T09 · Insecure Skill Coding Practices
- Location
scripts/scl90.sh:351- Finding
Unprotected Plaintext Storage of Sensitive Mental-Health Responses
- Content
View full analysis
Vulnerability Details
File Location:
scripts/scl90.sh, lines 9–11 and 351–360
Vulnerability Type: Plaintext storage of sensitive health information
Risk Level: MediumVulnerable Code
bash HISTORY_DIR="$HOME/.scl90_history" mkdir -p "$HISTORY_DIR"bash local timestamp=$(date +%Y%m%d_%H%M%S) local result_file="$HISTORY_DIR/result_$timestamp.txt" echo "Saving results to: $result_file" { echo "SCL-90 assessment result - $(date)" echo "Total score: $total_score" echo "Positive item count: $positive_items" echo "-------------------" echo "Answers: ${answers[*]}" } > "$result_file"The textual labels above are English renderings of the original localized output strings; the shell operations and variables are unchanged.
Technical Analysis
The application automatically creates a persistent history directory and writes the complete response set, total score, and positive-item count into an unencrypted text file. These records constitute sensitive mental-health information.
Neither the directory nor the result file is created with an explicit restrictive mode. Their effective permissions therefore depend on the invoking user's
umaskand the accessibility of the home directory. For example, with a permissive configuration, the directory or files may be readable by other local accounts, backup agents, support tools, or unrelated processes executing under the same user.The application also saves the information automatically without requesting explicit consent, providing a no-retention mode, or defining deletion and retention controls.
Attack Path
- A user runs the assessment and submits 90 sensitive responses.
- The application automatically creates
$HOME/.scl90_history. - The complete response set and derived scores are written to
result_YYYYMMDD_HHMMSS.txt. - A local actor or process with access to the user's home directory enumerates that directory ...[truncated 774 chars]
- Remediation
View remediation
Remediation Suggestions
- Default to not retaining assessment answers.
- Obtain explicit informed consent before saving any result.
- Set a restrictive process mask before creating storage:
bash umask 077 - Create the directory with an explicit owner-only mode:
bash mkdir -p -m 700 -- "$HISTORY_DIR" chmod 700 -- "$HISTORY_DIR" - Create result files atomically with mode
600, rather than relying only on shell redirection and the ambientumask. - Consider storing only aggregate results instead of the complete answer set.
- Encrypt retained records using authenticated encryption and protect the key separately from the data.
- Add commands to list and securely delete saved records.
- Document the storage location, retention behavior, and privacy implications before assessment collection begins.
