T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:5- Finding
Persistent plaintext logging without explicit access restrictions
- Content
View full analysis
> "$DATA_DIR/history.log"; } ``` User input is subsequently written to both a command-specific log and the central history log: ```bash else local input="$*" local ts=$(date '+%Y-%m-%d %H:%M') echo "$ts|$input" >> "$DATA_DIR/scan.log" local total=$(wc -l < "$DATA_DIR/scan.log") echo " [Syscheck] scan: $input" echo " Saved. Total scan entries: $total" _log "scan" "$input" fi ``` Equivalent persistent writes appear in the `monitor`, `report`, `alert`, `top`, `usage`, `check`, `fix`, `cleanup`, `backup`, `restore`, `log`, `benchmark`, and `compare` command handlers. ### Technical Analysis The script persistently stores arbitrary command-line arguments under `~/.local/share/syscheck`. It does not set a restrictive `umask`, explicitly create the data directory with mode `0700`, or create log files with mode `0600`. Consequently, effective permissions depend on the invoking process's environment and current `umask`. Under a permissive `umask`, the directory or generated log files may be readable by other local users. The same input is also duplicated into a command-specific log and `history.log`, increasing the number of locations from which sensitive content must be removed. This persistence is especially relevant because `SKILL.md` describes output as being returned to standard output but does not disclose that supplied arguments are retained in plaintext. ### Attack Path 1. A user invokes a command with sensitive text, for example diagnostic information, internal host details, tokens, or other confidential data. ...[truncated 1037 chars]- Remediation
View remediation
