T09 · Insecure Skill Coding Practices
- Location
scripts/llm_chat_scraper.py:107- Finding
Sensitive Prompt Content Exposed Through INFO-Level Logging
- Content
View full analysis
Vulnerability Details
File Location:
scripts/llm_chat_scraper.py, line 107
Vulnerability Type: Sensitive information exposure through application logs
Risk Level: MediumVulnerable Code
python logger.info(f"Creating task for {actor} with prompt: {prompt[:50]}...")Technical Analysis
The Skill records the first 50 characters of every user prompt at INFO level. Prompt content can contain API credentials, personal information, proprietary material, internal system details, or other confidential data.
Logging prompt text is not required to create or retrieve a Scrapeless API task. Because INFO logging is enabled globally, the disclosure occurs during normal operation rather than only in an explicitly enabled debugging mode. The resulting text may be retained in terminal transcripts, CI/CD output, centralized logging systems, Agent execution records, or process supervisors.
The exposure is limited to the first 50 characters of the prompt, but secrets and identifying information commonly occur at the beginning of a prompt. This issue does not directly grant system privileges or permit code execution.
Attack Path
- A user or calling Agent supplies a prompt containing confidential information within its first 50 characters.
- The Skill passes that prompt to
create_task(). - Before the network request is made, the INFO-level logging statement writes the prompt fragment to the configured logging destination.
- A user, service, or attacker with access to retained execution logs reads the disclosed prompt fragment.
- If the fragment contains a usable credential or sensitive business information, it can be misused outside the Skill.
Exploitation therefore requires the ability to cause sensitive content to be submitted and access to the resulting logs.
Impact Assessment
The primary impact is loss of confidentiality. Depending on prompt contents and log distribution, exposure may ...[truncated 262 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove prompt content from routine logs:
python logger.info("Creating task for actor: %s", actor) - Log only non-sensitive operational metadata, such as the actor name and server-generated task identifier.
- If request correlation is necessary, use an opaque locally generated correlation ID rather than prompt text.
- Do not use an ordinary unkeyed prompt hash as a secrecy mechanism because predictable prompts may be recoverable through guessing.
- Make any diagnostic content logging explicitly opt-in, disabled by default, and protected by redaction and retention controls.
- Review existing log storage and retention policies for previously captured prompt fragments.
- Remove prompt content from routine logs:
