T09 · Insecure Skill Coding Practices
- Location
SKILL.md:31- Finding
Plaintext Stash Created Without Restrictive File Permissions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 31–35
Vulnerability Type: Plaintext data exposure caused by insecure filesystem permissions
Risk Level: LowVulnerable Code
bash mkdir -p ~/.cache/clipboard-stash slug="$1"; shift; content="$*" printf '%s\t%s\t%s\n' "$slug" "$(date -Is)" "${content//$'\n'/\\n}" \ >> ~/.cache/clipboard-stash/stash.tsvTechnical Analysis
The command stores user-provided clipboard content persistently in the plaintext file
~/.cache/clipboard-stash/stash.tsv. Neither the containing directory nor the file is assigned an explicit owner-only permission mode. Their permissions therefore depend on the invoking process's ambientumask.With a commonly used
022umask, the directory may be created with mode0755and the stash file with mode0644. On a multi-user system, this can allow other local users to read saved snippets. Although the documentation advises users not to store secrets, that warning does not enforce confidentiality and ordinary notes may still contain private or sensitive information.Attack Path
- A user invokes the save command and supplies a text snippet.
- The command creates
~/.cache/clipboard-stashandstash.tsvunder the user's currentumask. - If the resulting directory traversal and file read permissions permit access, another local account reads
~/.cache/clipboard-stash/stash.tsv. - The local account obtains stored slugs, timestamps, and clipboard content.
Exploitation requires local access under another account and filesystem permissions that allow traversal of the user's home directory and stash path.
Impact Assessment
The issue can disclose all entries stored in the stash, including their slugs, timestamps, and plaintext content. It does not grant code execution, elevated privileges, or remote access. The exposure is limited to local principals that can traverse the relevant directories and rea ...[truncated 11 chars]
- Remediation
View remediation
Remediation Suggestions
Enforce owner-only permissions independently of the caller's environment:
bash umask 077 mkdir -p -m 700 ~/.cache/clipboard-stash touch ~/.cache/clipboard-stash/stash.tsv chmod 600 ~/.cache/clipboard-stash/stash.tsv slug="$1"; shift; content="$*" printf '%s\t%s\t%s\n' "$slug" "$(date -Is)" "${content//$'\n'/\\n}" \ >> ~/.cache/clipboard-stash/stash.tsvAdditionally:
- Verify and repair permissions on pre-existing directories and stash files.
- Retain the warning that secrets must not be stored in the stash.
- Consider refusing to operate if the file is not owned by the current user or is a symbolic link.
- Document that the data is persistent and unencrypted at rest.
