T09 · Insecure Skill Coding Practices
- Location
src/douyin/comment-cli.js:134- Finding
Automatic Plaintext Retention of User-Linked Douyin Data
- Content
View full analysis
- Remediation
View remediation
` or `--save`. - Do not write any result file unless the user requests it. 2. **Provide an explicit disable control** - If backward compatibility requires automatic export temporarily, support `--no-save` and document it prominently. - Prefer changing the next major version to disable retention by default. 3. **Apply data minimization** - Store only fields required for the requested analysis. - Omit or redact `user_uid`, `user_sec_uid`, `user_nickname`, `ip_label`, and complete request URLs unless the user explicitly requires them. - Consider pseudonymizing stable identifiers before export. 4. **Use restrictive filesystem permissions** - Create the log or export directory with mode `0700`. - Create result files with mode `0600`. - Avoid relying solely on the process umask. ```js await fs.promises.mkdir(outputDirectory, { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, flag: "wx", }); ``` 5. **Add retention controls** - Support automatic expiration or a configurable retention duration. - Provide a documented cleanup command. - Avoid accumulating historical results indefinitely. 6. **Separate diagnostics from data exports** - Keep diagnostic messages on stderr. - Treat complete API responses as data exports rather than logs. - Do not mix personal or user-linked records with operational logging. 7. **Improve disclosure and consent** - Clearly state in `SKILL.md` when data will be written, where it will be stored, which fields are included, and how users can prevent or delete it. - Obtain explicit confirmation before retaining comment datasets containing identifiers or regional labels. 8. **Add security tests** - Verify that no file is created during default command exec ...[truncated 235 chars]
