T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:5- Finding
Undisclosed Persistent Storage of Potentially Sensitive Legal Data
- Content
View full analysis
> "$DATA_DIR/history.log"; } ``` ```bash cmd_add() { echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo " Added: $*" _log "add" "${1:-}" } ``` ### Technical Analysis The script creates a persistent application data directory on every invocation. The `add` command appends the complete user-supplied entry to `data.log`, while `_log` records command activity and, for `add`, the first user-supplied argument in `history.log`. Court-preparation input may contain party names, dispute descriptions, financial amounts, dates, or other confidential legal information. This storage behavior is not disclosed in `SKILL.md`, which describes command output as being returned through standard output. The script also does not request consent before retaining data, implement a retention policy, redact sensitive values, or provide effective deletion functionality. The directory and files rely on the process umask rather than explicitly enforcing restrictive permissions. Under a permissive or unusual umask, other local users may be able to read retained information. Backups and filesystem snapshots may also preserve the data beyond the user's expected session. This is a confidentiality and privacy weakness. It does not establish remote code execution, privilege escalation, or system-level persistence. ### Attack Path 1. A user invokes the tool with sensitive case information, for example through `court-prep add`. 2. `cmd_add` expands `$*` and appends the complete entry in plaintext to `$DATA_DIR/data.log`. 3. `_log` also appen ...[truncated 1021 chars]- Remediation
View remediation
