T09 · Insecure Skill Coding Practices
- Location
references/scripts.md:53- Finding
Plaintext login passwords can be exposed through insecure mutation dump files
- Content
View full analysis
Vulnerability Details
File Location:
references/scripts.md, lines 53–89 and 105–122
Vulnerability Type: Insecure temporary-file handling and ineffective secret redaction
Risk Level: MediumComplete Code Snippet
bash SAFE_MUTATE_DIR="${SAFE_MUTATE_DIR:-/tmp/lingjun-mutate}" mkdir -p "$SAFE_MUTATE_DIR" safe_mutate() { local action="${1:?action name required, e.g. extend-cluster}" shift local intent="" if [ "${1:-}" = "--intent" ]; then intent="${2:?--intent value required, e.g. --intent \"extend my cluster\"}" shift 2 fi case "$action" in extend-cluster|shrink-cluster|delete-node|delete-hyper-node|\ change-node-group|create-node-group|update-node-group|delete-node-group|\ create-instance) ;; *) echo "❌ safe_mutate applies only to mutating actions; got: $action" >&2; return 2 ;; esac local args_json hash args_json=$(printf '%s\n' "$@" | jq -R . | jq -s .) hash=$(printf '%s|%s' "$action" "$args_json" | sha256sum | cut -c1-12) local dump="$SAFE_MUTATE_DIR/${action}-${hash}.json" printf '%s' "$args_json" | \ jq --arg action "$action" --arg hash "$hash" --arg intent "$intent" \ '{action:$action, hash:$hash, intent:$intent, args:., redacted:false}' \ | sed -E 's/(LoginPassword"[^"]*")[^,}]*"[^"]*"/\1"******"/g; s/(--login-password"[^,}]*")[^,}]*"[^"]*"/\1"******"/g' \ > "$dump" echo "$hash" return 0 } safe_mutate_confirm() { local hash="${1:?hash required}" local dump dump=$(ls -1 "$SAFE_MUTATE_DIR"/*-"$hash".json 2>/dev/null | head -1) if [ -z "$dump" ] || [ ! -f "$dump" ]; then echo "❌ confirm submission failed: token invalid or expired" >&2 return 2 fi local action action=$(jq -r .action "$dump") local -a argv while IFS= read -r line; do argv+=("$line"); done < <(jq -r '.args[]' "$dump") safe_aliyun "${argv[@]}" local rc=$? rm -f "$dump" return $rc }Technical Analysis
The documented mutation wrapper serializes every c ...[truncated 3277 chars]
- Remediation
View remediation
Remediation Suggestions
-
Use a private, per-user temporary directory
- Create it with
mktemp -dunder a user-private runtime directory. - Set
umask 077before creating any state. - Verify that the directory is owned by the current effective UID and has mode
0700. - Do not reuse a pre-existing shared directory without ownership and permission validation.
- Create it with
-
Enforce restrictive file permissions
- Create dump files atomically with mode
0600. - Reject symbolic links and unexpected existing paths.
- Avoid ordinary shell redirection into attacker-influenced or shared locations.
- Create dump files atomically with mode
-
Do not persist authentication secrets
- Store only non-sensitive confirmation metadata and a digest of the authorized parameter set.
- Keep passwords in memory for the shortest possible duration.
- If cross-turn secret persistence is unavoidable, use an OS-backed secret store or authenticated encryption with a key unavailable to other users.
-
Replace regular-expression redaction
- Parse known JSON-bearing arguments with
jqand recursively replace secret fields before writing them. - Handle separate options such as
--login-passwordby redacting the following argument before serialization. - Maintain an explicit allowlist of safe fields rather than attempting to detect every secret name after serialization.
- Add regression tests for nested JSON, escaped strings, separate flag/value pairs, arrays, and malformed input.
- Parse known JSON-bearing arguments with
-
Guarantee cleanup
- Install cleanup traps for
EXIT,INT,TERM, and error paths. - Delete pending state when the user cancels or confirmation expires.
- Apply a short expiration period and securely remove stale dumps at startup.
- Install cleanup traps for
-
