T09 · Insecure Skill Coding Practices
- Location
SKILL.md:40- Finding
Predictable Temporary Log File Enables Data Exposure and File Truncation
- Content
View full analysis
/tmp/pilot-stream.log & ``` ### Technical Analysis The documented command redirects received stream data to a fixed path in the shared `/tmp` directory. Shell redirection opens the destination with truncation semantics and ordinarily follows an existing symbolic link. Because the path is predictable, another local process may prepare it before the command runs. Depending on operating-system symlink protections, directory permissions, file ownership, and the invoking user's privileges, this can cause the shell to truncate or overwrite a different file writable by that user. The newly created log file also inherits permissions from the invoking process's `umask`. With a permissive `umask`, other local users may be able to read potentially sensitive stream contents. ### Attack Path 1. A local attacker learns that the documented listener command uses `/tmp/pilot-stream.log`. 2. Before the command is executed, the attacker creates the predictable path or, where platform protections permit, places a symbolic link at that path targeting another file. 3. The user or agent executes the documented command. 4. The shell opens the path using output-redirection and truncation behavior. 5. The target file may be truncated or overwritten with stream data if it is writable under the invoking user's privileges. 6. Alternatively, if the log is created with permissive permissions, the attacker reads incoming stream records directly from the predictable file. Successful exploitation requires local access and is constrained by filesystem permissions and platform-level temporary-directory protections. ### Impact Assessment The issue does not grant privileges beyond those already held by the process running the command. Its potential effects are: - Disclosure of strea ...[truncated 472 chars]- Remediation
View remediation
"$STREAM_LOG" & listener_pid=$! wait "$listener_pid" ``` Additional hardening measures: 1. Avoid fixed filenames in shared temporary directories. 2. Set `umask 077` before creating files that may contain stream data. 3. Use `mktemp -d` so the log resides in a uniquely named directory accessible only to the current user. 4. Quote all generated paths to prevent shell word splitting. 5. Register cleanup handlers with `trap`. 6. If persistent logging is required, use an application-controlled directory with explicit ownership, `0700` directory permissions, and `0600` file permissions. 7. Consider processing the listener output directly instead of writing sensitive stream data to disk. ]]>
