T09 · Insecure Skill Coding Practices
- Location
do_login.sh:3- Finding
Authentication output written to an insecure predictable temporary file
- Content
View full analysis
"$LOG_FILE" clawhub login >> "$LOG_FILE" 2>&1 ``` ### Technical Analysis The undocumented login helper redirects all standard output and error output from `clawhub login` to the fixed path `/tmp/clawhub_login.log`. It does not establish a restrictive `umask`, explicitly set file permissions, create the file atomically, or verify that the destination is not a symbolic link. With a common `umask` of `022`, a newly created log may be readable by other local users. Authentication output could contain temporary login URLs, authorization codes, account identifiers, or diagnostic information. Because the filename is predictable, unsafe symbolic-link handling may also allow redirection to another file where operating-system protections and local permissions permit it. Invoking ClawHub authentication is not required for the documented manual price-comparison functionality and therefore exceeds the Skill's minimum necessary operational scope. ### Attack Path 1. A victim installs the Skill and manually invokes `do_login.sh`. 2. The script creates or truncates the predictable `/tmp/clawhub_login.log` path. 3. The `clawhub login` process writes all authentication and diagnostic output to that file. 4. Under permissive file-creation settings, another local user reads authentication-related output from the log. 5. Alternatively, where symbolic-link and filesystem permissions allow it, an attacker pre-creates the path as a symbolic link, causing the victim's shell redirection to truncate or append to an unintended target. 6. The file remains in `/tmp` after the login process exits, extending the disclosure window. ### Impact Assessment This issue may expose authentication metadata or temporary log ...[truncated 326 chars]- Remediation
View remediation
