T09 · Insecure Skill Coding Practices
- Location
src/douyin/comment-cli.js:159- Finding
Automatic Plaintext Retention of Collected Douyin Data
- Content
View full analysis
- Remediation
View remediation
`. - Continue using stdout as the default output channel. 2. **Apply restrictive file permissions** - Create the log directory with mode `0700`. - Create result files with mode `0600`. - Where supported, use exclusive creation to avoid overwriting existing files. Example: ```js await fs.promises.mkdir(logDirectory, { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, flag: "wx", }); ``` 3. **Minimize stored data** - Store only fields explicitly requested by the user. - Avoid retaining complete API responses when a summary is sufficient. - Provide an option to redact usernames, stable user identifiers, profile URLs, and comment-author metadata. 4. **Avoid identifiers in filenames** - Replace keywords, account identifiers, and video identifiers with random identifiers or non-reversible hashes. - Keep sensitive request details inside the protected file only when necessary. 5. **Implement retention controls** - Support a configurable expiration period. - Delete expired records automatically. - Provide a documented command for removing all retained results. 6. **Document retention clearly at execution time** - If saving is requested, report the destination, retained fields, permissions, and retention period before or immediately after writing. - Explain that collected public data may still constitute personal data under applicable policies or regulations. 7. **Protect existing installations** - Recommend deleting unnecessary files already present under `logs/`. - Ensure `logs/` is excluded from source control, package publication, and build artifacts. ]]>
