T05 · Unauthorized Access and Privilege Escalation
- Location
push.js:12- Finding
Undocumented Access to an External User Configuration File
- Content
View full analysis
{ https.get(fullUrl, (res) => { ``` ### Technical Analysis When the `BARK_KEY` environment variable is absent, the Skill constructs a path two directories above its own installation directory and reads the entire `USER.md` file. This crosses the Skill's local directory boundary and accesses user or agent configuration that is not required to be stored within the Skill. The behavior is not disclosed in `SKILL.md`, which states that the key is read from the `BARK_KEY` environment variable when omitted. Although the current implementation only extracts text matching a Bark key pattern, `fs.readFileSync` first loads the complete external file into the process. This violates least-privilege principles and increases the exposure of unrelated information contained in that file. The extracted key is then placed in the path component of an HTTPS URL sent to `api.day.app`. HTTPS protects the request in transit, but URL paths may still be visible to the destination service and may be retained by application, proxy, monitoring, or diagnostic logs. ### Attack Path 1. A user or agent invokes `push.js` without defining the `BARK_KEY` environment variable. 2. `getBarkKey()` resolves `../../USER.md` relative to ...[truncated 1553 chars]- Remediation
View remediation
