T09 · Insecure Skill Coding Practices
- Location
scripts/upload.py:345- Finding
Sensitive-file protections are bypassed for directly specified files
- Content
View full analysis
- Remediation
View remediation
None: if _is_sensitive_file(path): raise ValueError(f"Refusing to upload sensitive file: {path.name}") if _resolve_mime(path) is None: raise ValueError(f"Unsupported file type: {path.suffix}") ``` 2. Apply the validator to: - Direct `upload.py` files - Single-file `--context` input - `--file --use-file-store` - Inline `--file` input - Every file returned by recursive collection 3. Keep sensitive files denied by default, even if their MIME type is supported. 4. If an override is necessary, require an explicit flag such as `--allow-sensitive-file`, display the destination and filename, and require interactive confirmation. 5. Disable sensitive-file overrides in non-interactive Agent mode unless a separate trusted policy explicitly authorizes them. 6. Add regression tests covering `.env`, `.env.*`, `.npmrc`, `.netrc`, credential JSON files, SSH private-key names, and sensitive extensions through every input mode. ]]>
