T09 · Insecure Skill Coding Practices
- Location
templates/authenticated-session.sh:15- Finding
Authentication State Files Are Saved Without Explicit Access Controls
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 fi install -m 600 /dev/null "$STATE_FILE" agent-browser state save "$STATE_FILE" chmod 600 -- "$STATE_FILE" ``` 3. For temporary state, use a private runtime directory and an unpredictable filename rather than a fixed `/tmp` path: ```bash umask 077 STATE_FILE="$(mktemp "${XDG_RUNTIME_DIR:-/tmp}/agent-browser-state.XXXXXX.json")" trap 'rm -f -- "$STATE_FILE"' EXIT ``` 4. Verify that the selected path is a regular file owned by the current user before loading it: ```bash if [[ ! -f "$STATE_FILE" || -L "$STATE_FILE" || ! -O "$STATE_FILE" ]]; then echo "ERROR: Unsafe authentication state file" >&2 exit 1 fi ``` 5. Delete state files as soon as reuse is no longer required and revoke the associated web session after suspected disclosure. 6. Update every documentation example to use environment-provided credentials, private state directories, restrictive permissions, and automatic cleanup. Retain the existing recommendation to exclude all state files from version control, but do not treat `.gitignore` as an access-control mechanism. ]]>
