T09 · Insecure Skill Coding Practices
- Location
SKILL.md:188- Finding
Persistent Storage of Process Command Lines Without Restrictive Permissions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 188–223
Vulnerability Type: Sensitive information exposure through insecure file permissions
Risk Level: MediumVulnerable Code
bash # Initialize directories mkdir -p "$SNAPSHOT_DIR" "$TREND_DIR" # Collect: PID, process name, RSS (MB), VmSize (MB), runtime, command line echo "# System memory snapshot $TIMESTAMP" > "$snapshot_file" echo "# PID|NAME|RSS|VSZ|TIME|CMD" >> "$snapshot_file" # Command line (truncated) cmd=$(cat "$pid_dir/cmdline" 2>/dev/null | tr '\0' ' ' | cut -c1-50 || echo "[kernel]") [ -z "$cmd" ] && cmd="[$name]" echo "$pid|$name|$rss_mb|$vsz_mb|$etime|$cmd" >> "$snapshot_file"The configured storage location is
/var/log/memory-inspector.Technical Analysis
The script reads command-line arguments from
/proc/<pid>/cmdlinefor every eligible process and persists the first 50 characters in timestamped snapshot files. Command-line arguments may contain passwords, API tokens, session credentials, database connection strings, internal paths, or other sensitive operational information.Capturing command lines is not necessary for the declared memory-growth calculation, which only requires process identity, timestamps, and memory values. Moreover, the script neither establishes a restrictive
umasknor explicitly assigns secure permissions to the directory and generated files. Their effective permissions therefore depend on the invoking environment. A common defaultumaskmay create files readable by users other than the intended administrator.Running the scanner with elevated privileges increases the exposure because it may permit the collection of command lines belonging to services and users that an unprivileged scanner could not inspect.
Attack Path
- An administrator or scheduled job runs the scanner with sufficient privileges to inspect system-wide process metadata.
- A process has sensiti ...[truncated 1149 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not collect process command lines by default. Memory trend analysis should use only PID, process name, start time, RSS, and virtual-memory measurements.
- If command-line collection is explicitly required, make it opt-in and clearly warn that arguments may contain secrets.
- Set a restrictive process mask before creating any storage:
bash umask 077 - Create the storage directories with explicit access controls:
bash install -d -m 0700 "$SNAPSHOT_DIR" "$TREND_DIR" - Create snapshots and reports with mode
0600, verify ownership, and reject unsafe pre-existing directories or symbolic links. - Redact common secret-bearing arguments, including passwords, tokens, authorization headers, keys, and credential-bearing URLs. Prefer allowlisting safe metadata over pattern-based redaction.
- Run the scanner under a dedicated least-privileged account and grant only the process visibility required for the monitoring objective.
- Establish explicit retention and secure-deletion policies for snapshots, reports, cron logs, and exited-process trend records.
- Document who may access the monitoring data and avoid placing sensitive output in broadly readable logs.
