T09 · Insecure Skill Coding Practices
- Location
scripts/log_routing_decision.py:39- Finding
Default Persistence of Potentially Sensitive Routing Metadata
- Content
View full analysis
Vulnerability Details
File Location:
scripts/log_routing_decision.py:39-64
Vulnerability Type: Plaintext storage of potentially sensitive task content
Risk Level: MediumVulnerable Code
python def append_log(entry): with LOG.open('a', encoding='utf-8') as f: f.write(json.dumps(entry, ensure_ascii=False) + '\n') def main(): ap = argparse.ArgumentParser(description='Log skill-router routing decisions and mark skill usage') ap.add_argument('--intent', required=True) ap.add_argument('--domain', default='') ap.add_argument('--subdomain', default='') ap.add_argument('--risk', default='') ap.add_argument('--skills', nargs='+', required=True) ap.add_argument('--candidates', nargs='*', default=[]) ap.add_argument('--reason', default='') args = ap.parse_args() ts = datetime.now(timezone.utc).isoformat() mark_usage(args.skills) append_log({ 'timestamp': ts, 'intent': args.intent, 'domain': args.domain, 'subdomain': args.subdomain, 'risk': args.risk, 'skills': args.skills, 'candidates': args.candidates, 'reason': args.reason, }) print('logged routing decision for:', ', '.join(args.skills))The behavior is enabled by default in
SKILL.md:166:markdown 11. After a skill is actually chosen and used, treat routing-decision logging as the default post-action: record the chosen skill(s) with `python3 scripts/log_routing_decision.py ...` unless there is a concrete reason not to.Technical Analysis
The routing logger accepts unrestricted free-form
--intentand--reasonvalues and writes them verbatim to the append-onlyreferences/routing-decisions.jsonlfile. User task descriptions and routing rationales can contain personal information, confidential business data, infrastructure identifiers, financial details, or credent ...[truncated 2174 chars]- Remediation
View remediation
Remediation Suggestions
- Record only coarse structured metadata by default, such as domain, subdomain, risk level, and selected Skill identifier.
- Make free-form
intentandreasonstorage explicitly opt-in rather than the default. - Add secret and personal-data redaction before serialization, including API keys, tokens, passwords, email addresses, account identifiers, and private filesystem paths.
- Avoid passing sensitive text through command-line arguments. Accept structured input through standard input or another protected local channel.
- Create the log with owner-only permissions, such as mode
0600, and verify the parent directory is not broadly writable or readable. - Add configurable retention and rotation, including maximum age and maximum file size.
- Provide a command to purge routing history safely.
- Document that raw user prompts, credentials, personal data, and confidential business information must never be logged.
- Ensure generated telemetry files are excluded from source-control commits and unintended synchronization where appropriate.
- Consider storing only a non-reversible category or short user-approved summary when detailed auditing is required.
