T09 · Insecure Skill Coding Practices
- Location
src/utils/log.js:29- Finding
Automatic Plaintext Retention of User Queries and Retrieved Data
- Content
View full analysis
- Remediation
View remediation
` option before writing results. 2. **Apply restrictive permissions** - Create the output directory with mode `0700`. - Create result files with mode `0600`. - Reject output paths that resolve outside an approved directory. Example: ```js await fs.promises.mkdir(outputDirectory, { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, content, { mode: 0o600, flag: "wx", }); ``` 3. **Minimize retained information** - Do not place search keywords in filenames. - Use random identifiers or timestamps instead. - Allow users to store only results, excluding request metadata where unnecessary. - Add configurable field redaction. 4. **Introduce retention controls** - Support automatic deletion after a configurable period. - Provide a documented command to purge saved results. - Warn users when existing logs are detected. 5. **Prevent accidental distribution** - Add `logs/` to `.gitignore`. - Exclude generated records from release archives and package manifests. - Document backup and synchronization risks. 6. **Align all documentation** - Clearly state in `SKILL.md` that successful search, post, and comment operations may create local files. - Distinguish “no Douyin-side write operations” from local filesystem writes. - Explain the stored fields, location, retention behavior, and permission model. ]]>
