pyperclip") return None except Exception as e: logger.error(f"Error getting clipboard: {e}") return None ``` ### Technical Analysis The controller records the first 50 characters of typed and clipboard content. Desktop automation routinely handles passwords, authentication tokens, recovery codes, private messages, personal data, and other secrets. Logging their plaintext prefixes violates data minimization and creates a secondary copy outside the original application. Typed text and clipboard writes are logged at `INFO` level. Because the module configures logging with `logging.basicConfig(level=logging.INFO)`, these disclosures occur under the default configuration. Clipboard reads use `DEBUG`, but become exposed whenever debugging is enabled by the application. Approval prompts also interpolate typed content into the terminal when `require_approval=True`, which can expose the same sensitive material to terminal history or session capture. ### Attack Path 1. ...[truncated 1098 chars]- Remediation
View remediation
