T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:5- Finding
Undisclosed Persistent Financial Logging Permits Local Data Exposure and Log Injection
- Content
View full analysis
> "$DATA_DIR/history.log"; } cmd_track() { echo " Transaction: $1 Amount: ${2:-0}" _log "track" "${1:-}" } ``` ### Technical Analysis The script creates persistent local storage and writes user-controlled transaction descriptions to `history.log`. This behavior is not disclosed in `SKILL.md`, which presents the project as a Chinese personal income-tax calculator rather than a persistent financial transaction tracker. The directory and log file are created without explicit restrictive permissions. Their effective permissions therefore depend on the invoking process's `umask`. Under a permissive configuration, financial descriptions could become readable by other local users. The `_log` function also inserts the transaction description directly into a line-oriented log without rejecting or escaping carriage-return or newline characters. A crafted description containing newline characters can inject forged records into `history.log`. Quoting the shell expansion prevents word splitting but does not remove embedded newline characters. No network transmission, privilege escalation, remote execution, or cross-session system backdoor was identified. ### Attack Path 1. A victim or integrating agent invokes `scripts/script.sh track` with a sensitive or attacker-controlled transaction description. 2. `cmd_track` forwards the description to `_log`. 3. `_log` stores the description persistently in `$DATA_DIR/history.log`. 4. If the description contains embedded newline characters, those characters create additional apparent log records. 5. If ...[truncated 1028 chars]- Remediation
View remediation
> "$DATA_DIR/history.log" } ``` 7. Minimize retained data, provide a deletion mechanism, and define a retention period. 8. Align the documented commands and advertised purpose with the executable behavior included in the package. ]]>
