T09 · Insecure Skill Coding Practices
- Location
src/utils/log.js:25- Finding
Automatic Plaintext Retention of Queries and Collected Douyin Data
- Content
View full analysis
Vulnerability Details
File Location:
src/utils/log.js:25-35; invoked fromsrc/douyin/search-cli.js:280-283,src/douyin/comment-cli.js:198-201, andsrc/douyin/post-cli.js:209-212
Vulnerability Type: Plaintext storage of potentially sensitive query and collected user data
Risk Level: MediumVulnerable Code
src/utils/log.js:25-35:js const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outputFilename, content);src/douyin/search-cli.js:280-283:js await log.taskWrite( `${startTime}_${keyword}_${sort}_${time}_${duration}_${content}_search.json`, JSON.stringify(finalOutput, null, 2), );src/douyin/comment-cli.js:198-201:js await log.taskWrite( `${startTime}_${url}_comment.json`, JSON.stringify(finalOutput, null, 2), );src/douyin/post-cli.js:209-212:js await log.taskWrite( `${startTime}_${url}_post.json`, JSON.stringify(finalOutput, null, 2), );Technical Analysis
Every successful search, comment retrieval, and profile-post retrieval operation automatically serializes the complete output object and writes it to the project’s
logsdirectory. The stored object includes the original request parameters and all returned records. Depending on the command, this can retain search keywords, profile or video identifiers, comments, public user identifiers, and other collected content.Although the README discloses that results are archived, the implementation does not provide an opt-out, expiration policy, cleanup mechanism, encryption, or explicit restrictive filesystem permissions.
mkdirandwriteFileinherit permissions from the process umask. In a shared workspace, permissive umask configuration can therefore make these files acce ...[truncated 1717 chars]- Remediation
View remediation
Remediation Suggestions
- Make local persistence opt-in through an explicit option such as
--outputor--save. - Provide a
--no-logoption if backward compatibility requires logging to remain enabled by default. - Create the log directory with mode
0700and result files with mode0600, while documenting platform-specific permission limitations. - Avoid placing raw search keywords in filenames; use a random identifier or cryptographic hash instead.
- Implement configurable retention and automatic cleanup, such as deleting files after a defined number of days.
- Clearly warn users before saving large comment or profile datasets and describe exactly which fields are retained.
- Consider data minimization by omitting unnecessary request metadata and user identifiers from persisted output.
- For environments requiring stronger confidentiality, support encrypted storage or instruct users to save results only in an access-controlled directory.
- Make local persistence opt-in through an explicit option such as
