T09 · Insecure Skill Coding Practices
- Location
src/douyin/search-cli.js:253- Finding
Automatic Plaintext Retention of Query Results and Public Personal Data
- Content
View full analysis
Vulnerability Details
File Location:
src/douyin/search-cli.js:253-260,src/douyin/comment-cli.js:151-162, andsrc/utils/log.js:25-35
Vulnerability Type: Automatic plaintext storage of potentially sensitive query and response data
Risk Level: MediumVulnerable Code
src/douyin/search-cli.js:253-260:js console.log(JSON.stringify(finalOutput, null, 2)); utils.printSuccess( `搜索任务完成, 共返回 ${finalOutput.results.length} 条结果`, ); await log.taskWrite( `${startTime}_${keyword}_${sort}_${time}_${duration}_${content}_search.json`, JSON.stringify(finalOutput, null, 2), );src/douyin/comment-cli.js:151-162:js console.log(JSON.stringify(finalOutput, null, 2)); utils.printSuccess( `获取评论任务完成, 共返回 ${finalOutput.results.length} 条结果`, ); url = url.replace(/[^a-zA-Z0-9_-]/g, ""); url = url.replace("httpswwwdouyincomvideo", ""); url = url.replace("httpswwwdouyincomnote", ""); await log.taskWrite( `${startTime}_${url}_comment.json`, JSON.stringify(finalOutput, null, 2), );src/utils/log.js:25-35:js const outputFilename = path.join( path.dirname(__filename), "..", "..", "logs", safeFilename, ); try { await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true }); await fs.promises.writeFile(outputFilename, content);Technical Analysis
Successful search and comment operations are automatically serialized and written to the project’s
logs/directory. Persistence is not opt-in, no retention policy is enforced, and no redaction is applied before writing the complete response.Comment response records may contain comment text, user IDs, nicknames, stable
SEC_UIDidentifiers, and IP-region labels, as documented inassets/comment_cli_resp.schema.json:23-41. Search logs also retain the user’s keyword, filtering parameters, and complete API results. The files are created using the process and ...[truncated 2091 chars]- Remediation
View remediation
Remediation Suggestions
- Disable persistence by default. Return results through standard output without creating files unless the user explicitly requests storage.
- Add an explicit output option. Require a flag such as
--saveor--output <path>before writing any result data. - Apply data minimization. Exclude fields that are unnecessary for the requested analysis, particularly stable user identifiers and IP-region labels.
- Provide redaction controls. Support an anonymized output mode that replaces user IDs and nicknames with non-reversible aliases and removes location-related fields.
- Use restrictive file permissions. Create the log directory with mode
0700and output files with mode0600, subject to platform support. - Implement retention controls. Add configurable expiration, maximum file count, and secure cleanup functionality.
- Document local storage behavior. Clearly notify users before saving data and identify the storage location, retained fields, and deletion procedure.
- Separate operational logs from datasets. Operational logs should contain only status and diagnostic metadata, while full API responses should be treated as explicitly exported datasets.
