T09 · Insecure Skill Coding Practices
- Location
scripts/scan.sh:32- Finding
Detected secrets and attacker-controlled scan results are disclosed verbatim
- Content
View full analysis
/dev/null || true) if [ -n "$SECRETS" ]; then echo "WARNING: Potential hardcoded secrets found:" echo "$SECRETS" else echo "OK: No obvious hardcoded secrets detected." fi ``` The same unsafe rendering pattern is used for dangerous-call matches and world-writable filenames: ```bash if [ -n "$DANGEROUS_CALLS" ]; then echo "WARNING: Potential dangerous function calls found:" echo "$DANGEROUS_CALLS" fi ``` ```bash if [ -n "$WORLD_WRITABLE" ]; then echo "WARNING: World-writable files found:" echo "$WORLD_WRITABLE" fi ``` ### Technical Analysis Recursive `grep -n` output includes the matching source line in full. When that line contains a credential matching one of the scanner's expressions, `echo "$SECRETS"` reproduces the complete credential in terminal output. This can propagate sensitive material from the source tree into CI logs, audit transcripts, agent context, terminal history captures, or other retained output. The target project also controls matched source text and filenames. Printing these values without escaping non-printable characters permits embedded terminal control sequences, carriage returns, or multiline text to alter the visual presentation of results. This is an output-injection concern rather than shell command injection: quoting prevents ordinary shell expansion, but it does not make terminal control characters safe. ### Attack Path 1. A target repository contains a real credential matching on ...[truncated 1056 chars]- Remediation
View remediation
